Laboratory digital safety workspace management method, system and equipment based on trusted computing and medium
By using trusted computing technology to measure and perform multi-factor authentication on laboratory terminals, a secure workspace is dynamically created, and unalterable logs are generated in real time. This solves the problems of security isolation and policy adaptability in laboratory information systems, and realizes the trustworthiness of laboratory terminals and the traceability of data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD
- Filing Date
- 2026-01-27
- Publication Date
- 2026-05-05
AI Technical Summary
Existing laboratory information systems lack reliable security mechanisms, making digital security workspaces vulnerable to malware or unauthorized access. Insufficient security isolation between terminals and servers makes it impossible to effectively prevent data leakage and tampering. Security policies lack dynamic adaptability and are difficult to implement differentiated management.
It employs trusted computing technology, measures the startup chain through trusted hardware to achieve trusted verification of the terminal, and establishes an encrypted communication channel using a multi-factor authentication mechanism. It dynamically creates workspaces, monitors user behavior in real time, generates an immutable chain signature log, and supports enhanced authentication and hierarchical response for cross-domain transmission.
It ensures the trustworthiness of laboratory terminals, enables multi-tasking and secure isolation, supports differentiated access control, improves the ability to detect and respond to security incidents, and ensures the integrity and traceability of scientific research data.
Smart Images

Figure CN121980573A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of laboratory information security management technology, specifically to a method, system, equipment, and medium for managing laboratory digital security workspaces based on trusted computing. Background Technology
[0002] With the accelerated digital transformation of laboratory research activities, a large amount of experimental data, parameters, and research results are stored and transmitted in network environments. However, existing laboratory information systems generally suffer from the following problems: The lack of a reliable security mechanism makes the digital secure workspace access management system vulnerable to malware or unauthorized access. The laboratory terminals and servers lack sufficient security isolation, which cannot effectively prevent the leakage and tampering of experimental data; Workspace security policies lack dynamic adaptability and are difficult to differentiate based on different experimental tasks and personnel permissions.
[0003] Therefore, there is an urgent need for a laboratory digital security workspace management method and system that combines trusted computing technology to achieve trusted verification, dynamic isolation and security control of laboratory terminals and data, and to ensure the integrity and confidentiality of scientific research data and experimental processes.
[0004] This invention relates to the fields of information security management and laboratory digitization, specifically to a method and system for managing laboratory digital security workspaces based on trusted computing, applicable to scientific research laboratories, testing laboratories, and digital experimental environments involving sensitive data processing. Summary of the Invention
[0005] In view of the above-mentioned problems, the present invention is proposed.
[0006] Therefore, the technical problems solved by this invention are: the lack of a trusted root security mechanism makes the digital secure workspace access management system vulnerable to threats from malware or unauthorized access; insufficient security isolation between laboratory terminals and servers cannot effectively prevent the leakage and tampering of experimental data; and the lack of dynamic adaptability in the workspace security policy, making it difficult to achieve differentiated management based on different experimental tasks and personnel permissions.
[0007] To address the aforementioned technical problems, this invention provides the following technical solution: a laboratory digital security workspace management method based on trusted computing, comprising, The boot chain is measured using trusted hardware. Once verified, the measurement value is uploaded and the chain enters the authentication process. A multi-factor authentication mechanism is used to authenticate user identity, an encrypted communication channel is established, and policy compliance checks are performed on access attributes.
[0008] Workspaces are dynamically created based on experimental tasks and user identities to ensure that each task environment is independent and resources are isolated.
[0009] Security policies are dynamically loaded from the management center to the workspace.
[0010] Real-time monitoring of user terminal behavior and peripheral device access during workspace operation.
[0011] Enhanced authentication is performed during cross-domain transmission, and data verification and transmission are completed through a controlled encrypted channel.
[0012] The entire operation is recorded and a tamper-proof chain signature log is generated and centrally stored for auditing and analysis; Event reports are automatically generated based on logs and monitoring results, and tiered responses and joint actions are initiated to form a traceable chain of responsibility for determination.
[0013] As a preferred embodiment of the laboratory digital security workspace management method and system based on trusted computing described in this invention, the step of measuring the startup chain through trusted hardware includes: When the laboratory terminal is powered on or restarted, the trusted boot module calls the trusted platform module or equivalent security chip on the terminal hardware platform to complete the integrity measurement of the boot chain step by step, including the verification of the bootloader, operating system kernel, driver and application files.
[0014] Each level of measurement generates a corresponding hash value, which is compared with the trusted baseline value pre-stored in the trusted platform module. After the measurement is completed, a trusted measurement value is generated.
[0015] If the hash value generated by each level of measurement is the same as the trusted benchmark value pre-stored in the trusted platform module, it indicates a successful comparison, and the digital security workspace access management system determines that the laboratory terminal is in a trusted state.
[0016] If the hash value generated by any level of metric is different from the trusted baseline value pre-stored in the trusted platform module, it indicates that the comparison has failed. The digital security workspace access management system then enters a security isolation mode, prohibiting users from continuing to operate, and prompts the administrator to repair and re-verify.
[0017] As a preferred embodiment of the laboratory digital security workspace management method based on trusted computing described in this invention, the user identity authentication mechanism using a multi-factor authentication mechanism includes first-level verification, second-level verification, and third-level verification.
[0018] Level 1 verification requires the experimenter to enter their account password and pass it through local encryption verification.
[0019] Secondary verification involves collecting the biometric information of the experimenters and comparing it with the information reserved in the database.
[0020] Level 3 authentication involves calling the digital certificate stored in the user terminal or laboratory smart card to verify the public / private key pair.
[0021] Once the Level 1, Level 2, and Level 3 verifications are all successful, the digital secure workspace access management system calls the hardware security module to generate a one-time dynamic key and completes two-way identity verification through digital signature.
[0022] The policy compliance check on the access attributes includes, After two-way identity verification is completed, the digital secure workspace access management system establishes an encrypted channel based on TLS or IPSec protocol between the laboratory terminal and the security management center to verify whether the network address, access method and access time of the access laboratory terminal meet the preset specifications. If the access request does not meet the requirements, it will be rejected.
[0023] As a preferred embodiment of the laboratory digital security workspace management method based on trusted computing described in this invention, the dynamic creation of the workspace includes: Once user authentication is complete and access permission is granted, the digital secure workspace access management system initiates the secure workspace generation process through the workspace management module, based on the user's identity information and the type of experimental task applied for.
[0024] The workspace is built based on virtualization and containerization technologies.
[0025] As a preferred embodiment of the trusted computing-based laboratory digital security workspace management method of the present invention, wherein: the dynamic loading of security policies into the workspace includes, After the secure workspace is initialized, the security policy module automatically retrieves the security policy matching the user role and experimental task from the security management center, including: Data access permissions define the data directories and operational scope that experimenters can access in the workspace.
[0026] The application whitelist restricts the experimental software and analysis tools that can be run.
[0027] Peripheral access restrictions specify the types of peripherals that are allowed to be connected.
[0028] The network communication scope is defined as the range of network addresses that the workspace is allowed to access.
[0029] Cross-domain transfer control is a mechanism that triggers additional verification and controlled transfer when experimental tasks involve cross-laboratory data interaction.
[0030] If the policy fails to load or is tampered with, the Digital Secure Workspace Access Management System will immediately suspend the task execution and prompt the administrator to check.
[0031] As a preferred embodiment of the trusted computing-based laboratory digital security workspace management method of the present invention, wherein: the enhanced authentication during cross-domain transmission includes, When researchers need to access or share data between different experimental domains, the Digital Secure Workspace Access Management System automatically activates cross-domain transmission control mechanisms, including... Two-factor authentication is triggered, requiring the user to reconfirm their identity. After successful authentication, data transmission from the cloud terminal to the server must be conducted through a controlled encrypted channel. The transmitted content is encrypted before transmission and an integrity check code is attached.
[0032] The digital secure workspace access management system monitors the transmission frequency in real time. When the transmission frequency exceeds the threshold, an alarm is triggered and the transmission channel is temporarily frozen.
[0033] As a preferred embodiment of the laboratory digital security workspace management method based on trusted computing described in this invention, the generation of the tamper-proof chained signature log includes: Throughout the lifecycle of the safe workspace, all operational behaviors are recorded and chained log entries are generated.
[0034] Log entries are linked by hash pointers and include timestamps and digital signatures.
[0035] Audit logs are stored in a trusted log library, which can be retrieved by the security management center for unified analysis and tracing.
[0036] The activation of tiered response and joint handling includes, When a security incident occurs, the security management center automatically generates an incident report based on audit logs and monitoring results.
[0037] Implement tiered response measures based on the report, including local isolation, network blocking, policy escalation, or cross-domain joint handling.
[0038] Establish a traceable safety disposal chain for laboratory compliance verification and liability determination.
[0039] This invention provides a laboratory digital safety workspace management system based on trusted computing.
[0040] To address the aforementioned technical problems, this invention provides the following technical solution: a system for managing a laboratory digital security workspace based on trusted computing, comprising: a trusted startup module, an identity authentication and secure access module, a workspace management module, a security policy module, a trusted monitoring module, and a security audit module. The Trusted Boot Module is used to invoke the Trusted Platform Module to perform integrity measurements on the bootloader, operating system kernel, drivers, and applications and generate trusted measurement values when the laboratory terminal is powered on or started.
[0041] The identity authentication and secure access module is used to authenticate the experimenters based on a multi-factor authentication method, and establish an encrypted communication channel based on TLS or IPSec after successful authentication to enable trusted access between the experimenters and the terminal, while verifying the access time, access method and network location.
[0042] The workspace management module is used to create, destroy, and isolate secure workspaces within laboratory terminals using virtualization and containerization technologies.
[0043] The security policy module is used to load and issue differentiated access control policies based on user identity and task type, and supports dynamic policy adjustments.
[0044] The trusted monitoring module is used to monitor system calls, process behavior, network communication and peripheral device access in real time during the operation of the secure workspace, and to perform isolation and alarm when an anomaly is detected.
[0045] The security audit module is used to generate chained logs and store them in a trusted log library to implement operational behaviors.
[0046] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor executes the computer program to implement the steps of the laboratory digital security workspace management method based on trusted computing.
[0047] The present invention provides a computer-readable storage medium having a computer program stored thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the laboratory digital security workspace management method based on trusted computing.
[0048] The beneficial effects of this invention are as follows: the laboratory terminal verification mechanism based on trusted computing ensures the trustworthiness of the system operating environment; the containerized digital workspace isolation mechanism realizes multi-task parallelism and secure isolation, avoiding data leakage and cross-contamination; it supports differentiated security policies based on user identity and experimental tasks, achieving fine-grained access control; it provides real-time monitoring and anomaly handling functions, improving the detection and response capabilities of laboratory safety incidents; and it establishes an immutable audit log library, realizing the traceability and accountability of scientific research data operations. Attached Figure Description
[0049] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0050] Figure 1 The above is a flowchart of a trusted computing-based laboratory digital security workspace management method provided in one embodiment of the present invention.
[0051] Figure 2 This is an overall framework diagram of a trusted computing-based laboratory digital safe workspace management system provided as an embodiment of the present invention. Detailed Implementation
[0052] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0053] Example 1, referring to Figure 1 This is one embodiment of the present invention, which provides a laboratory digital security workspace management method based on trusted computing, including: S1. Measure the boot chain through trusted hardware, upload the measurement value after successful verification and enter the authentication process.
[0054] Furthermore, measuring the boot chain through trusted hardware includes, When the laboratory terminal is powered on or restarted, the trusted boot module calls the trusted platform module or equivalent security chip on the terminal hardware platform to complete the integrity measurement of the boot chain step by step, including the verification of the bootloader, operating system kernel, driver and application files.
[0055] Each level of measurement generates a corresponding hash value, which is compared with the trusted baseline value pre-stored in the trusted platform module. After the measurement is completed, a trusted measurement value is generated.
[0056] Content used in credibility metrics: 1. As the core credential (part of the identity) for terminal network access authentication, the trust metric serves as proof of "device health status". When the laboratory terminal completes startup and attempts to access the laboratory digital security workspace system, the client agent on the terminal will send a request to the TPM to obtain the current value of the specified PCR register (i.e., the trust metric).
[0057] 2. As a key basis for access control decisions (dynamic trust assessment), the security management center verifies the trust measurement report after receiving it and makes access decisions accordingly.
[0058] 3. Implement dynamic, fine-grained access authorization. Based on trust metrics, the system can grant different levels of permissions.
[0059] 4. Provides irrefutable security audit evidence. The verification results of all trust measurement reports are recorded in detail in the audit log. In the event of a security incident, the exact security status of a specific terminal at a specific point in time can be traced back, providing cryptographic-level, unforgeable ironclad evidence for incident investigation.
[0060] If the hash value generated by each level of measurement is the same as the trusted benchmark value pre-stored in the trusted platform module, it indicates a successful comparison, and the digital security workspace access management system determines that the laboratory terminal is in a trusted state.
[0061] If the hash value generated by any level metric is different from the trusted baseline value pre-stored in the trusted platform module, it indicates a comparison failure. The digital security workspace access management system then enters a security isolation mode, prohibiting users from continuing operations. At the same time, the administrator is prompted to repair and re-verify to ensure the security and reliability of the subsequent operating environment.
[0062] S2. Employ a multi-factor authentication mechanism to authenticate user identity, establish an encrypted communication channel, and perform policy compliance checks on access attributes.
[0063] The multi-factor authentication mechanism for authenticating user identity includes Level 1 verification, Level 2 verification, and Level 3 verification. Level 1 verification requires the experimenter to enter their account password and pass it through local encryption verification.
[0064] Secondary verification involves collecting biometric information of the experimenters, such as fingerprints, iris scans, or facial recognition, and comparing it with pre-reserved information in the database.
[0065] Level 3 authentication involves calling the digital certificate stored in the user terminal or laboratory smart card to verify the public / private key pair.
[0066] Once the Level 1, Level 2, and Level 3 verifications are all successful, the digital secure workspace access management system calls the hardware security module to generate a one-time dynamic key and completes two-way identity verification through digital signature.
[0067] The policy compliance check on the access attributes includes, After two-way identity verification is completed, the digital secure workspace access management system establishes an encrypted channel based on TLS or IPSec protocol between the laboratory terminal and the security management center to verify whether the network address, access method and access time of the access laboratory terminal meet the preset specifications. If the access request does not meet the requirements, it will be rejected.
[0068] The pre-defined specifications comprise the key security capabilities of the Digital Secure Workspace Access Management System, ensuring that only the correct users, at the correct time, using the correct devices, from the correct location, and in the correct manner, can access protected laboratory resources. If any step deviates from the pre-defined policy, the connection will be denied.
[0069] 1. Network address (IP address / address range) Static IP whitelist: Only allows terminals from one or more specific public or private network IP addresses to access the network.
[0070] IP range: Allows terminals from a single IP network segment to access the network.
[0071] VPN or specific gateway IP: Requires users to first connect to a specific VPN or specific network gateway, and then initiate a connection from the IP address of that gateway.
[0072] 2. Access time Working hours: Access is only allowed during the preset working hours. Access requests outside of working hours will be rejected.
[0073] Date restrictions: Set fine-grained rules to allow access during weekend overtime but not during statutory holidays.
[0074] Session timeout and idle disconnection: Set to automatically disconnect the encrypted channel after 5 minutes of user inactivity, requiring re-authentication and verification.
[0075] Encrypted channels based on TLS or IPSec protocols are capable of resisting man-in-the-middle attacks and replay attacks. Simultaneously, the system verifies whether the network address, access method, and access time of the access terminal conform to preset specifications; access requests that do not meet the requirements will be rejected, thereby ensuring the trustworthiness of the laboratory network access points.
[0076] S3. Dynamically create workspaces based on experimental tasks and user identities to ensure that each task environment is independent and resources are isolated.
[0077] Dynamically creating workspaces includes, Once user authentication is complete and access permission is granted, the digital secure workspace access management system initiates the secure workspace generation process through the workspace management module, based on the user's identity information and the type of experimental task applied for.
[0078] The workspace is built using virtualization and containerization technologies, possessing a completely independent file system, process space, and network stack, thus isolating it from the host system. If an experimenter undertakes multiple experimental tasks, the system will simultaneously generate multiple corresponding workspace instances, each running independently with data and operations free from interference, preventing cross-contamination. In core technology prototype development scenarios (algorithm design, design drawings, experimental results), the digital secure workspace access management system further enhances security by adding a file system sandbox and mandatory access control mechanisms on top of container isolation. This hierarchical isolation design ensures both efficient utilization of system resources and guarantees data independence and reliable operation between tasks. S4. Dynamically load security policies from the management center to the workspace.
[0079] Dynamically loading security policies into the workspace includes, After the secure workspace is initialized, the security policy module automatically retrieves the security policy matching the user role and experimental task from the security management center, including: Data access permissions define the data directories and operational scope (read-only, read-write, etc.) that experimenters can access in the workspace.
[0080] The application whitelist restricts the experimental software and analysis tools that can be run, preventing malicious or unauthorized programs from executing.
[0081] Peripheral access restrictions specify the types of peripherals that are allowed to be connected. For example, some experimental tasks allow printers to be connected, but prohibit mobile storage devices.
[0082] The network communication scope is limited to the range of network addresses that the workspace is allowed to access, avoiding arbitrary external connections.
[0083] Cross-domain transfer control triggers additional verification and controlled transfer mechanisms when experimental tasks involve cross-laboratory data interaction, i.e., enhanced authentication during cross-domain transfers in S6.
[0084] Furthermore, when the experimental task phase changes (e.g., from sample data acquisition to results analysis), the digital secure workspace access management system will automatically issue new policy configurations based on the task characteristics, thereby ensuring that different phases comply with laboratory safety regulations. If the policy loading fails or is tampered with, the system will immediately suspend task execution and prompt the administrator to check.
[0085] S5. Real-time monitoring of user terminal behavior and peripheral device access during workspace operation.
[0086] Furthermore, during normal operation of the workspace, the trusted monitoring module continues to function, performing real-time measurement and monitoring of system calls, process behavior, and external communication requests, including: System call monitoring records and verifies critical API calls to prevent malware injection or tampering with system calls.
[0087] Process behavior analysis is used to detect abnormally high-frequency operations, memory out-of-bounds access, or unauthorized process startup.
[0088] Network communication detection ensures that external communication complies with security policy limits through protocol parsing and traffic analysis, and immediately blocks any abnormal data packets detected.
[0089] Peripheral access control detects access to USB, Bluetooth, and serial devices, and blocks any unauthorized devices.
[0090] When an abnormal call, unauthorized process, or malicious data packet is detected, the system will immediately trigger an alarm and take measures such as isolation, freezing, or shutdown of the workspace. The incident information will also be reported to the security management center for unified response coordination.
[0091] S6. Enhanced authentication is performed during cross-domain transmission, and data verification and transmission are completed through a controlled encrypted channel; Enhanced authentication during cross-domain transmission includes, When researchers need to access or share data between different experimental domains, the Digital Secure Workspace Access Management System automatically activates cross-domain transmission control mechanisms, including... Two-factor authentication is triggered, requiring the user to reconfirm their identity. After successful authentication, data transmission from the cloud terminal to the server must be conducted through a controlled encrypted channel. The transmitted content is encrypted before transmission and an integrity check code is attached.
[0092] The digital secure workspace access management system monitors the transmission frequency in real time. When the transmission frequency exceeds the threshold, an alarm is triggered and the transmission channel is temporarily frozen to prevent large-scale data leakage or abnormal transmission.
[0093] S7. Record all operations and generate tamper-proof chained signature logs, which are centrally stored for auditing and analysis.
[0094] Generating a tamper-proof chained signature log includes, Throughout the lifecycle of the safe workspace, all operational behaviors are recorded and chained log entries are generated.
[0095] Log entries are linked by hash pointers and include timestamps and digital signatures.
[0096] Audit logs are stored in a trusted log library, which can be retrieved by the security management center for unified analysis and tracing. S8. Automatically generate event reports based on logs and monitoring results, initiate tiered responses and joint handling, and form a traceable chain of responsibility determination.
[0097] Initiating tiered response and joint handling includes, When a security incident occurs, the security management center automatically generates an incident report based on audit logs and monitoring results.
[0098] Implement tiered response measures based on the report, including local isolation, network blocking, policy escalation, or cross-domain joint handling.
[0099] Establish a traceable safety disposal chain for laboratory compliance verification and liability determination.
[0100] Example 2, refer to Figure 2 This embodiment of the present invention provides a system for managing a laboratory digital security workspace based on trusted computing, comprising: a trusted startup module, an identity authentication and secure access module, a workspace management module, a security policy module, a trusted monitoring module, and a security audit module.
[0101] The Trusted Boot Module is used to invoke the Trusted Platform Module to perform integrity measurements on the bootloader, operating system kernel, drivers, and applications and generate trusted measurement values when the laboratory terminal is powered on or started.
[0102] The identity authentication and secure access module is used to authenticate the experimenters based on a multi-factor authentication method, and establish an encrypted communication channel based on TLS or IPSec after successful authentication to enable trusted access between the experimenters and the terminal, while verifying the access time, access method and network location.
[0103] The workspace management module is used to create, destroy, and isolate secure workspaces within laboratory terminals using virtualization and containerization technologies.
[0104] The security policy module is used to load and issue differentiated access control policies based on user identity and task type, and supports dynamic policy adjustments.
[0105] The trusted monitoring module is used to monitor system calls, process behavior, network communication and peripheral device access in real time during the operation of the secure workspace, and to perform isolation and alarm when an anomaly is detected.
[0106] The security audit module is used to generate chained logs and store them in a trusted log library to implement operational behaviors.
[0107] This embodiment also provides an electronic device applicable to the trusted computing-based laboratory digital safe workspace management method, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the trusted computing-based laboratory digital safe workspace management method proposed in the above embodiment.
[0108] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the laboratory digital safety workspace management method based on trusted computing as proposed in the above embodiments.
[0109] The storage medium proposed in this embodiment and the method for implementing a trusted computing-based laboratory digital security workspace management proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0110] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0111] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A laboratory digital security workspace management method based on trusted computing, characterized in that: include, The boot chain is measured using trusted hardware. Once verified, the measurement value is uploaded and the chain enters the authentication process. A multi-factor authentication mechanism is used to authenticate user identity, an encrypted communication channel is established, and policy compliance checks are performed on access attributes. Workspaces are dynamically created based on experimental tasks and user identities to ensure that each task environment is independent and resources are isolated. Dynamically load security policies from the management center to the workspace; Real-time monitoring of user terminal behavior and peripheral device access during workspace operation; Enhanced authentication is performed during cross-domain transmission, and data verification and transmission are completed through a controlled encrypted channel; The entire operation is recorded and a tamper-proof chain signature log is generated and centrally stored for auditing and analysis; Event reports are automatically generated based on logs and monitoring results, and tiered responses and joint actions are initiated to form a traceable chain of responsibility for determination.
2. The laboratory digital security workspace management method based on trusted computing as described in claim 1, characterized in that: The measurement of the boot chain via trusted hardware includes, When the laboratory terminal is powered on or restarted, the trusted boot module calls the trusted platform module or equivalent security chip on the terminal hardware platform to complete the integrity measurement of the boot chain step by step, including the verification of the bootloader, operating system kernel, driver and application files. Each level of measurement generates a corresponding hash value, which is compared with the trusted baseline value pre-stored in the trusted platform module. After the measurement is completed, a trusted measurement value is generated. If the hash value generated by each level of measurement is the same as the trusted benchmark value pre-stored in the trusted platform module, it indicates that the comparison is successful, and the digital security workspace access management system determines that the laboratory terminal is in a trusted state. If the hash value generated by any level of metric is different from the trusted baseline value pre-stored in the trusted platform module, it indicates that the comparison has failed. The digital security workspace access management system then enters a security isolation mode, prohibiting users from continuing to operate, and prompts the administrator to repair and re-verify.
3. The laboratory digital security workspace management method based on trusted computing as described in claim 2, characterized in that: The multi-factor authentication mechanism for authenticating user identity includes Level 1 verification, Level 2 verification, and Level 3 verification. Level 1 verification requires experimenters to enter their account password and pass it through local encryption verification. Secondary verification involves collecting the biometric information of the experimenters and comparing it with the information reserved in the database; Level 3 authentication involves calling the digital certificate stored in the user terminal or laboratory smart card to complete the verification of the public / private key pair; Once the Level 1, Level 2, and Level 3 verifications are all passed, the digital secure workspace access management system calls the hardware security module to generate a one-time dynamic key and completes two-way identity verification through digital signature. The policy compliance check on the access attributes includes, After two-way identity verification is completed, the digital secure workspace access management system establishes an encrypted channel based on TLS or IPSec protocol between the laboratory terminal and the security management center to verify whether the network address, access method and access time of the access laboratory terminal meet the preset specifications. If the access request does not meet the requirements, it will be rejected.
4. The laboratory digital security workspace management method based on trusted computing as described in claim 3, characterized in that: The dynamically created workspace includes, Once user authentication is complete and access permission is granted, the digital secure workspace access management system initiates the secure workspace generation process through the workspace management module, based on the user's identity information and the type of experimental task applied for. The workspace is built based on virtualization and containerization technologies.
5. The laboratory digital security workspace management method based on trusted computing as described in claim 4, characterized in that: The dynamic loading of security policies into the workspace includes, After the secure workspace is initialized, the security policy module automatically retrieves the security policy matching the user role and experimental task from the security management center, including: Data access permissions define the data directories and operational scope that experimenters can access in the workspace; The application whitelist restricts the experimental software and analysis tools that can be run. Peripheral access restrictions are defined to specify the types of peripherals that are allowed to be connected; The network communication scope is limited to the range of network addresses that the workspace is allowed to access; Cross-domain transfer control is a mechanism that triggers additional verification and controlled transfer when experimental tasks involve cross-laboratory data interaction; If the policy fails to load or is tampered with, the Digital Secure Workspace Access Management System will immediately suspend the task execution and prompt the administrator to check.
6. The laboratory digital security workspace management method based on trusted computing as described in claim 4, characterized in that: The enhanced authentication during cross-domain transmission includes, When researchers need to access or share data between different experimental domains, the Digital Secure Workspace Access Management System automatically activates cross-domain transmission control mechanisms, including... Triggering two-factor authentication requires the user to reconfirm their identity. After successful verification, data transmission from the cloud terminal to the server must be conducted through a controlled encrypted channel. The transmitted content is encrypted before transmission and an integrity check code is attached. The digital secure workspace access management system monitors the transmission frequency in real time. When the transmission frequency exceeds the threshold, an alarm is triggered and the transmission channel is temporarily frozen.
7. The laboratory digital security workspace management method based on trusted computing as described in claim 4, characterized in that: The generation of the tamper-proof chained signature log includes, Throughout the lifecycle of the safe workspace, all operational behaviors are recorded and chained log entries are generated; Log entries are linked together using hash pointers and include timestamps and digital signatures; Audit logs are stored in a trusted log library, which can be retrieved by the security management center for unified analysis and tracing. The activation of tiered response and joint handling includes, When a security incident occurs, the security management center automatically generates an incident report based on audit logs and monitoring results; Implement tiered response measures based on the report, including local isolation, network blocking, policy escalation, or cross-domain joint handling; Establish a traceable safety disposal chain for laboratory compliance verification and liability determination.
8. A laboratory digital safety workspace management system based on trusted computing, employing the laboratory digital safety workspace management method based on trusted computing as described in any one of claims 1 to 7, characterized in that, include: Trusted boot module, identity authentication and secure access module, workspace management module, security policy module, trusted monitoring module, and security audit module. The Trusted Boot Module is used to invoke the Trusted Platform Module to perform integrity measurements on the bootloader, operating system kernel, drivers, and applications and generate trusted measurement values when the laboratory terminal is powered on or started. The identity authentication and secure access module is used to authenticate the identity of the experimenters based on a multi-factor authentication method, and establish an encrypted communication channel based on TLS or IPSec after successful authentication to realize trusted access between the experimenters and the terminal, while verifying the access time, access method and network location. The workspace management module is used to create, destroy, and isolate secure workspaces within laboratory terminals using virtualization and containerization technologies. The security policy module is used to load and issue differentiated access control policies based on user identity and task type, and supports dynamic policy adjustment; The trusted monitoring module is used to monitor system calls, process behavior, network communication and peripheral device access in real time during the operation of the secure workspace, and to perform isolation and alarm when an anomaly is detected; The security audit module is used to generate chained logs and store them in a trusted log library to implement operational behaviors.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the laboratory digital security workspace management method based on trusted computing as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the laboratory digital security workspace management method based on trusted computing as described in any one of claims 1 to 7.