Method and system for realizing security control and whole-course credibility based on double-circulation credibility verification

By employing a dual-loop trusted verification method, an inner-loop trust chain is constructed using a USB key and a trusted enhanced BIOS, while an outer-loop trust chain is constructed using a security management center. This solves the problems of isolated trust islands and incomplete verification in the network security system, achieving a unified trusted system across the entire network and dynamic trusted verification throughout the entire lifecycle, ensuring the continuous trustworthiness of the operating environment and user behavior.

CN120979827AActive Publication Date: 2025-11-18SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511474176.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-15
Publication Date
2025-11-18
Estimated Expiration
2045-10-15

AI Technical Summary

Technical Problem

The existing cyberspace security system suffers from problems such as isolated trust silos on single machines, incomplete verification, insufficient offline adaptability, low business coupling, and a disconnect between security policies and business operations. It is difficult to build a unified and trustworthy system across the entire network and cannot achieve dynamic and trustworthy verification throughout the entire lifecycle from device startup to business operation.

Method used

A dual-loop trusted verification method is adopted, which constructs an inner loop trust chain through USBKEY and trusted enhanced BIOS, and constructs an outer loop trust chain in conjunction with the security management center, so as to realize dynamic trusted verification throughout the entire life cycle from device startup to business operation, and establish a dynamic linkage mechanism between trusted status and business permissions.

Benefits of technology

Break down trust silos on individual machines, build a unified and trusted system across the entire network, achieve dynamic trusted verification throughout the entire lifecycle, ensure the continuous trustworthiness of the operating environment, application operations, and user behavior, realize deep coupling between security and business, and implement precise access control based on real-time trusted status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979827A_ABST
    Figure CN120979827A_ABST
Patent Text Reader

Abstract

The invention provides a method and a system for realizing security control and whole-course credibility based on dual-cycle credibility verification, which are characterized in that when a response is made to trigger a computing node to execute a service, internal-cycle credibility verification is executed, and full-life-cycle dynamic credibility verification of the computer node from equipment starting to service operation is realized through a USBKEY + BIOS credibility enhancement mode; executing external loop credibility verification on the basis of completing node internal loop credibility verification, including performing identity authentication on the computing node passing the internal loop credibility verification by the security control center, and issuing a security policy corresponding to a service to the computing node according to a node credibility state; and controlling the computing node to execute the security policy in the process of executing the service, and feeding back dynamic credible information when the service is executed to the security management and control center so as to maintain the credibility and controllability of the whole process of the service.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network space security and trusted computing, in particular to a method and system for realizing safe management and whole-process trusted based on double-cycle trusted verification. BACKGROUND

[0002] In today's digital era, the railway ticket network system is facing increasingly complex and diverse security threats and potential risks, such as information leakage, which may lead to the acquisition of passenger personal privacy and travel information by illegal persons; weak password problems make account easy to be cracked, increasing the risk of system intrusion; SQL injection attacks can maliciously tamper with database data, affecting the normal operation of the ticket system; unauthorized access may cause illegal viewing and operation of data; and login blasting attempts to obtain legitimate user rights through brute force cracking means.

[0003] The current network space security faces double threats from inside and outside. The traditional security defense system is based on the core idea of "boundary protection + static rules", which has fundamental defects: first, it is difficult to resist internal attacks such as malicious operation of internal personnel and abuse of power; second, it lacks dynamic perception ability for hidden attacks such as advanced persistent threats (APT), and attackers can freely move horizontally after breaking through the boundary; third, the security policy is disconnected from the business process, forming a governance problem of "two skins of security and business".

[0004] Trusted computing technology builds a trust chain by introducing a hardware-level trusted root (such as TPM, TPCM chip), which improves the security of the system to a certain extent, but there are significant shortcomings in actual application: 1. Single-machine trust island problem: existing TPM / TPCM scheme builds a trust system with a single machine as the core, and each device trust chain is independent of each other, lacking a network-wide collaborative verification mechanism, unable to build a unified trust system across nodes, unable to form a unified trust domain across the network, and difficult to meet the collaborative protection needs of distributed network environment. 2. Incomplete verification coverage: traditional trust chain only covers static measurement at the system startup stage, and stops at the system startup stage, lacking dynamic verification capability in running state, including lack of continuous verification of runtime application state and user behavior, vulnerable to runtime memory attacks and other new threats, and difficult to guarantee the continuous trust of application operation and user behavior. 3. Insufficient offline adaptability: most schemes rely on network connection to complete authentication, and cannot realize trusted verification and authorization in offline scenarios, affecting business continuity. 4. Low business coupling degree: the linkage between trusted state and access control policy is insufficient, and the business rights cannot be dynamically adjusted according to the real-time trust level, and the security protection lags behind the business operation. 5. Security and business are disconnected: security policy and business process are separated, and precise access control cannot be implemented according to real-time trusted state, restricting the safe circulation of data elements.

[0005] In view of the above problems, the existing technology needs to be improved. SUMMARY

[0006] The purpose of the present application is to provide a method and system for realizing secure management and whole-process trusted based on double-loop trusted verification, which can break the single-machine trust island, build a whole-network unified trusted system with the security management center as the root node, realize dynamic trusted verification from device startup to business operation, cover the environment, application and user dimensions, establish a dynamic linkage mechanism between trusted state and business rights, and achieve the advantages of deep coupling of security and business.

[0007] In a first aspect, the present application provides a method for realizing secure management and whole-process trusted based on double-loop trusted verification, which is used for trusted verification of computing nodes and security management centers, comprising: In response to triggering the computing node to perform a business, performing an inner-loop trusted verification; the inner-loop trusted verification comprises dynamically verifying the environment of the computing node from startup to business operation based on USBKEY and trusted enhanced BIOS, to establish a node trusted state; Performing an outer-loop trusted verification, comprising identity authentication of the computing node passing the inner-loop trusted verification by the security management center, and according to the node trusted state, issuing a security policy corresponding to the business to the computing node; Controlling the computing node to perform the security policy in the process of performing the business, and feeding back dynamic trusted information of business execution to the security management center, to maintain the trusted and controllable of the whole process of the business.

[0008] Further, the performing an inner-loop trusted verification comprises: Performing trusted USBKEY availability detection and matching detection to realize trusted USBKEY detection; Verifying the PIN code input by the user to confirm the legality of the user identity, to realize user identity authentication; Performing integrity check on the operating system kernel file, to realize operating system kernel file verification; Verifying the integrity of the operating system key file by comparing the benchmark value of the list configuration file, to realize verification table and file integrity check; After the above node system startup phase trusted verification passes, loading the operating system; During the operation of the operating system, dynamically measuring and monitoring the executable files and behaviors, to realize application program trusted dynamic verification.

[0009] Further, the performing trusted USBKEY availability detection and matching detection to realize trusted USBKEY detection comprises: Through the loaded USBKEY driver, it is detected whether the USBKEY has been inserted and the state is normal or not, if not, the starting is terminated; It is checked whether the signature stored in the USBKEY matches the signature saved in the hard disk of the current computing node, if not, the starting is terminated.

[0010] Further, the dynamic measurement and monitoring of the executable files and behaviors during the operation of the operating system is implemented, and the dynamic verification of the application program is realized, including: After the operating system is started, the process monitoring system cooperates with the trusted software base, when the executable file or script is called, the actual hash value is calculated and compared with the legal hash value in the trusted software base, the dynamic measurement result is obtained, and after the comparison passes, the executable file or script is allowed to be loaded and executed; During the running of the executable file or script, the behavior information is continuously monitored and judged, the behavior information is matched with the preset security policy, and the unauthorized behavior is identified; the behavior information includes system call events, network connection events and file access events; The dynamic measurement result and the behavior information are encrypted and written into the security log, and are reported to the security management center, so that the continuous trust and controllability of the application program and behavior during the operation of the operating system are maintained.

[0011] Further, the external loop trusted verification is executed, including: System initialization and establishment of global trusted root: the security management center loads the hardware password and calls the national secret service to generate the root certificate key pair, initializes the global policy library and trust chain database, and establishes the global trusted root of the whole system; Network node trusted authentication: for the new device accessing the trusted network, the security management center verifies the authenticity of the device certificate and issues the device certificate, and then completes the identity mutual trust verification between the device and the security management center through the bidirectional certificate authentication mechanism before each session; Policy generation and delivery: after the device trusted authentication is successful, the security management center generates the device-level security policy according to the device identity, real-time trusted state and security policy library, signs the device-level security policy to ensure the integrity, and then delivers the device-level security policy to the trusted security agent for execution; Dynamic monitoring of application program: the trusted security agent continuously collects system behaviors for dynamic measurement and comparison with the policy by calling the security trusted policy library, and realizes the blocking and reporting of abnormal behaviors; Log database trace retention: the log library records the authentication, policy and behavior log information of the whole network, provides a visual interface to centrally display the device trust state, security situation and alarm events, and supports the trace and audit analysis of security events.

[0012] Further, the network node trusted authentication further includes: The computing node corresponding to the device sends a registration request to the security management center, and the security management center issues a device digital certificate for the computing node after verifying the credentials of the computing node; Before the device accesses the network, the security management center performs two-way authentication based on a random number and a digital certificate, to ensure that the identities of the two parties are trusted.

[0013] Further, the application program dynamic monitoring further includes: The trusted security agent continuously collects system calls, network access behaviors, and compares and measures benchmark values in the security trusted policy library; When abnormal or illegal behaviors are detected, the trusted security agent performs local blocking and reports to the security management center; The trusted security agent receives and executes access control decisions issued by the security management center.

[0014] The second aspect further provides a security management and control and whole-process trusted system based on double-cycle trusted verification, for trusted verification of a computing node and a security management center, comprising: An inner-cycle trusted verification module is configured to perform inner-cycle trusted verification in response to triggering the computing node to perform a service; the inner-cycle trusted verification includes dynamic trusted verification of an environment of the computing node from startup to service running based on a USBKEY and a trusted enhanced BIOS, to establish a node trusted state; An outer-cycle trusted verification module is configured to perform outer-cycle trusted verification, including identity authentication of the computing node passing the inner-cycle trusted verification by the security management center, and issuing a security policy corresponding to the service to the computing node according to the node trusted state; A control and feedback module is configured to control the computing node to execute the security policy in the process of executing the service, and feed back dynamic trusted information of the service execution to the security management center, to maintain the trust and controllability of the whole process of the service.

[0015] The third aspect further provides a network node trusted diffusion outer-cycle system based on a security management center, the system comprising a security management center, a secure transmission platform, a trusted security agent, a security policy library, and a log database; wherein: The security management center is configured to generate a system root certificate based on a hardware cryptographic module; receive a registration request of a network computing node, verify the credentials of the network computing node, and issue a device digital certificate for the network computing node; and perform two-way certificate authentication with the trusted security agent through the secure transmission platform before establishing a connection with the network computing node; The secure transmission platform is configured to establish an end-to-end encrypted communication link between the security management center and the trusted security agent based on a national cryptographic algorithm; and after the two-way certificate authentication is completed, dynamically generate a session key to ensure the independence and forward security of the communication; A trusted security agent is used to monitor the runtime behavior of the network computing nodes it resides in, collect security metrics and report them to the security management center through the secure transmission platform; receive and verify security policies issued by the security management center, and perform access control, process isolation and file permission management operations locally; when it detects behavior that deviates from the security baseline, it performs local blocking and reports it. The security policy library is used to store and manage security policy rules, including integrity metric baselines, mandatory access control rules, and abnormal behavior response mechanisms. The log database is used to record device certificates, trust status, authentication logs, and policy execution logs, and provides a visual display of the overall network trust status and security posture.

[0016] Fourthly, a trusted inner-loop trust chain diffusion system based on a USB key is also proposed. This system includes a USB key and BIOS module, a USB key driver, a boot authentication module, a trusted boot module, and a runtime monitoring module; wherein: The USBKEY and BIOS module is used to form the hardware root of trust together with the trusted enhanced BIOS, wherein the BIOS is set as a trusted measurement root, and the USBKEY is set as a trusted reporting root and a trusted storage root; The USBKEY driver is used to encapsulate the interface for interacting with the USBKEY (100) and to provide call support for other modules, including the real-mode driver that works in the early stage of system startup and the operating system environment driver that works after the operating system is loaded. The power-on authentication module is used to verify the PIN code entered by the user and perform two-way authentication with the USBKEY, and allow the system to start after successful authentication; The trusted boot module is used to call the USBKEY to perform integrity measurement on the system kernel file and key components before loading the operating system kernel, and compare the measurement result with the baseline value stored in the USBKEY. The operating system will only continue to be loaded after the verification is successful. The monitoring module is used to generate an integrity benchmark library for critical system processes after the system's first trusted boot and to sign it using the certificate of the USBKEY; during system operation, it continuously monitors the integrity of critical processes and compares them with the integrity benchmark library.

[0017] From the above, the application provides a safe control and whole-process trusted method and system based on double-cycle trusted verification, which takes trusted verification as the core, takes trusted USBKEY and safe control center as the support, and uses innovative double-trust chain diffusion mechanism of "outer cycle" and "inner cycle" to break the single-machine trust island and build a unified trusted system taking the safe control center as the trusted root and covering all nodes in the network. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be considered as limiting the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0019] Figure 1 is a schematic diagram of a safe control and whole-process trusted system based on double-cycle trusted verification disclosed by the embodiments of the present application; Figure 2 is a step flow chart of a safe control and whole-process trusted method based on double-cycle trusted verification disclosed by the embodiments of the present application; Figure 3 is a flow chart of a trusted inner cycle trust chain diffusion system disclosed by the embodiments of the present application; Figure 4 is a flow chart of an inner cycle trusted verification method disclosed by the embodiments of the present application; Figure 5 is a step flow chart of an outer cycle trusted verification disclosed by the embodiments of the present application; Figure 6 is a flow chart of an outer cycle trust chain diffusion disposal disclosed by the embodiments of the present application; Figure 7 is a schematic diagram of a network trusted extended outer cycle system structure based on the security management center disclosed by the embodiments of the present application; Figure 8 is a schematic diagram of a trusted inner cycle trust chain diffusion system architecture based on USBKEY disclosed by the embodiments of the present application. DETAILED DESCRIPTION

[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments belong. The terminology used in the description herein is for describing particular embodiments only and is not intended to be limiting of the embodiments. The terms "comprises", "comprising", "includes", "including", "has", "having" and any variations thereof are intended to cover a non-exclusive inclusion. The terms "first", "second", and the like, used in the description and in the claims, do not necessarily have an ordinal implication, and are used to distinguish one element from another.

[0021] The implementation details of the technical solutions of the embodiments are described below in detail: As shown in Figure 1 The schematic diagram of the double-cycle trusted verification architecture of the embodiments is shown. The local computing node trust is established through the "in-node cycle", and the network global device trust is established through the "out-network cycle", and finally the business whole-process trust is realized through the "double-cycle cooperation". The USBKey+BIOS is taken as the trusted root to perform startup measurement on the computing node, and then the executable file hash check and behavior monitoring are continuously completed by the process monitoring and trusted software base during the operation of the operating system, forming the in-node "measurement-comparison-blocking-recording" inner cycle. At the same time, the dynamic measurement results of each node are encrypted and reported to the security management center, and the center analyzes and uniformly issues strategies to realize the strategy synchronization and trust chain diffusion across nodes, constituting the out-network cycle, so as to break through the whole-process trust and security management from startup to running and from single point to the whole network.

[0022] The embodiments propose a method for realizing security management and whole-process trust based on double-cycle trusted verification, which is used for trusted verification of computing nodes and a security management center, as shown in Figure 2 The method comprises the following steps: S201, in response to triggering the computing node to perform a business, performing an inner-cycle trusted verification; the inner-cycle trusted verification comprises dynamically verifying the environment of the computing node from startup to business running based on USBKEY and trusted enhanced BIOS, to establish a node trusted state; S202, performing an outer-cycle trusted verification, comprising identity authentication of the computing node passing the inner-cycle trusted verification by the security management center, and issuing a security strategy corresponding to the business to the computing node according to the node trusted state; S203, controlling the computing node to execute the security strategy in the process of executing the business, and feeding back dynamic trusted information of the business execution to the security management center, to maintain the trust and controllability of the whole process of the business.

[0023] Specifically, for step S201, in response to triggering the computing node to perform the service, the inner loop trusted verification is performed. The purpose of the inner loop is to ensure that the running environment of a single computing node from the underlying hardware to the upper application is trusted, and the core is to perform trusted enhancement by using an external plug-in card and combining BIOS trusted upgrade, replace the TPM with a USBKEY with trusted verification function, and take the USBKEY+BIOS as a trusted root. On this basis, through boot authentication, trusted boot, trusted software base and support system, the security and trust of the entire computing environment are further extended.

[0024] As shown in Figure 3 , it is a flow chart of the trusted inner loop trust chain diffusion system of the embodiment. The core is that when the GRUB booting the operating system, the boot authentication and integrity measurement links are integrated in the startup process, effectively building a complete and uninterrupted trust chain from the trust root (USBKEY) to the operating system loading, thereby ensuring the security and trust of system startup. Then, through the software trusted base, the trusted dynamic verification of the application program is realized, thereby completing the transmission and extension of the entire inner loop trust chain.

[0025] Further, the method for performing the inner loop trusted verification of the embodiment is shown in Figure 4 , which includes: S401, performing trusted USBKEY availability detection and matching detection to realize trusted USBKEY detection.

[0026] Further, the trusted USBKEY availability detection and matching detection are performed to realize trusted USBKEY detection, which includes: detecting whether the USBKEY has been inserted and whether the state is normal and available through the loaded USBKEY driver, and if not, terminating the startup; verifying whether the signature stored in the USBKEY matches the signature saved in the hard disk of the current computing node, and if not, terminating the startup.

[0027] Specifically, in the embodiment, when the system starts, first, the BIOS power-on self-test (complete the hardware basic self-test) is performed; then, the USBKEY driver is loaded to provide program support for the authentication of the USBKEY. The verification function function in the driver program is used to check whether the USBKEY has been inserted and confirm whether its state is normal and available. If there are abnormal conditions such as no USBKEY inserted or the inserted USBKEY cannot normally read data, the startup process will be immediately terminated.

[0028] After the USBKEY insertion detection verification passes, the system checks the signature saved in the hard disk to verify whether the USBKEY matches the current computer. If not, it indicates that the USBKEY is not software-bound with the computer and is not its trusted extension module, and finally prompts an error and closes the computer (processed uniformly with other error branches) to end the process.

[0029] S402, the PIN code input by the user is verified to confirm the legitimacy of the user identity, and user identity authentication is realized. Specifically, in this embodiment, after the USBKEY matching detection, user identity authentication is performed, and the system prompts the user to input a PIN code to log in to the operating system. If the input PIN code is incorrect, the system will determine the number of remaining errors. After reaching the maximum number of errors, the system will report an error and lock the USBKEY, terminating the startup; if the maximum number of errors has not been reached, the user will be prompted to re-enter the PIN code until the verification passes or the USBKEY is locked.

[0030] S403, integrity verification of the operating system kernel file is performed to realize operating system kernel file verification. Specifically, in this embodiment, the system verifies the legality of the "operating system kernel file" (whether it meets the trusted standard): if the verification fails, an error is prompted and the computer is closed (processed uniformly with other error branches) to end the process; if the verification passes, the "list configuration file" is read to obtain the file list and rules to be verified.

[0031] S404, the integrity of the operating system key file is verified by comparing the reference value of the list configuration file to realize verification table and file integrity verification. Specifically, in this embodiment, the verification table correctness verification is performed: by comparing the read list configuration file with the trusted list configuration file reference value pre-stored in the trusted software base of the USBKEY, it is determined whether the "verification table is correct". If the verification table prompts an error and the computer is closed (processed uniformly with other error branches), the process ends; if it is correct, the next step of verifying the "file integrity in the verification table" is entered.

[0032] The file integrity verification in the verification table is performed: by comparing the Hash value of the corresponding file in the read list configuration file with the Hash value pre-stored in the trusted list configuration file in the trusted software base of the USBKEY, the file integrity verification is performed. If the file integrity verification fails, an error is prompted and the computer is closed (processed uniformly with other error branches) to end the process; if it passes, the next step is entered.

[0033] S405, after the trusted verification passes in the above node system startup phase, the operating system is loaded.

[0034] Specifically, in the embodiment, after the verification passes, the inner loop completes the trusted verification of the system startup phase, the system normally loads the operating system, and the process enters the trusted verification link of the application program.

[0035] S406, during the operation of the operating system, the executable files and behaviors are dynamically measured and monitored to realize the trusted dynamic verification of the application program.

[0036] Further, the dynamic measurement and monitoring of the executable files and behaviors during the operation of the operating system to realize the trusted dynamic verification of the application program comprises: after the operating system is started, the process monitoring system cooperates with the trusted software base to calculate the actual hash value of the executable file or script when it is called and compare it with the legal hash value in the trusted software base to obtain a dynamic measurement result; after the comparison passes, the executable file or script is allowed to be loaded and executed; during the execution of the executable file or script, the behavior information is continuously monitored and judged, the behavior information is matched with the preset security policy, and unauthorized behavior is identified; the behavior information comprises system call events, network connection events and file access events; the dynamic measurement result and the behavior information are encrypted and written into a security log, and are reported to the security management center to maintain the continuous trust and controllability of the application program and behavior during the operation of the operating system.

[0037] Specifically, in the embodiment, after the operating system is started, the dynamic measurement is a continuation and diffusion of the trust chain during the operation of the operating system, which is mainly executed by the process monitoring system cooperating with the trusted software base to verify the hash values of all executable files and scripts to be loaded, and to monitor system calls, network connections, file accesses and the like, and finally to record these dynamic information in a security log. Ensure the continuous trust of the application program and behavior.

[0038] Executable file / script measurement: when an application program (such as ls, java) or a script is called for execution, the process monitoring system will intercept the execution request, calculate the hash value of the executable file first, and compare it with the legal hash value stored in the trusted software base. After the verification passes, it is allowed to load and execute. At the same time, the configuration files and startup scripts dependent on the application program are also measured before loading to prevent malicious tampering of the configuration.

[0039] Behavior monitoring: for dynamic measurement, the process monitoring system will monitor the behavior of the application program, including: system call situation, network connection situation, file access situation. For system call situation monitoring, the system call (such as file operation, process creation, etc.) initiated by the application program is monitored to determine whether its behavior conforms to the security policy; for network connection situation monitoring, the network connection behavior of the process is recorded and analyzed to determine whether it connects an unauthorized address or port; for file access situation monitoring, the access behavior of the software application to the key system files and sensitive data is monitored.

[0040] Security log generation: the process monitoring system records all measured hash values, system behavior events (including success, failure, exception) and related context information in the security log after encryption, and sends it to the security management center for analysis, evidence and policy decision.

[0041] The above node trusted inner loop runs throughout the entire life cycle of the computer node from hardware to application, ensuring that even in operation, the execution environment of the node is under continuous monitoring and verification, realizing the complete diffusion of the trust chain from static startup to dynamic maintenance.

[0042] Further, as Figure 5 The flowchart for performing outer loop trusted verification is shown. The execution of the outer loop trusted verification includes: S501, system initialization and global trusted root establishment: the security management center loads the hardware password and calls the national secret service to generate the root certificate key pair, initializes the global policy library and trust chain database, and establishes the global trusted root of the whole system; S502, network node trusted authentication: for new devices accessing the trusted network, the security management center verifies the authenticity of the device certificate and issues a device certificate, and then completes the identity mutual trust verification between the device and the security management center through a two-way certificate authentication mechanism before each session; S503, policy generation and delivery: after successful device trusted authentication, the security management center generates device-level security policies based on device identity, real-time trusted state and security policy library, signs them to ensure integrity, and then delivers them to the trusted security agent for execution; S504, dynamic monitoring of application programs: the trusted security agent continuously collects system behavior through the security trusted policy library and compares it with the policy to realize abnormal behavior blocking and reporting; S505, log database trace retention: the log library records the authentication, policy, behavior log information of the whole network, provides a visual interface to centrally display the device trust state, security situation and alarm events, and supports security event trace and audit analysis.

[0043] Further, the network node trusted authentication further includes: based on the device corresponding to the computing node, sending a registration request to the security management center, and the security management center verifying the certificate and issuing a device digital certificate; before the device accesses the network, two-way authentication based on random number and digital certificate is performed with the security management center to ensure the identity of both parties is trusted.

[0044] Further, the application dynamic monitoring further comprises: based on the trusted security agent continuously collecting system calls, network access behaviors, and comparing and measuring benchmark values in the security trusted policy library; when abnormal or illegal behaviors are detected, the trusted security agent performs local blocking and reports to the security management center; based on the trusted security agent, the security management center issues access control decisions, which are received and executed.

[0045] Specifically, in the embodiment, the outer circulation trust chain diffusion is to diffuse the trust to all network devices by taking the security management center as a global trusted root and using a two-way certificate authentication mechanism. The outer circulation trust chain diffusion processing flow is as shown in Figure 6

[0046] First, system initialization and global trusted root establishment. This step aims to determine the global trusted root by initializing the trusted root of the security management center and the SQY20 cryptographic system parameters. The specific steps include: the security management center is powered on, the built-in hardware cryptographic module is started; SQY20 service is called, the key pair of the root certificate (Root CA) is generated based on the root seed; the global policy library and the log database are initialized; the security management center completes self-checking, and its own state is trusted, becoming a global trusted root.

[0047] Second, network node trusted authentication. The purpose of network node trusted authentication is to safely spread the trust of the security management center to each device in the network, and the implementation is two-way certificate authentication. (1) Device registration and certificate issuance: in order to guarantee the security of the computing network, any device (computing node or network device) must register with the security management center before accessing the network. First, the device sends a registration request to the security management center, which contains the endorsement credentials and public key of the TPCM. After verifying the authenticity of the endorsement credentials, the security management center issues a digital certificate for the device using its root private key. At the same time, the device certificate is issued to the device, and the device is recorded in the log database, and the status is marked as "registered".

[0048] ​(2) Bidirectional authentication: before each attempt to access the network or establish a secure session, the device must complete a bidirectional authentication with the security management center. First, the device sends a connection request to the security management center, containing a random number Nonce_C, and then the security management center sends its own certificate and a new random number Nonce_S to the device. After receiving the certificate of the security management center, the device will verify its signature, and encrypt the random number (Nonce_C+Nonce_S) with the public key in the security management center to get the ciphertext C1, and send it to the security management center together with the device certificate; after receiving the ciphertext and device certificate, the security management center first verifies the device certificate, and then decrypts the ciphertext C1 using its own private key to get Nonce_C*+Nonce_S*, if Nonce_S* = Nonce_S, the device identity is real, and the authentication is successful.

[0049] Third, policy generation and delivery. After successful authentication of the device and the security management center, the security management center will generate and deliver the trusted response policy. The specific sub-steps are: (1) Policy generation: the security management center will generate a device-level security policy based on the device identity, real-time trusted state and security policy library.

[0050] (2) Policy delivery: after generating the security policy, the security management center signs it to ensure its integrity, and delivers it to the trusted security agent using the session key, which receives and loads the policy for execution.

[0051] Fourth, dynamic monitoring of application programs. The trusted security agent will continuously monitor and dynamically process the trusted state of application programs, including the following sub-steps: (1) Behavior monitoring: the trusted security agent continuously collects system behaviors including system calls, network access, etc., and continuously measures whether there are unauthorized or illegal actions in combination with the trusted benchmark values in the security and trusted policy library.

[0052] (2) Abnormal reporting: when there are abnormal or illegal actions in the system behavior, the trusted security agent will block the abnormal behavior and report it to the security management center for decision, and receive the comprehensive trust evaluation and delivery decision from the security management center.

[0053] (3) Execution of security policy: when the decision result is delivered to the trusted security agent, it will execute the specific control actions of allowing or rejecting access at the local and network levels.

[0054] Fifth, log database trace retention. The log database will record the authentication, policy, behavior log and other information of the whole network, provide a visual interface to display the trust state, security situation and alarm events of the device, and support the trace and audit analysis of security events.

[0055] The second aspect also provides a secure management and control and whole-process trusted system based on double-cycle trusted verification, which is used for trusted verification of a computing node and a secure management and control center, and comprises the following: an inner-cycle trusted verification module, configured to perform inner-cycle trusted verification in response to triggering the computing node to perform a service; the inner-cycle trusted verification comprises dynamic trusted verification of an environment of the computing node from startup to service running based on a USBKEY and a trusted enhanced BIOS, so as to establish a node trusted state; an outer-cycle trusted verification module, configured to perform outer-cycle trusted verification, which comprises identity authentication of the computing node passing the inner-cycle trusted verification by the secure management and control center, and issuing of a security policy corresponding to the service to the computing node according to the node trusted state; a control and feedback module, configured to control the computing node to perform the security policy in a process of performing the service, and feed back dynamic trusted information in service performance to the secure management and control center, so as to maintain the trusted and controllable whole process of the service.

[0056] The third aspect also provides a network node trusted diffusion outer-cycle system based on a secure management and control center, which comprises a secure management and control center, a secure transmission platform, a trusted security agent, a security policy library and a log database; wherein: the secure management and control center is configured to generate a system root certificate based on a hardware cryptographic module; receive a registration request of a network computing node, verify a credential thereof and issue a device digital certificate for the network computing node; and perform bidirectional certificate authentication with the trusted security agent through the secure transmission platform before establishing a connection with the network computing node; the secure transmission platform is configured to establish an end-to-end encrypted communication link between the secure management and control center and the trusted security agent based on a national cryptographic algorithm; and after bidirectional certificate authentication is completed, dynamically generate a session key to guarantee independence and forward security of communication; the trusted security agent is configured to monitor runtime behavior of a network computing node where the trusted security agent is located, collect a security measurement value and report the security measurement value to the secure management and control center through the secure transmission platform; receive and verify a security policy issued from the secure management and control center, and perform local access control, process isolation and file permission management operations; and when detecting a behavior deviating from a security baseline, perform local blocking and reporting; the security policy library is configured to store and manage security policy rules, including an integrity measurement baseline value, a mandatory access control rule and an abnormal behavior response mechanism; the log database is configured to record device certificates, trust states, authentication logs and policy execution logs, and provide visual display of a whole-network trusted state and a security posture.

[0057] Specifically, the embodiment comprises the following: Figure 7The diagram shows the architecture of the network trusted extension outer loop system based on the security management center in this embodiment. The system uses the security management center as the root of trust, the secure transmission platform as the foundation, and the security policy library as support. It employs two-way certificate authentication for network computing nodes to achieve the diffusion of the trusted chain in the computing network space. The system mainly consists of components such as the security management center, the security policy library, the secure transmission platform, the log database, and the trusted security proxy.

[0058] The security management center, acting as the system's global root of trust and command center, is responsible for the unified management, policy distribution, and dynamic decision-making of the entire trusted network. Its core functions include: generating root certificates based on the hardware-based national cryptographic module (SQY20) to ensure the trustworthiness of the entire system's starting point; receiving device registration requests, verifying the authenticity of their digital credentials, and issuing device digital certificates; performing two-way certificate authentication with devices before network access or session establishment to ensure mutual trust between devices and the security management center; and finally, generating and signing security policies based on device identity, internal loop measurement results, and the global policy library, and distributing them to network devices or terminal agents for execution.

[0059] The secure transmission platform: The secure transmission platform provides a secure communication framework that guarantees the confidentiality, integrity, and availability of the system, mainly including: An end-to-end encrypted communication link is constructed based on national cryptographic algorithms to prevent data eavesdropping and tampering; and after two-way authentication is completed, a session key is dynamically generated to ensure the independence and forward security of each communication.

[0060] The Trusted Security Agent: The Trusted Security Agent is a software agent deployed on the terminal computing node, responsible for the construction and maintenance of the local trusted environment. Its functions include: monitoring application loading, system calls, network connections, file operations and other behaviors, collecting and reporting metrics in real time; receiving and verifying the issued security policies, performing network access control, process isolation, file permission management and other operations locally, and blocking and reporting to the security management center when deviating from the baseline behavior is detected locally.

[0061] The security and trust policy library is a core database that stores and manages all security policy rules. It contains a systematic security solution, which includes baseline values ​​(such as expected hash values) for integrity measurement of system bootloaders, critical applications and sensitive data, permission rules for mandatory access control, and response mechanisms (such as alarms, blocking or recovery) for abnormal behavior.

[0062] The log database: records the certificates, public keys, registration time, recent authentication time, trust status (such as "registered", "authenticated", "suspicious", "revoked", etc.) of all registered devices, and stores all authentication, policy distribution, access decision logs, and provides a visual interface to display the network trust status and security situation.

[0063] The double-book authentication module: the double-book authentication module is the core security component in the external circulation trust chain diffusion process, responsible for implementing high-strength, two-way identity authentication between the security management center and the access network device. Based on the public key infrastructure, the module generates and verifies digital certificates relying on the national encryption algorithm, ensuring the legality and trustworthiness of the identity of both parties in communication.

[0064] The fourth aspect also proposes a USBKEY-based trusted internal circulation trust chain diffusion system, which comprises a USBKEY and BIOS module, a USBKEY driver, a boot authentication module, a trusted boot module, and a running monitoring module; wherein: The USBKEY and BIOS module is used to jointly constitute the hardware trusted root with the USBKEY and the trusted enhanced BIOS, wherein the BIOS is set as the trusted measurement root, and the USBKEY is set as the trusted reporting root and the trusted storage root; The USBKEY driver is used to encapsulate the interface for interacting with the USBKEY (100) and provide calling support for other modules, including a real mode driver working at the initial stage of system startup and an operating system environment driver working after the operating system is loaded; The boot authentication module is used to verify the PIN code input by the user and perform two-way authentication with the USBKEY, and allow the system to start after the authentication is passed; The trusted boot module is used to call the USBKEY to measure the integrity of the system kernel file and key components before loading the operating system kernel, and compare the measurement result with the reference value stored in the USBKEY, and only continue to load the operating system after the verification is passed; The running monitoring module is used to generate an integrity reference library of system key processes after the system is first trusted to start, and sign it using the certificate of the USBKEY; during system operation, continuously monitor the integrity of the key processes and compare it with the integrity reference library.

[0065] As Figure 8The USBKEY is used to replace the traditional TPM (trusted platform module) to form a more flexible and powerful trusted root in combination with the BIOS. The user verifies the legitimacy of his / her identity by inputting a PIN code and successfully passing the boot authentication. Subsequently, the trusted boot mechanism performs strict integrity verification on the system kernel file to ensure that each link in the system startup process remains trusted, thereby seamlessly extending the trust chain to every corner of the computer system.

[0066] The hardware trusted root is composed of the USBKEY and the BIOS with enhanced trustworthiness. The BIOS serves as the trusted measurement root, and the USBKEY acts as the trusted reporting root and the trusted storage root. The USBKEY as the trusted root is a smart card with a USB interface and has high security.

[0067] The overall architecture of the USBKEY is composed of two core components: the smart card and the Flash CD-ROM area. The smart card is built-in with an independent CPU and a COS (chip on system), which can autonomously perform complex operation tasks including encryption, decryption and digital signature, etc. to ensure that the key information is always kept inside the device rather than exposed in the computer memory, thereby effectively preventing the risk of direct key theft by external attackers through the computer system. The COS is responsible for regulating the information interaction process with the external environment, managing the use of the internal memory, and directly processing various operation instructions in the device. The Flash CD-ROM area serves as the carrier for data storage, and the data therein is not directly accessible but needs to be read and written through a specific interface program, thereby enhancing the security of the data. In this embodiment, this area is mainly used to store various key files, including but not limited to the driver program of the USBKEY, the trusted boot authentication program, the trusted boot program, and the pre-stored digest value and other important information. These files collectively support the secure boot, authentication process and efficient operation of the USBKEY.

[0068] The USBKEY driver carefully encapsulates all the core interfaces for interacting with the USBKEY device, providing a convenient and secure calling approach for other modules in the system. According to different actual application scenarios, the USBKEY driver is ingeniously divided into two categories: the real mode driver and the operating system environment driver. The former starts working in the initial boot stage of system startup, directly calling through the BIOS interface to ensure that a security barrier is established at the most bottom layer of the system; and the latter is activated after the operating system kernel is successfully loaded and runs, using the USB protocol stack inside the operating system to realize communication with the USBKEY, and providing stable and efficient security support for the system process library and the monitoring system and other advanced functions.

[0069] The trusted enhanced BIOS adopts the strategy of embedding GRUB (GRand Unified Bootloader) into the USBKEY, which serves as a bridge to guide the loading of the operating system. In order to realize trusted boot, the source code of GRUB is customized and modified in this embodiment, so that GRUB can seamlessly integrate boot authentication and trusted boot program in the boot process, thereby ensuring that every step from the trusted source USBKEY to the loading of the operating system is strictly controlled. The specific modifications include the following: The trusted boot function is integrated into the Stage2 main function of GRUB. Before loading the system kernel, Stage2 calls the trusted boot program as a key step. This program is responsible for performing integrity measurement on the system kernel file, list configuration file and other key system components. Only when the integrity of these components is verified, i.e. it is confirmed that they have not been tampered with or damaged, GRUB will continue to execute and load the operating system. This mechanism effectively improves the security of the system startup process, preventing potential security threats and malicious software intrusion.

[0070] The main purpose of the boot authentication module is to verify the legitimacy of the user and the USBKEY device. It verifies the user's identity through PIN code, while the USBKEY authenticates the computer, and this double verification ensures the legitimacy of the user. Only when the correct USBKEY is inserted and the correct PIN code is entered, the computer can be successfully started.

[0071] The main responsibility of the trusted boot module is to verify the integrity of the system kernel file, which is an important link to ensure the security of the system core. It adopts a trust model based on data integrity, which simplifies the trust state into "trusted" and "untrusted", and assumes that trust will not weaken or be lost in the transmission process. In order to perform efficient integrity verification, the module uses the domestic SM3 digest algorithm to calculate the digest value of the component to be loaded, and this process is assisted by the real mode driver on the USBKEY.

[0072] The trusted software base, as the core component of the trusted internal loop trust extension transmission, cooperates with software foundations such as device drivers to ensure that upper-layer applications can efficiently use the rich trusted computing functions provided by USBKEY, while making up for the shortcomings of USBKEY in computing and storage capacity, and jointly supporting the trusted computing needs of the entire platform. As an extension of USBKEY, the trusted software base provides an interface for upper-layer applications to access USBKEY, not only supporting application programs to access USBKEY, but also being responsible for managing USBKEY.

[0073] The trusted support subsystem starts running after the system core environment is ready (i.e. the kernel is loaded and all system processes are initialized successfully), and its main functions include: (1) Ensure that the system complies with the strict trusted boot process to load securely, and maintain the security state of the system during operation. Specifically, it integrates the boot authentication and trusted boot functions using GRUB as the boot tool, ensures that the preset trust chain is followed from the beginning of the boot, and only allows the operating system to load after passing the authentication and boot verification.

[0074] (2) Build and maintain a system benchmark library, which is not limited to integrity verification at startup, but also continuously monitors the integrity of each process during system operation. After the first trusted boot and initialization of all system processes, the subsystem captures the current state snapshot of these processes, generates a unique digest value based on the process name, path and executable file using the SM3 algorithm, and forms a system benchmark library. This benchmark library is then securely signed by the identity certificate of the USBKEY, and uploaded to the security management platform by the trusted security agent for subsequent comparison and monitoring, thereby achieving comprehensive reinforcement of system security.

[0075] The process monitoring system uses a process monitoring system based on double-process protection technology. This system works when the operating system is running, and its main task is to monitor the processes of the system and verify their integrity to prevent malicious tampering and ensure the security of the computer. To ensure that the monitoring process is always running, we use double-process protection technology to prevent the monitoring process from being accidentally terminated. The monitoring process and the protection process listen to each other, and if one of them is terminated, the other will immediately take measures to restore it.

[0076] The above only describes the embodiments of the present application and does not limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for achieving security control and end-to-end trust based on dual-loop trusted verification, used for trusted verification of computing nodes and security control centers, characterized in that, include: When a computing node is triggered to execute a business function, an inner loop of trusted verification is performed. The inner loop trusted verification includes dynamic trusted verification of the computing node's environment from startup to business operation based on USBKEY and trusted enhanced BIOS, in order to establish the node's trusted state; Performing outer loop trusted verification includes the security control center authenticating the identity of the computing node that has passed the inner loop trusted verification, and issuing the security policy corresponding to the service to the computing node according to the trusted status of the node; The system controls the computing nodes to execute the security policy during business operations and feeds back dynamic trust information during business execution to the security management center to maintain the trust and control of the entire business process.

2. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 1, characterized in that, The execution of the inner loop trusted verification includes: Perform trusted USB key availability and matching checks to achieve trusted USB key detection; Verify the PIN code entered by the user to confirm the legitimacy of the user's identity and achieve user authentication; Perform integrity verification on the operating system kernel file to achieve operating system kernel file verification; By comparing the baseline values ​​in the list configuration file, the integrity of critical operating system files is verified, thus realizing the verification of the integrity of the verification table and files. After the trusted verification is passed during the startup phase of the above-mentioned node system, the operating system is loaded; During the operation of the operating system, executable files and behaviors are dynamically measured and monitored to achieve trusted dynamic verification of applications.

3. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 2, characterized in that, The process of performing trusted USB key availability and matching checks to achieve trusted USB key detection includes: The loaded USBKEY driver detects whether the USBKEY is inserted and whether its status is normal and usable. If it is not usable, the startup process is terminated. Verify that the signature stored in the USBKEY matches the signature saved on the hard drive of the current compute node. If they do not match, terminate the startup process.

4. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 2, characterized in that, The process of dynamically measuring and monitoring executable files and behaviors during the operation of the operating system to achieve trusted dynamic verification of applications includes: After the operating system starts, the process monitoring system works in conjunction with the trusted software base. When an executable file or script is called, it calculates its actual hash value and compares it with the valid hash value in the trusted software base to obtain a dynamic measurement result. If the comparison is successful, the executable file or script is allowed to be loaded and executed. During the execution of an executable file or script, its behavior information is continuously monitored and judged, and the behavior information is matched with a preset security policy to identify unauthorized behavior; the behavior information includes system call events, network connection events, and file access events; The dynamic measurement results and behavioral information are encrypted and written into the security log, and then reported to the security control center to maintain the continuous trust and controllability of applications and behaviors during the operation of the operating system.

5. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 1, characterized in that, The execution of the outer loop trusted verification includes: System initialization and global root of trust establishment: The security management center loads the hardware cryptography and calls the national cryptographic service to generate root certificate key pairs, and initializes the global policy library and trust chain database to establish the global root of trust for the entire system; Trusted authentication of network nodes: For new devices accessing the trusted network, the security management center verifies the authenticity of the device credentials and issues a device certificate. Then, before each session, a two-way certificate authentication mechanism is used to complete the mutual trust verification between the device and the security management center. Policy generation and distribution: After successful device trusted authentication, the security management center generates a device-level security policy based on the device identity, real-time trusted status and security policy library, signs it to ensure its integrity, and then distributes it to the trusted security agent for execution; Application dynamic monitoring: The trusted security agent calls the security and trusted policy library to continuously collect system behavior, perform dynamic measurement and compare it with the policy, so as to block and report abnormal behavior; Log database traceability and retention: The log database records authentication, policy, and behavior log information across the entire network, and provides a visual interface to centrally display device trust status, security posture, and alarm events, supporting the tracing and auditing analysis of security events.

6. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 5, characterized in that, The network node trusted authentication also includes: Based on the device corresponding to the computing node, a registration request is sent to the security management center. After verifying its credentials, the security management center issues a device digital certificate. Before the device connects to the network, it undergoes two-way authentication with the security management center based on random numbers and digital certificates to ensure the trustworthiness of both parties' identities.

7. The method for achieving security control and end-to-end trust based on dual-loop trusted verification according to claim 5, characterized in that, The application dynamic monitoring also includes: Based on the trusted security agent, system calls and network access behaviors are continuously collected and compared with the benchmark values ​​in the security and trusted policy library. When abnormal or illegal behavior is detected, the trusted security agent blocks it locally and reports it to the security control center; The trusted security agent receives and executes access control decisions issued by the security management center.

8. A security control and end-to-end trust system based on dual-loop trusted verification, used for trusted verification of computing nodes and security control centers, characterized in that, include: The inner loop trusted verification module is used to perform inner loop trusted verification in response to the triggering of computing nodes to execute business operations; The inner loop trusted verification includes dynamic trusted verification of the computing node's environment from startup to business operation based on USBKEY and trusted enhanced BIOS, in order to establish the node's trusted state; The outer loop trusted verification module performs outer loop trusted verification, including the security control center authenticating the computing node that has passed the inner loop trusted verification, and issuing a security policy corresponding to the service to the computing node based on the trusted status of the node. The control and feedback module is used to control the computing nodes to execute the security policy during the execution of business operations, and to feed back dynamic trust information during business execution to the security management center in order to maintain the trust and controllability of the entire business process.

9. A network node trusted diffusion outer loop system based on a security control center, characterized in that, The system includes a security management center, a secure transmission platform, a trusted security proxy, a security policy library, and a log database; wherein: The security control center is used to generate system root certificates based on hardware cryptographic modules; receive registration requests from network computing nodes, verify their credentials and issue device digital certificates for them; and perform two-way certificate authentication with the trusted security agent through the secure transmission platform before establishing a connection with the network computing node. A secure transmission platform is used to establish an end-to-end encrypted communication link between the security control center and the trusted security agent based on national cryptographic algorithms; after two-way certificate authentication is completed, a session key is dynamically generated to ensure the independence and forward security of the communication. A trusted security agent is used to monitor the runtime behavior of the network computing nodes it resides in, collect security metrics and report them to the security management center through the secure transmission platform; receive and verify security policies issued by the security management center, and perform access control, process isolation and file permission management operations locally; when it detects behavior that deviates from the security baseline, it performs local blocking and reports it. The security policy library is used to store and manage security policy rules, including integrity metric baselines, mandatory access control rules, and abnormal behavior response mechanisms. The log database is used to record device certificates, trust status, authentication logs, and policy execution logs, and provides a visual display of the overall network trust status and security posture.

10. A trusted inner-loop trust chain diffusion system based on a USB key, characterized in that, The system includes a USB key and BIOS module, a USB key driver, a boot authentication module, a trusted boot module, and a runtime monitoring module; wherein: The USBKEY and BIOS module is used to form a hardware root of trust together with the USBKEY and the trust-enhanced BIOS, wherein the BIOS is set as a trust measurement root, and the USBKEY is set as a trust reporting root and a trust storage root; The USBKEY driver is used to encapsulate the interface for interacting with the USBKEY and to provide calling support for other modules, including the real-mode driver that works in the early stage of system startup and the operating system environment driver that works after the operating system is loaded. The power-on authentication module is used to verify the PIN code entered by the user and perform two-way authentication with the USBKEY, and allow the system to start after successful authentication; The trusted boot module is used to call the USBKEY to perform integrity measurement on the system kernel file and key components before loading the operating system kernel, and compare the measurement result with the baseline value stored in the USBKEY. The operating system will only continue to be loaded after the verification is successful. The monitoring module is used to generate an integrity benchmark library for critical system processes after the system's first trusted boot and to sign it using the certificate of the USBKEY; during system operation, it continuously monitors the integrity of critical processes and compares them with the integrity benchmark library.

Citation Information

Patent Citations

  • Internet safe payment method and system based on electronic contract

    CN101251915A

  • Validation using key pairs and interprocess communications

    US20200134598A1