Reliable Measurement Method, Apparatus, Computer Device, and Readable Medium

By offloading cloud platform components to a control daughter card and using intelligent network cards for virtualization software isolation, the solution addresses performance and security issues in cloud computing platforms, ensuring reliable measurement and secure resource utilization.

JP7709607B2Active Publication Date: 2025-07-16ZTE CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024522336
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-10-12
Filing Date
2022-10-12
Publication Date
2025-07-16
Estimated Expiration
2042-10-12

AI Technical Summary

Technical Problem

Cloud computing platforms face performance loss and security risks due to the deployment of cloud platform management programs and service virtual machines on the same server, necessitating a solution for reliable measurement and isolation of computing resources.

Method used

Offloading cloud platform control, computing, and storage modules to a control daughter card, using intelligent network cards for virtualization software isolation, and implementing a reliable measurement method to ensure zero performance interference and secure resource utilization.

Benefits of technology

Ensures zero performance loss and enhanced security by isolating virtual machines from physical resources, allowing for reliable measurement and management of computing servers, thereby maintaining server performance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709607000001
    Figure 0007709607000001
  • Figure 0007709607000002
    Figure 0007709607000002
  • Figure 0007709607000003
    Figure 0007709607000003
Patent Text Reader

Abstract

The present application provides a trusted measurement method, in which, when a trusted measurement device performs a trusted boot, the method connects to a computing server to identify a boot mode of a first boot loader program of the computing server, and in response to the first boot loader program being in a trusted boot mode, obtains a first group of trusted measurement results stored in the computing server, and in response to the first group of trusted measurement results being identical to a pre-stored first group of trusted measurement expected values, the method identifies that the computing server has performed a trusted boot, and the first group of trusted measurement expected values ​​are transmitted to the trusted measurement device by a security supervision control server. The present application further provides a trusted measurement device, a computer device, and a readable medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] [Cross - reference to Related Applications] This application claims priority to Chinese Patent Application No. CN202111186512.8, titled "Reliable Measurement Method, Apparatus, Computer Device, and Readable Medium", filed on October 12, 2021, and incorporates all of its contents herein by reference. [Technical Field] This application relates to the field of cloud computing technology, and more specifically, to a reliable measurement method, apparatus, computer device, and readable medium.

Background Art

[0002] Cloud computing uses a virtualization layer to uniformly manage and shield the underlying layer hardware, provides computing services to users according to demand, realizes resource sharing, and improves resource utilization. However, the cloud platform management program is deployed on the server, which generally causes loss of server performance. In addition, the cloud platform management program and the service virtual machine are deployed on the same server and are not physically isolated, resulting in security risks.

[0003] To solve the above problems, a pioneering solution in the industry is to offload modules such as cloud platform control, computing, network, and storage from the server to the control daughter card, realizing zero loss of server performance and making all the computing capabilities of the physical machine available for use by the user's virtual machine. When the virtualization software is offloaded to the intelligent network card, it is completely isolated from the user's computing resources, ensuring zero performance interference. In such a situation, how to effectively monitor the reliable measurement of the computing server to ensure the security and reliability of the entire cloud platform has become an issue that needs to be solved.

Summary of the Invention

Means for Solving the Problems

[0004] This application provides a reliable measurement method, apparatus, computer device, and readable medium.

[0005] In a first aspect, an embodiment of this application provides a reliable measurement method applicable to a reliable measurement apparatus. The method includes: when the reliable measurement apparatus starts up reliably, connecting to a computing server and specifying a startup mode of a first bootloader program of the computing server; in response to the first bootloader program being in a reliable boot mode, obtaining a first group of reliable measurement results stored in the computing server; and in response to the first group of reliable measurement results being the same as a first group of pre-stored reliable measurement expected values, specifying that the computing server has started up reliably, where the first group of reliable measurement expected values are transmitted to the reliable measurement apparatus by a security overall control server.

[0006] In a further aspect, the embodiment of the present application further provides a reliable measurement device comprising a first communication module and a first processing module. When the reliable measurement device is reliably started, the first communication module is used to connect to a computing server and obtain a first group of reliable measurement results stored in the computing server. The first processing module is used to identify the startup mode of a first bootloader program of the computing server. When the first bootloader program is in a reliable boot mode, the first communication module is instructed to obtain a first group of reliable measurement results stored in the computing server. In response to the first group of reliable measurement results being the same as a first group of pre-stored reliable measurement expected values, it is used to identify that the computing server has been reliably started. The first group of reliable measurement expected values are transmitted to the reliable measurement device by a security master control server.

[0007] In a further aspect, the embodiment of the present application further provides a computer device comprising one or more processors and a storage device storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the reliable measurement method described above.

[0008] In a further aspect, the embodiment of the present application further provides a computer-readable medium storing a computer program. When the computer program is executed, the processor is caused to implement the reliable measurement method described above.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0010] Hereinafter, exemplary embodiments will be described in more detail with reference to the drawings. However, the exemplary embodiments may be embodied in different forms and should not be construed as being limited to the embodiments described herein. Rather, these embodiments are provided to make the present application detailed and complete, and to fully enable those skilled in the art to understand the scope of the present application.

[0011] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0012] The terms used in this specification are used only for the purpose of describing specific embodiments and are not intended to limit the present application. The singular terms "one" and "said" used in this specification are intended to include the plural as well, unless the context clearly indicates otherwise. Furthermore, when the terms "comprising" and / or "consisting of" are used in this specification, they indicate the presence of the said features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof.

[0013] The embodiments described in this specification can be described with reference to the plan view and / or cross-sectional view according to the ideal schematic diagram of the present application. Therefore, the exemplary drawings can be modified according to the manufacturing technology and / or tolerance. For this reason, the embodiments are not limited to the embodiments shown in the drawings and include modifications to the arrangements formed by the manufacturing process. Therefore, the exemplary regions in the drawings have schematic attributes, and the shapes of the regions shown in the drawings illustrate the specific shapes of the regions of the elements, but are not limiting.

[0014] Unless otherwise limited, the meanings of all terms (including technical and scientific terms) used in this specification are the same as those generally understood by those skilled in the art. Furthermore, these terms defined in a general dictionary should be interpreted as having meanings consistent with their meanings in the context of the related technology and the present application, and should not be interpreted as having idealized or overly formal meanings unless clearly limited as such in this specification.

[0015] The reliable measurement method provided by the embodiments of the present application can be applied to the system as shown in FIG. 1.

[0016] As shown in FIG. 1, the system includes a reliable measurement device 1, a computing server 2, and a security overall control server 3. The reliable measurement device 1 is a controlled daughter card, which is connected to the computing server 2 using a peripheral bus interface and is connected to the security overall control server 3 via a security network encrypted with a digital certificate. The reliable measurement device 1 includes a CPU (Central Processing Unit), an internal memory, an operating system, and a security measurement module. The peripheral bus interface may include, but is not limited to, a network interface, a PCI (Peripheral Component Interconnect) interface, a PCIE (peripheral component interconnect express) interface, an SPI (Serial Peripheral Interface), an I2C (Inter-Integrated Circuit) interface, an SCSI (Small Computer System Interface), etc. The computing server 2 is a physical server that provides computing resources (CPU, internal memory, storage, network, etc.) to virtual machines. The computing resources it provides may be attached to its own board card or provided by various buses or networks. Both the computing server 2 and the reliable measurement device 1 are equipped with their own hardware security measurement modules. The security measurement module includes, but is not limited to, a passive measurement security chip (TPM) or an active measurement security chip (TCM, TPCM board card, etc.) commonly used in the industry. The security measurement module incorporates a trust basis and cryptographic algorithms and can perform static or dynamic measurements on the entire system.As the basis of trust for the entire cloud platform, the security control server 3 stores all the reliable measurement devices 1, computing servers 2, and reliable measurement expected values of virtual machines that can be trusted.

[0017] The reliable measurement device 1 is equipped with a virtualization control module and a cloud platform control proxy module. The virtualization control module is a program resident in the reliable measurement device 1, which connects to the virtualization control proxy module in the computing server 2 via a peripheral interface channel, and can convert the instructions related to the virtualization management of the security control server 3 according to the type and configuration information of the computing server 2. The virtualization control proxy module realizes the monitoring of the reliable measurement process of the computing server 2 and the virtual machine, controls the life cycle of the virtual machine, and connects to the power management module through a dedicated line such as IPMI (Intelligent Platform Management Interface) to control the power state of the computing server 2. The cloud platform control proxy module is a program resident in the reliable measurement device 1, which can perform reliable measurements dynamically with the startup of the reliable measurement device 1. After authentication with a digital certificate, the cloud platform control proxy module receives and stores the reliable measurement expected values of the reliable measurement device 1, the computing server 2, and the virtual machine operating therein sent by the security control server 3 via an encrypted security network. The reliable measurement expected value is encrypted with the unique private key of the security control server 3 and stored in the security measurement module of the reliable measurement device 1. When used, it can be decrypted using the public key of the digital certificate of the security control server 3 to prevent tampering.

[0018] The computing server 2 is equipped with a virtualization control proxy module and a virtual machine monitor (VMM). The virtualization control proxy module is a program resident in the computing server 2, capable of making reliable measurements upon the startup of the computing server 2, and communicating with the virtualization control module in the reliable measurement device 1 through a peripheral bus interface. The virtual machine monitor, also known as a hypervisor, is software, firmware, or hardware used for the construction and execution of virtual machines, and can access the operating system inside the virtual machine through the virtio channel technology to execute corresponding instructions.

[0019] As shown in Figure 2, the reliable measurement method provided by the embodiments of the present application can be applied to a reliable measurement device, and the method includes the following steps S21 to S23.

[0020] Step 21, when the reliable measurement device performs a reliable startup, connect to the computing server and identify the startup mode of the first bootloader program of the computing server.

[0021] The reliable measurement device 1 and the computing server 2 are successively powered on. During the startup process, the reliable measurement device 1 and the computing server 2 respectively perform reliable boots through their own security measurement modules. The reliable measurement device 1 completes the dynamic measurement of its bootloader (bootloader program), operating system, virtualization control module, and cloud platform proxy module. The computing server 2 completes the dynamic measurement of its bootloader, operating system, and virtualization control proxy module.

[0022] In this step, after the reliable measurement device 1 has been reliably started, the virtualization control module therein connects, via the hardware channel, to the virtualization control proxy module operating on the computing server 2, and the virtualization control proxy module executes an inquiry command related to the security measurement module to determine whether the startup mode of the bootloader of the computing server 2 (i.e., the first bootloader program) is a reliable startup mode.

[0023] Step 22, in response to the first bootloader program being in a reliable boot mode, obtain the first group of reliable measurement results stored in the computing server.

[0024] In this step, if the reliable measurement device 1 determines that the first bootloader program is in a reliable boot mode, the virtualization control module of the reliable measurement device 1 reads, via the virtualization control proxy module of the computing server 2, the measurement results (i.e., the first group of reliable measurement results) stored in the PCR (Platform Configuration Register) of the security measurement module in the computing server 2. The first group of reliable measurement results includes multiple measurement values such as, for example, the measurement value of the security measurement module and the measurement value of the virtualization control proxy module.

[0025] Step 23 is a step of determining that the computing server has been reliably started in response to the first group of reliable measurement results being the same as the pre-stored first group of reliable measurement expected values, where the first group of reliable measurement expected values are sent by the security overall control server to the reliable measurement device.

[0026] In this step, the reliable measuring device 1 compares each measured value in the reliable measurement results of the first group with each expected value in the pre-stored reliable measurement expected values of the first group. If each measured value is identical to the corresponding expected value respectively, the computing server 2 determines that it is a reliable startup.

[0027] The security overall control server 3 transmits in advance the reliable measurement expected values of the reliable measuring device 1 and the reliable measurement expected values of the computing server 2 (that is, the reliable measurement expected values of the first group) to the reliable measuring device 1 via an encrypted network. In some embodiments, the reliable measurement expected values may be transmitted in response to a spontaneous request of the reliable measuring device 1. The reliable measurement expected values may be transmitted via an encrypted network authenticated by a digital certificate and encrypted and stored in the security measurement module of the reliable measuring device 1, and decrypted using the public key of the digital certificate of the security overall control server 3 during use.

[0028] The reliable measurement method provided by the embodiments of the present application can be applied to a reliable measurement device. The method includes: when the reliable measurement device starts up reliably, connecting to a computing server and identifying the startup mode of the first bootloader program of the computing server; in response to the first bootloader program being in a reliable boot mode, obtaining a first group of reliable measurement results stored in the computing server; and in response to the first group of reliable measurement results being the same as a first group of pre-stored reliable measurement expected values, identifying that the computing server has started up reliably, wherein the first group of reliable measurement expected values are sent by a security management control server to the reliable measurement device. The embodiments of the present application send the first group of reliable measurement expected values to the reliable measurement device by the security management control server. After the reliable measurement device locally caches the first group of reliable measurement expected values, dynamic measurement monitoring is further performed on the reliable startup process of the computing server. Therefore, the security management control server does not need to be always online and has a low possibility of being invaded or attacked. Since the embodiments of the present application offload the functions of reliable measurement monitoring and security management from the computing server to the reliable measurement device to the greatest extent, reliable measurement does not occupy computing resources, can not only implement security management control, but also leave the computing resources to the greatest extent.

[0029] In some embodiments, as shown in FIG. 3, after obtaining the first group of reliable measurement results stored in the computing server (i.e., step 22), the method further includes the following step S23'.

[0030] S23': Execute a first security management control policy in response to at least one of the first group of reliable measurement results being different from at least one of the first group of reliable measurement expected values.

[0031] If the reliable measurement results of the first group are not exactly the same as the reliable measurement expected values of the first group cached in the reliable measurement device 1, it may indicate that the computing server 2 has been illegally tampered with, or the operating system and software of the computing server 2 need to be updated and upgraded, or the measurement range of the computing server 2 needs to be adjusted. In such a case, the preset security management control policy is executed.

[0032] In some embodiments, the first security management control policy includes at least one of sending a first security warning to a preset server, instructing the computing server to upgrade the operating system of the computing server, and instructing the computing server to adjust the reliable measurement range of the computing server.

[0033] Note that the preset server that receives the first security warning may be the security general control server 3, or may be other cloud servers.

[0034] In some embodiments, when the reliable measurement device 1 starts up reliably, the reliable measurement method further includes executing a second security management control policy in response to meeting a preset first condition. The preset first condition includes at least one of exceeding a preset first time length and not successfully connecting to the computing server, not obtaining the reliable measurement results of the first group stored in the computing server, the number of reliable measurement results of the first group being less than the number of reliable measurement expected values of the first group, and the first bootloader program not being in a reliable boot mode.

[0035] In some embodiments, if the reliable startup of the computing server 2 is incomplete, or the virtualization control module of the reliable measurement device 1 times out and cannot connect to the virtualization control proxy module of the computing server 2, or the reliable measurement device 1 cannot read the measurement results (i.e., the first group of reliable measurement results) in the security measurement module of the computing server 2 by the virtualization control proxy module, the reliable measurement device 1 can execute a pre-set second security management control policy. If the reliable measurement device 1 determines that the number of the first group of reliable measurement results is less than the number of the first group of reliable measurement expected values, it indicates that the reliable startup of the computing server 2 is incomplete.

[0036] In some embodiments, the second security management control policy includes at least one of sending a second security warning to a pre-set server and instructing the computing server to shut down and lock the startup.

[0037] Note that the pre-set server that receives the second security warning may be the security general control server 3, or may be other cloud servers. When instructing the computing server 2 to shut down and lock the startup, the reliable measurement device 1 shuts down the computing server 2 through the power management module of the computing server 2 to lock the startup of the computing server 2.

[0038] In a scenario where the cloud computing control plane and computing resources are separated, virtual machines are deployed on computing servers, and the computing servers are merely resource providers and do not have reliable certificates and sufficient information to uniformly manage and control each virtual machine. Therefore, the conventional reliable measurement of virtual machines is to perform reliable startup on the backend virtual machines using virtual security chips, which depends on the autonomy of the service virtual machines. However, if there are malicious programs in the virtual machines themselves, reliable measurement cannot be performed, it is impossible to monitor whether the virtual machines perform reliable measurement, and it is difficult to guarantee the effectiveness of reliable measurement. In such a situation, it has become an issue that needs to be solved how to perform dynamic reliable measurement on the virtual machine operating system and the application programs that operate internally, and guarantee the security and reliability of the entire cloud end.

[0039] In the embodiments of the present application, after the computing server 2 is powered on and completes a reliable startup, in order to further perform operations to maintain the virtual machine life cycle, it is necessary to further monitor whether the virtualized operating environment of the computing server 2 is reliable.

[0040] In some embodiments, as shown in FIG. 4, after it is determined that the computing server has performed a reliable startup (that is, step 23), the reliable measurement method may further include the following step S24.

[0041] Step 24, in response to determining that the virtualized operating environment of the computing server is reliable, it is a step of instructing the computing server to execute an operation to maintain the virtual machine life cycle, and when a change occurs in the virtual machine life cycle, the computing server performs a reliable measurement on the virtual machine.

[0042] In this step, if the reliable measurement device 1 determines that the computing server 2 has been started up reliably, and the computing server 2 has already measured the operating system and the VMM during the reliable startup process, it can be determined that the virtualized operating environment of the computing server 2 is reliable. Therefore, the virtualization control module of the reliable measurement device 1 can send the control command of the cloud platform control and management module to the virtualization control proxy module of the computing server 2. The control command includes but is not limited to being sent by the security overall control server 3, and is a control command for operating to maintain the virtual machine life cycle, for example, a control command for constructing, deleting, restarting, taking a snapshot, restoring, and moving a virtual machine. After the computing server 2 receives and executes the control command, a corresponding change occurs in the life cycle of the virtual machine. At this time, a reliable measurement of the virtual machine of the computing server 2 is triggered. Here, the reliable VMM can generate a reliable virtual security measurement module (for example, vTPM) while constructing a virtual machine and make it available for the virtual machine.

[0043] In some embodiments, as shown in FIG. 5, after instructing the computing server to perform an operation to maintain the virtual machine life cycle (that is, step 24), the reliable measurement method further includes the following steps S25 to S27.

[0044] Step 25, access the virtual machine and identify the startup mode of the second bootloader program of the virtual machine.

[0045] In this step, the reliable measurement device 1 is connected to the VMM by the virtualization control module and the virtualization control proxy module of the computing server 2, accesses the inside of the virtual machine through a virtual machine monitoring channel (such as virtio console, etc.), and the virtualization control proxy module executes a query command related to the virtual security measurement module to determine whether the startup mode of the bootloader of the virtual machine (that is, the second bootloader program) is a reliable startup mode.

[0046] Step 26: In response to the second bootloader program being in a reliable boot mode, obtain the second group of reliable measurement results stored in the virtual machine.

[0047] In this step, when the reliable measurement device 1 determines that the second bootloader program is in a reliable boot mode, the virtualization control module of the reliable measurement device 1, through the virtualization control proxy module of the computing server 2, reads the measurement results (that is, the second group of reliable measurement results) stored in the PCR (Platform Configuration Register) of the security measurement module from the computing server 2. The second group of reliable measurement results is the reliable measurement results for the virtual machine. The second group of reliable measurement results includes multiple measurement values such as, for example, the measurement values of the security measurement module and the measurement values of the virtual machine application program.

[0048] Step 27: In response to the second group of reliable measurement results being the same as the pre-stored second group of reliable measurement waiting values, it is a step to determine that the virtual machine has started up reliably. The second group of reliable measurement waiting values is sent by the security overall control server to the reliable measurement device.

[0049] In this step, the reliable measurement device 1 compares each measured value in the reliable measurement results of the second group with each expected value in the pre-stored reliable measurement expected values of the second group. If each measured value is identical to the corresponding expected value respectively, the virtual machine determines that it is a reliable startup. Here, the security comprehensive control server 3 transmits the reliable measurement expected values (that is, the reliable measurement expected values of the second group) of the virtual machine operating on the computing server 2 to the reliable measurement device 1 in advance via the encrypted network. In some embodiments, the reliable measurement expected values may be transmitted in response to a spontaneous request from the reliable measurement device 1. The reliable measurement expected values may be transmitted via an encrypted network authenticated by a digital certificate and encrypted and stored in the security measurement module of the reliable measurement device 1, and decrypted using the public key of the digital certificate of the security comprehensive control server 3 during use.

[0050] In some embodiments, after instructing the computing server to execute an operation for maintaining the virtual machine life cycle (that is, step 24), the reliable measurement method further includes executing a third security management control policy in response to satisfying a preset second condition. The preset second condition includes at least one of exceeding a preset time length and not succeeding in accessing the virtual machine, the second bootloader program of the virtual machine not being in a reliable boot mode, and being identified that the virtual machine has not had a reliable startup.

[0051] In some embodiments, when the virtualization control module of the reliable measurement device 1 times out and cannot access the virtual machine, or the virtual machine has not had a reliable startup, or the bootloader of the virtual machine is not in a reliable boot mode, the reliable measurement device 1 can execute a preset third security management control policy.

[0052] In some embodiments, the third security management control policy includes at least one of transmitting a third security warning to a preset server and instructing a computing server to temporarily stop the operation of the central processing unit (CPU) of a virtual machine.

[0053] Note that the preset server that receives the third security warning may be the security overall control server 3, or may be other cloud servers.

[0054] In some embodiments, as shown in FIG. 6, after obtaining the second group of reliable measurement results stored in the virtual machine (that is, step 26), the reliable measurement method further includes the following step S27'.

[0055] Step S27', in response to at least one of the second group of reliable measurement results being different from at least one of the second group of reliable measurement expected values, execute the fourth security management control policy.

[0056] If the second group of reliable measurement results in the virtual machine is not exactly the same as the second group of reliable measurement expected values cached in the reliable measurement device 1, it means that the virtual machine may have been illegally modified, or the operating system and software of the virtual machine need to be updated, or the measurement range of the application program of the virtual machine needs to be adjusted. In such a case, execute the preset fourth security management control policy.

[0057] In some embodiments, the fourth security management control policy includes at least one of the following: sending a fourth security warning to a preset server, instructing a computing server to upgrade the operating system of a virtual machine, instructing a computing server to adjust the reliable measurement range of the application program of the virtual machine, and sending a measurement waiting value update instruction to the computing server for the computing server to update the measurement waiting value stored in the virtual machine.

[0058] Note that the preset server that receives the fourth security warning may be the security overall control server 3, or may be other cloud servers.

[0059] The embodiments of the present application can perform reliable measurement on the virtualized operating environment of the technology server from the reliable measurement device 1, initiate measurement for the startup of the virtual machine, and ensure the effectiveness and reliability of the dynamic measurement of the host machine virtualization environment, the virtual machine operating system, and the application program.

[0060] In some embodiments, the reliable measurement method further includes receiving at least one group of reliable measurement waiting values sent by the security overall control server via an encrypted network and storing the at least one group of reliable measurement waiting values locally.

[0061] In this step, when the reliable measurement waiting value of the reliable measurement device 1, the computing server 2, or the virtual machine thereof needs to be updated, the security overall control server 3 can be powered on only during the update, and the reliable measurement waiting value to be updated is sent to the reliable measurement device 1 via a security network authenticated by a digital certificate and cached. Therefore, the security overall control server 3 does not need to be always online and has a low possibility of being invaded or attacked.

[0062] The embodiment of the present application introduces a dynamic and reliable measurement mechanism initiated by the reliable measurement device 1. After receiving the reliable measurement expected value of the security overall control server 3 by the reliable measurement device 1, it is cached. Then, it is monitored using the communication interface of the computing server 2 to ensure that the computing server 2 measures its bootloader, operating system, hypervisor, and virtualization control proxy module, and completes a reliable startup. Furthermore, reliable measurement monitoring is performed on the virtual machines operating on the computing server 2 to ensure that it uses a reliable startup method and that the measurement results of the virtual machine operating system and the required application programs match the expected ones.

[0063] To more preferably illustrate the technical solution of the present application, the embodiments of the present application will be further described below with specific examples.

[0064] As shown in FIG. 7, the computing server uses an x86 computing server 71, and the reliable measurement device uses an arm64 control daughter card 72 to connect to the x86 computing server 71 through a PCI endpoint interface.

[0065] The x86 computing server 71 is a physical server that provides computing resources (CPU, internal memory, storage, network, etc.) to virtual machines. Its CPU uses the x86 architecture, and one of its PCI slots accesses the TPCM (Trust Platform Control Module). The board card, as a security measurement module, can be powered on preferentially before the CPU is powered on and spontaneously measures the BIOS and other hardware. The x86 computing server 71 further includes a remote power management module that supports the IPMI protocol and can be accessed through an independent power management interface.

[0066] The arm64 control daughter card 72 is connected to the x86 computing server 71 through a PCI bus interface. The arm64 control daughter card 72 operates as a PCI endpoint, and is also equipped with its own CPU (arm64 architecture), internal memory, Linux (registered trademark) operating system, and an independent security chip (TPM) to serve as a security measurement module. The TPM chip connects to the system through an I2C bus. The arm64 control daughter card 72 stores the digital certificate of the security overall control server 73 and connects to the security overall control server 73 through an ssh (Secure Shell) encrypted security network authenticated by the certificate.

[0067] The cloud platform control proxy module in the arm64 control daughter card 72 uses the openstack-nova-compute service program. With the startup of the arm64 control daughter card 72, reliable measurement can be performed. It communicates with the openstack components of other cloud platform main machines through a network interface, receives the management information of the cloud platform administrator, and can receive and store the reliable measurement waiting values of the x86 computing server 71 and the virtual machines operating thereon sent by the security overall control server 73 through an encrypted network by authenticating with a digital certificate. The reliable measurement waiting value is encrypted with the private key of the security overall control server 73 and stored in the security hardware (TPM chip) of the arm64 control daughter card 72, and is decrypted using the public key of the digital certificate during use.

[0068] The VMC (Virtual Machine Controller) module is a virtualization control module that operates on the arm64 controlled daughter card 72. It connects to the VMC agent (virtualization control proxy) module of the x86 computing server 71 via the PCI interface, obtains the type and configuration information of the x86 computing server 71, such as the CPU type, security module type, hypervisor type, etc., converts the virtualization management commands sent by the security overall control server 73 into corresponding compatible commands, executes reliable measurement monitoring of the x86 computing server 71 and the virtual machine, controls the life cycle of the virtual machine according to the commands sent by QEMU (virtual operating system simulator), and can control its power state through the IPMI power management module of the x86 computing server 71 via the IPMI interface.

[0069] The VMC agent module resides in the x86 computing server 71 to become a virtualization control proxy program, can perform reliable measurement with the startup of the x86 computing server 71, communicates with the VMC module of the arm64 controlled daughter card 72 via the PCI bus interface, and executes the transmission of VMC module commands.

[0070] The Virtual Machine Monitor (VMM) uses QEMU + KVM (Kernel-based Virtual Machine), and as the infrastructure of the hypervisor that constructs and maintains the virtual machine life cycle, it is equipped with the virtio console technology and can access the internal operating system of the virtual machine to execute corresponding commands.

[0071] As the basis of trust for the entire cloud platform, the Security Comprehensive Control Server 73 stores all the reliable measurement waiting values of the arm64 control daughter cards 72, the x86 computing servers 71, and the virtual machines. To prevent encountering intrusions, it is normally in a non-powered state and is only powered on when the reliable measurement waiting values need to be updated. After authentication with a digital certificate, the updated reliable measurement waiting values are sent to each arm64 control daughter card 72 via an ssh encrypted security network for caching, or are sent after being spontaneously requested by each arm64 control daughter card 72.

[0072] The implementation process of the reliable measurement method in this specific embodiment is as follows. The Security Comprehensive Control Server 73 sends the latest reliable measurement waiting values of the ssh encrypted security network authenticated by a digital certificate in advance to each arm64 control daughter card 72 for encrypted caching.

[0073] After the x86 computing server 71 is powered on, the TPCM board card starts operating first. Based on the built-in trust basis, it measures the reliability of the bios and the bootloader. After confirming that they are reliable, the CPU starts powering on. After the reliable bios operates and reads the reliable measurement waiting values pre-arranged in the TPCM board card, it measures the Linux (registered trademark) kernel. If the measured value and the expected value match, it means that the Linux (registered trademark) kernel is reliable. Then, it continues to dynamically measure the expected value to verify whether QEMU and the VMC agent are reliable.

[0074] The arm64 controlled daughter card 72 is also powered on simultaneously, and during the startup process, the measurement waiting value in the TPM chip is read. For the bootloader, the arm Linux (registered trademark) kernel, and the VMC module, the dynamic and reliable measurement of openstack-nova-compute is sequentially completed. If the measured value matches the one sent by the security overall control server 72, the startup process ends.

[0075] The VMC module connects to the VMC agent operating on the x86 computing server 71 via the PCI channel. First, a reliable measurement is performed on the bootloader, and after confirming that it uses a reliable startup method, the VMC agent reads the PCR value of the TPCM board card and compares it with the reliable measurement waiting value cached in the arm64 controlled daughter card 72. If they match, the x86 computing server 71 determines that a reliable startup has been performed.

[0076] If it is determined that the startup of the x86 computing server 71 is not complete, or the VMC module times out and cannot connect to the VMC agent, or the VMC agent cannot read the PCR value in the TPCM of the x86 computing server 71, the pre-set security management control policy is executed. For example, it is shut down by the IPMI power management module to lock the startup of the x86 computing server 71 and generate a security warning.

[0077] If the expected PCR value in the TPCM of the x86 computing server 71 read by the VMC module by the VMC agent does not match the reliable measurement expected value cached in the arm64 control daughter card 72, it means that the x86 computing server 71 may have been illegally modified, or the operating system and software of the x86 computing server 71 need to be updated and upgraded, or the measurement range of the x86 computing server 71 needs to be adjusted. At this time, the arm64 control daughter card 72 sends a security warning to the cloud platform by openstack-nova-compute, or upgrades the system according to the cloud platform's policy to adjust the dynamic measurement range of the application program. During the adjustment, the VMC module can update the measurement expected value (PCR) in the TPCM board card according to the TPCM-related command sent by the VMC agent.

[0078] If it is confirmed that the x86 computing server 71 has a reliable startup and the measurement of the operating system, QEMU, and VMC agent is included in the reliable startup process, it is determined that the virtual operation environment of the x86 computing server 71 is reliable. The VMC module receives the control of openstack-nova-compute and constructs, deletes, restarts, takes snapshots, restores, and moves virtual machines on the x86 computing server 71 according to the commands sent by the VMC agent, that is, controls the life cycle of the virtual machine. The reliable QEMU simulates a reliable virtual security module (vTPM) when constructing the virtual machine and makes it available to the virtual machine.

[0079] The VMC module, through the VMC agent and further via the virtio console channel provided by QEMU, executes query commands related to the virtual security module (vTPM) inside the virtual machine. Specifically, it reads the measured values stored in the PCR of the vTPM, compares them with the reliable measurement waiting values cached in the arm64 controlled daughter card 72, and measures whether the virtual machine bootloader is a reliable bootloader expected by the cloud platform. By doing so, it obtains whether the internal operating system of the virtual machine has a reliable boot, and whether the key application program in the virtual machine (which is the Redis database service program in this embodiment) has undergone dynamic measurement during the reliable startup process.

[0080] If the VMC module times out and cannot access the inside of the virtual machine, or if it is found that the internal operating system bootloader of the virtual machine is not reliable or has not undergone a reliable boot after access, the VMC module may execute QEMU commands through the VMC agent, including but not limited to security management control means such as suspending the operation of the virtual CPU of the virtual machine by the QEMU command and generating a security warning.

[0081] If the PCR of the vTPM in the virtual machine read by the VMC module after accessing the inside of the virtual machine by the VMC agent does not match the reliable measurement waiting value cached in the arm64 controlled daughter card 72, it means that the virtual machine may have been illegally modified, or the operating system of the virtual machine or the application program in the virtual machine may need to be updated or upgraded, or the dynamic measurement range of the application program in the virtual machine needs to be adjusted. At this time, a security warning is generated, and after confirmation by the cloud platform administrator and the virtual machine user, the operating system or application program of the virtual machine can be upgraded, or the dynamic measurement range of the application program in the virtual machine can be adjusted according to the cloud platform policy. After that, the VMC module executes commands related to vTPM inside the virtual machine through the virtio console channel provided by QEMU by the VMC agent, and updates the measurement waiting value (PCR) in the vPM device of the virtual machine.

[0082] When the security overall control server 73 needs to update the reliable measurement waiting value of the arm64 controlled daughter card 72, the x86 computing server 71 or its virtual machine, it can only be powered on when the update is required, and the updated reliable measurement waiting value is transmitted to each arm64 controlled daughter card 72 via an encrypted network authenticated by a digital certificate and cached.

[0083] Based on the same technical idea, the embodiment of the present application further provides a reliable measurement device. As shown in FIG. 8, the reliable measurement device includes a first communication module 101 and a second processing module 102.

[0084] The first communication module 101 is used to connect to the computing server and obtain the first group of reliable measurement results stored in the computing server when the reliable measurement device starts up reliably.

[0085] The first processing module 102 identifies the startup mode of the first bootloader program of the computing server, and when the first bootloader program is in a reliable boot mode, instructs the first communication module to obtain the first group of reliable measurement results stored in the computing server, and in response to the first group of reliable measurement results being the same as the pre-stored first group of reliable measurement expected values, it is used to identify that the computing server has started up reliably. The first group of reliable measurement expected values are those sent by the security overall control server to the reliable measuring device.

[0086] In some embodiments, after the first processing module 102 obtains the first group of reliable measurement results stored in the computing server, it is further used to execute the first security management control policy in response to at least one of the first group of reliable measurement results being different from at least one of the first group of reliable measurement expected values.

[0087] In some embodiments, the first security management control policy includes at least one of sending a first security warning to a pre-set server, instructing the computing server to upgrade the operating system of the computing server, and instructing the computing server to adjust the reliable measurement range of the computing server.

[0088] In some embodiments, when the reliable measurement device has a reliable startup, the first processing module 102 is further used to execute a second security management control policy in response to meeting a preset first condition. The preset first condition includes at least one of the following: exceeding a preset first time length and not successfully connecting to the computing server; not obtaining a first group of reliable measurement results stored in the computing server; the number of the first group of reliable measurement results being less than the number of the first group of reliable measurement waiting values; and the first bootloader program not being in a reliable boot mode.

[0089] In some embodiments, the second security management control policy includes at least one of the following: sending a second security warning to a preset server; and instructing the computing server to shut down and lock the startup.

[0090] In some embodiments, as shown in FIG. 9, the reliable measurement device further includes a second processing module 103.

[0091] After identifying that the computing server has a reliable startup, the second processing module 103 is used to instruct the computing server to perform operations for maintaining the virtual machine life cycle in response to identifying that the virtualized operation environment of the computing server is reliable. When a change occurs in the life cycle of the virtual machine, the computing server performs reliable measurements on the virtual machine.

[0092] In some embodiments, after instructing the computing server to perform operations for maintaining the virtual machine life cycle, the second processing module 103 accesses the virtual machine, determines the startup mode of the second bootloader program of the virtual machine, and in response to the second bootloader program being in a trustworthy boot mode, obtains the second group of trustworthy measurement results stored in the virtual machine. Further, in response to the second group of trustworthy measurement results being the same as the pre-stored second group of trustworthy measurement expected values, it is further used to determine that the virtual machine has started up trustworthily. The second group of trustworthy measurement expected values are those sent by the security control server to the trustworthy measurement device.

[0093] In some embodiments, after instructing the computing server to perform operations for maintaining the virtual machine life cycle, the second processing module 103 is further used to execute the third security management control policy in response to meeting a preset second condition. The preset second condition includes at least one of the following: exceeding a preset time length and not successfully accessing the virtual machine, the second bootloader program of the virtual machine not being in a trustworthy boot mode, and being determined that the virtual machine has not started up trustworthily.

[0094] In some embodiments, the third security management control policy includes at least one of the following: sending a third security warning to a preset server, and instructing the computing server to temporarily stop the operation of the central processing unit (CPU) of the virtual machine.

[0095] In some embodiments, after obtaining the second group of trustworthy measurement results stored in the virtual machine, the second processing module 103 is further used to execute the fourth security management control policy in response to at least one of the second group of trustworthy measurement results being different from at least one of the second group of trustworthy measurement expected values.

[0096] In some embodiments, the fourth security management control policy includes at least one of the following: sending a fourth security warning to a preset server; instructing a computing server to upgrade the operating system of a virtual machine; instructing a computing server to adjust a reliable measurement range of an application program of a virtual machine; and sending a measurement waiting value update instruction to the computing server for the computing server to update a measurement waiting value stored in a virtual machine.

[0097] In some embodiments, as shown in FIG. 10, the reliable measuring device further includes a second communication module 104.

[0098] The second communication module 104 is used to receive at least one group of reliable measurement waiting values sent by a security overall control server via an encrypted network and locally store the at least one group of reliable measurement waiting values.

[0099] The embodiments of the present application further provide a computer device, which includes one or more processors and a storage device. One or more programs are stored in the storage device. When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the reliable measurement method provided by each of the above embodiments.

[0100] The embodiments of the present application further provide a computer-readable medium storing a computer program, where when the computer program is executed, the processor is caused to implement the reliable measurement method provided by each of the above embodiments.

[0101] Those skilled in the art can understand that all or some of the steps of the methods disclosed above, and the functional modules / units in the apparatus, may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware embodiments, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components. For example, one physical component may have multiple functions, or one function or step may be executed by several physical components in cooperation. A certain physical module or all physical modules may be implemented as software executed by a processor such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit such as an application-specific integrated circuit. Such software can be arranged on a computer-readable medium, and the computer-readable medium may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is known to those skilled in the art, the technical term "computer storage medium" includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). The computer storage medium includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk memory, magnetic boxes, magnetic tapes, magnetic disk memory or other magnetic storage devices, or any other medium capable of storing the desired information and accessible by a computer. Also, those skilled in the art know that a communication medium generally includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information transmission medium.

[0102] Although examples are disclosed and specific terms are employed in this specification, they are used only for general illustrative purposes and should be so construed and not for purposes of limitation. In some examples, features, characteristics and / or elements described in combination with a particular example can be used alone or in combination with features, characteristics and / or elements described in combination with other examples, which will be apparent to those skilled in the art. Thus, those skilled in the art will understand that various changes can be made in various forms and details without departing from the scope of the present application as described by the appended claims.

Claims

1. A reliable measurement method applicable to a reliable measurement device, comprising: When the reliable measurement device starts up reliably, connecting to a computing server and identifying the startup mode of the first bootloader program of the computing server; In response to the first bootloader program being in a reliable boot mode, obtaining a first group of reliable measurement results stored in the computing server; In response to the first group of reliable measurement results being the same as a first group of pre-stored reliable measurement expected values, identifying that the computing server has started up reliably, wherein the first group of reliable measurement expected values are transmitted to the reliable measurement device by a security master control server. A reliable measurement method.

2. After obtaining the first group of reliable measurement results stored in the computing server, Further comprising executing a first security management control policy in response to at least one of the first group of reliable measurement results being different from at least one of the first group of reliable measurement expected values. The method according to claim 1.

3. The first security management control policy includes at least one of: Sending a first security warning to a preset server; Instructing the computing server to upgrade its operating system; Instructing the computing server to adjust its reliable measurement range. The method according to claim 2.

4. When the reliable measurement device starts up reliably, Further comprising executing a second security management control policy in response to meeting a preset first condition, Wherein the preset first condition includes: Exceeding a preset first time length and not succeeding in connecting to the computing server; Not obtaining the first group of reliable measurement results stored in the computing server; The number of the first group of reliable measurement results being less than the number of the first group of reliable measurement expected values. including at least one of the facts that the first bootloader program is not in a trustworthy boot mode The method according to claim 1.

5. The second security management control policy sending a second security warning to a preset server including at least one of instructing the computing server to shut down and locking the startup The method according to claim 4.

6. After identifying that the computing server has performed a trustworthy startup responding to the identification that the virtualized operating environment of the computing server is trustworthy, and instructing the computing server to perform an operation for maintaining the virtual machine life cycle, further including the step of when a change occurs in the life cycle of the virtual machine, the computing server performing a trustworthy measurement on the virtual machine The method according to claim 1.

7. After instructing the computing server to perform an operation for maintaining the virtual machine life cycle accessing the virtual machine and identifying the startup mode of the second bootloader program of the virtual machine responding to the second bootloader program being in a trustworthy boot mode, and obtaining a second group of trustworthy measurement results stored in the virtual machine responding to the second group of trustworthy measurement results being the same as a second group of preset trustworthy measurement expected values, and identifying that the virtual machine has performed a trustworthy startup, wherein the second group of trustworthy measurement expected values are sent by the security overall control server to the trustworthy measurement device The method according to claim 6.

8. After instructing the computing server to perform an operation for maintaining the virtual machine life cycle further including executing a third security management control policy in response to meeting a preset second condition The preset second condition exceeding a preset time length and not succeeding in accessing the virtual machine the second bootloader program of the virtual machine not being in a trustworthy boot mode including at least one of the cases where it is determined that the virtual machine has not started up reliably The method according to claim 7

9. The third security management control policy sending a third security warning to a preset server including at least one of instructing the computing server to temporarily stop the operation of the central processing unit (CPU) of the virtual machine The method according to claim 8

10. after obtaining the second group of reliable measurement results stored in the virtual machine further including the step of executing a fourth security management control policy in response to at least one of the second group of reliable measurement results being different from at least one of the second group of reliable measurement expected values The method according to claim 7

11. The fourth security management control policy sending a fourth security warning to a preset server instructing the computing server to upgrade the operating system of the virtual machine instructing the computing server to adjust the reliable measurement range of the application program of the virtual machine including at least one of sending a measurement expected value update command to the computing server for the computing server to update the measurement expected value stored in the virtual machine The method according to claim 10

12. further including receiving, via an encrypted network, at least one group of reliable measurement expected values sent by the security overall control server and locally storing the at least one group of reliable measurement expected values The method according to claim 1

13. A reliable measuring device, comprising a first communication module and a first processing module The first communication module when the reliable measuring device starts up reliably, connecting to a computing server used to obtain the first group of reliable measurement results stored in the computing server The first processing module Identify the startup mode of the first bootloader program of the computing server, and when the first bootloader program is in a trustworthy boot mode, instruct the first communication module to obtain the first group of trustworthy measurement results stored in the computing server, and in response to the first group of trustworthy measurement results being the same as the pre-stored first group of trustworthy measurement expected values, it is used to identify that the computing server has started up trustworthily. The first group of trustworthy measurement expected values are those transmitted by the security management control server to the trustworthy measurement device Trustworthy measurement device.

14. One or more processors and A storage device storing one or more programs, comprising When the one or more programs are executed by the one or more processors, the one or more processors implement the trustworthy measurement method according to any one of Claims 1 to 12 Computer device.

15. A computer-readable medium storing a computer program, wherein when the computer program is executed by a processor, the processor implements the trustworthy measurement method according to any one of Claims 1 to 12 Computer-readable medium.

Citation Information

Patent Citations

  • Electronic mail communication apparatus

    JP2009100439A

  • Information processing apparatus, information processing system, information processing method, and program

    JP2017153044A

  • Integrity verification device, integrity verification system, integrity verification method and integrity verification program

    JP2019133220A

  • Information processing apparatus

    JP2021047799A

  • Information processing apparatus, information processing system, information processing method, and computer-readable medium

    US20170249483A1