Trusted measurement report processing method, device, protective component, and storage medium

By processing trust measurement reports by aggregating and adding device information in protective components, the high communication cost problem in existing technologies is solved, and efficient trust verification in heterogeneous computing environments is achieved.

WO2026025852A1PCT designated stage Publication Date: 2026-02-05HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/076761
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2025-02-11
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing technologies struggle to differentiate between different types of devices when performing trust measurements, resulting in high communication costs in large-scale computing clusters and high performance requirements for the trust management center. This makes it difficult to effectively reduce the communication costs and resource demands of verification devices.

Method used

By acquiring trusted measurement reports from multiple measured devices through protective components, and adding device information, a second trusted measurement report is aggregated, reducing the amount of data and improving the accuracy of device information, while reducing communication frequency and computing resource requirements.

Benefits of technology

It reduces communication costs and resource requirements in single servers, heterogeneous computing devices, and large-scale computing clusters, improves verification efficiency and compatibility, and eliminates the performance bottleneck of cluster-level trust metrics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025076761_05022026_PF_FP_ABST
    Figure CN2025076761_05022026_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of communications, and discloses a trusted measurement report processing method, a device, a protective component, and a storage medium. The method comprises: a protective component acquiring a plurality of first trusted measurement reports of a plurality of measured apparatuses, each first trusted measurement report comprising apparatus information of a corresponding measured apparatus; aggregating the plurality of first trusted measurement reports to obtain a second trusted measurement report, the data volume of the second trusted measurement report being less than the sum of the data volumes of the plurality of first trusted measurement reports; and sending the second trusted measurement report to a verification apparatus, the second trusted measurement report being used by the verification apparatus to verify the plurality of measured apparatuses. According to the present application, the data volume of the second trusted measurement report sent to the verification apparatus is less than the sum of the data volumes of the plurality of unaggregated first trusted measurement reports, and the second trusted measurement report comprises the apparatus information, thereby reducing the volume of data transmitted between the protective component and the verification apparatus and communication costs, and improving the accuracy of verification.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, equipment, protective components, and storage media for trust measurement reports

[0001] This application claims priority to Chinese Patent Application No. 202411047598.X, filed on July 31, 2024, entitled “Processing Method, Apparatus, Protective Component and Storage Medium for Reliability Measurement Reports”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to methods, devices, protective components, and storage media for processing trust measurement reports. Background Technology

[0003] In the field of communication technology, trusted computing can improve the security of communication systems. Trusted computing can be implemented through verification techniques. During the verification process, a trusted root in the device generates a trusted measurement report and sends it to the trusted management center. The trusted management center then verifies the device's status based on the trusted measurement report, thereby determining whether the device to which the trusted root that generated the trusted measurement report belongs is trustworthy. Summary of the Invention

[0004] This application provides a method, device, protective component, and storage medium for processing trust measurement reports, in order to reduce the communication costs required for transmitting trust measurement reports. The technical solution is as follows:

[0005] In a first aspect, a method for processing a trusted measurement report is provided. The method includes: a protection component acquiring multiple first trusted measurement reports of multiple measured devices, each first trusted measurement report including device information of the corresponding measured device; the protection component aggregating the multiple first trusted measurement reports to obtain a second trusted measurement report, the data volume of the second trusted measurement report being less than the sum of the data volumes of the multiple first trusted measurement reports; and the protection component sending the second trusted measurement report to a verification device, the second trusted measurement report being used by the verification device to verify the multiple measured devices.

[0006] The second trusted measurement report sent to the verification device in this application is an aggregated trusted measurement report. The data volume of the second trusted measurement report is less than the sum of the data volumes of multiple unaggregated first trusted measurement reports, thus reducing the amount of data transmitted with the verification device and reducing the communication cost with the verification device. In addition, the first trusted measurement reports obtained by the protection component include device information. Therefore, the second trusted measurement report obtained by aggregating multiple first trusted measurement reports also includes device information, enabling the verification device to accurately determine whether each measured device corresponding to the first trusted measurement report is abnormal based on the device information in the second trusted measurement report.

[0007] In one possible implementation, the protection component acquires multiple first trusted measurement reports from multiple measured devices, including: receiving multiple third trusted measurement reports sent by multiple measured devices, wherein the multiple third trusted measurement reports are generated by trusted roots among multiple measured devices; adding device information of the corresponding measured device to the multiple third trusted measurement reports to obtain multiple first trusted measurement reports, wherein the added device information is the information of the measured device to which the trusted root that generated the third trusted measurement report belongs.

[0008] Device information is added to the received third trust measurement report to obtain multiple first trust measurement reports including device information. Then, the first trust measurement reports including device information are aggregated to obtain a second trust measurement report including device information, so that the verification device can accurately determine whether each measured device corresponding to the third trust measurement report is abnormal based on the device information in the second trust measurement report.

[0009] In one possible implementation, before adding device information of the corresponding measured device to multiple third trusted measurement reports to obtain multiple first trusted measurement reports, the method further includes: for any third trusted measurement report, determining the device information to be added to any third trusted measurement report based on the mapping relationship between port information and device information and the port information of the port receiving any third trusted measurement report. The mapping relationship between port information and device information allows for efficient and accurate determination of the device information corresponding to each third trusted measurement report, thereby enabling the acquisition of first trusted measurement reports including device information.

[0010] In one possible implementation, the protection component acquires multiple first trusted measurement reports, including: receiving multiple first trusted measurement reports sent by multiple measured devices. The multiple first trusted measurement reports include device information, which is added by a trusted root that generated the multiple first trusted measurement reports. The device information is information about the measured device to which the trusted root belongs. In this application, the first trusted measurement reports including device information can be generated by the trusted root within each measured device. Therefore, the received trusted measurement report is a first trusted measurement report including device information, improving the efficiency of acquiring multiple first trusted measurement reports.

[0011] In one possible implementation, the protection component aggregates multiple first trust measurement reports to obtain a second trust measurement report. This includes: aggregating multiple first trust measurement reports according to the device type corresponding to the multiple first trust measurement reports to obtain a second trust measurement report. The number of second trust measurement reports is at least one, and the device type corresponding to the first trust measurement reports that result in any one second trust measurement report is the same. Aggregating multiple first trust measurement reports according to the type of the device being measured allows first trust measurement reports corresponding to the same device type to be aggregated into a single second trust measurement report. This enables the verification device to determine whether a device of the same type is abnormal based on a single second trust measurement report, thereby improving verification efficiency.

[0012] In one possible implementation, the device information includes the device type. Before aggregating multiple first trust measurement reports according to their corresponding device types to obtain the second trust measurement report, the method further includes: reading the device types from the multiple first trust measurement reports. If the device information in the first trust measurement report includes the device type, then the device type can be efficiently obtained by reading the device information from the first trust measurement report.

[0013] In one possible implementation, the device information includes a device identifier. Before aggregating multiple first trust measurement reports according to their corresponding device types to obtain a second trust measurement report, the method further includes: reading the device identifiers from the multiple first trust measurement reports; and determining the device type corresponding to the multiple first trust measurement reports based on the mapping relationship between the device identifier and the device type, and the device identifier itself. Based on the mapping relationship between the device identifier and the device type, the device type can be accurately determined even when the device information in the first trust measurement report only includes the device identifier.

[0014] In one possible implementation, the method further includes: receiving a tracing request sent by a verification device; determining an anomaly report among multiple first trust measurement reports based on the tracing request; and determining the anomaly device corresponding to the anomaly report based on the anomaly report. If a tracing request is received, indicating that an anomaly report exists among the multiple first trust measurement reports from which the second trust measurement report is aggregated, the tracing device that generated the anomaly report can be determined based on the tracing request, thus achieving tracing.

[0015] In one possible implementation, the protective component is a baseboard manager controller (BMC).

[0016] Secondly, a protective component is provided, comprising: an acquisition module for acquiring multiple first trusted measurement reports of multiple measured devices, wherein the first trusted measurement reports include device information of the corresponding measured devices; an aggregation module for aggregating the multiple first trusted measurement reports to obtain a second trusted measurement report, wherein the data volume of the second trusted measurement report is less than the sum of the data volumes of the multiple first trusted measurement reports; and a sending module for sending the second trusted measurement report to a verification device, wherein the second trusted measurement report is used by the verification device to verify the multiple measured devices.

[0017] In one possible implementation, an acquisition module is used to receive multiple third-trusted measurement reports sent by multiple measured devices, the multiple third-trusted measurement reports being generated by the trust roots among the multiple measured devices; add device information to the multiple third-trusted measurement reports to obtain multiple first-trusted measurement reports, the added device information being the information of the measured device to which the trust root that generated the third-trusted measurement report belongs.

[0018] In one possible implementation, the protection component further includes a determination module; the determination module is used to determine, for any third trusted measurement report, the device information to be added to any third trusted measurement report based on the mapping relationship between port information and device information and the port information of the port receiving any third trusted measurement report.

[0019] In one possible implementation, an acquisition module is used to receive multiple first trust measurement reports, the multiple first trust measurement reports including device information, the device information being added by the trust root that generated the multiple first trust measurement reports, and the device information being the information of the measured device to which the trust root belongs.

[0020] In one possible implementation, the aggregation module is used to aggregate multiple first trust measurement reports according to the device type corresponding to the multiple first trust measurement reports to obtain a second trust measurement report. The number of second trust measurement reports is at least one, and the device type corresponding to the first trust measurement reports to which any second trust measurement report is aggregated is the same.

[0021] In one possible implementation, the device information includes the device type; the acquisition module is also used to read the device type from multiple first trust metric reports.

[0022] In one possible implementation, the device information includes a device identifier; the acquisition module is further configured to read the device identifier from multiple first trust measurement reports; and determine the device type corresponding to the multiple first trust measurement reports based on the mapping relationship between the device identifier and the device type and the device identifier.

[0023] In one possible implementation, the protection component further includes a receiving module; the receiving module is also used to receive a tracing request sent by the verification device; the determining module is also used to determine an anomaly report among multiple first trust measurement reports based on the tracing request; and to determine the anomaly device corresponding to the anomaly report based on the anomaly report.

[0024] Thirdly, a trust measurement report processing device is provided, the device including a processor coupled to a memory; the memory stores at least one instruction, which is loaded and executed by the processor to enable the trust measurement report processing device to implement the trust measurement report processing method in the first aspect or any possible implementation of the first aspect.

[0025] Fourthly, a system for processing trusted measurement reports is provided. This system includes a protection component, multiple measured devices, and a verification device. The protection component is used to acquire multiple first trusted measurement reports from the multiple measured devices, each first trusted measurement report including device information of the corresponding measured device. The protection component is also used to aggregate the multiple first trusted measurement reports to obtain a second trusted measurement report, and send the second trusted measurement report to the verification device. The data volume of the second trusted measurement report is less than the sum of the data volumes of the multiple first trusted measurement reports. The verification device is used to receive the second trusted measurement report and verify the multiple measured devices based on the second trusted measurement report.

[0026] In one possible implementation, the device being measured is used to send a third trusted measurement report to the protection component. The third trusted measurement report is generated by the root of trust in the device being measured. The protection component is used to receive multiple third trusted measurement reports sent by multiple devices being measured, and add the device information of the corresponding device being measured to the multiple third trusted measurement reports to obtain multiple first trusted measurement reports. The added device information is the information of the device being measured to which the root of trust that generated the third trusted measurement report belongs.

[0027] In one possible implementation, the device being measured is configured to add device information to the obtained third trusted measurement report through the trusted root within the device being measured, thereby obtaining a first trusted measurement report, and send the first trusted measurement report to the protection component. The device information is the information of the device being measured to which the trusted root belongs. The protection component is configured to receive multiple first trusted measurement reports sent by multiple devices being measured.

[0028] In one possible implementation, the multiple metric devices include one or more of a central processing unit (CPU), a data processing unit (DPU), a neural network processing unit (NPU), or a graphics processing unit (GPU).

[0029] In one possible implementation, the protective component is a BMC.

[0030] In one possible implementation, the verification device is a trusted management center.

[0031] Fifthly, a computer program (product) is provided, comprising: computer program code, which, when executed by a computer, causes the computer to perform the trust measurement report processing method in the first aspect or any possible implementation thereof.

[0032] In a sixth aspect, a computer-readable storage medium is provided that stores a program or instructions, wherein when the program or instructions are run on a computer, the method for processing the trust measurement report in the first aspect or any possible implementation thereof is executed.

[0033] In a seventh aspect, a chip is provided, including a processor for retrieving and executing instructions stored in a memory, causing a computer equipped with the chip to execute the trust measurement report processing method in the first aspect or any possible implementation thereof.

[0034] Eighthly, another chip is provided, comprising: an input interface, an output interface, a processor, and a memory, wherein the input interface, the output interface, the processor, and the memory are connected via an internal connection path, the processor is used to execute code in the memory, and when the code is executed, a computer with the chip installed executes the trust measurement report processing method in the first aspect or any possible implementation of the first aspect.

[0035] It should be understood that the beneficial effects of the technical solutions and corresponding possible implementations of the second to eighth aspects of this application can be found in the above description of the technical effects of the first aspect and its corresponding possible implementations, and will not be repeated here. Attached Figure Description

[0036] Figure 1 is a schematic diagram of a trusted computing system provided by related technologies;

[0037] Figure 2 is a schematic diagram of an implementation scenario of a trust measurement report processing method provided in an embodiment of this application;

[0038] Figure 3 is a schematic diagram of a trusted verification in a heterogeneous cluster provided by an embodiment of this application;

[0039] Figure 4 is a flowchart illustrating a method for processing a credibility measurement report according to an embodiment of this application;

[0040] Figure 5 is a schematic diagram of a first credibility measurement report provided in an embodiment of this application;

[0041] Figure 6 is a schematic diagram of adding device information according to an embodiment of this application;

[0042] Figure 7 is a schematic diagram of a report aggregation process provided in an embodiment of this application;

[0043] Figure 8 is a schematic diagram of a trusted verification process in a trusted computing system provided in an embodiment of this application;

[0044] Figure 9 is a structural schematic diagram of a protective component provided in an embodiment of this application;

[0045] Figure 10 is a schematic diagram of the structure of a trust measurement report processing device provided in an embodiment of this application;

[0046] Figure 11 is a schematic diagram of a trust measurement report processing system provided in an embodiment of this application. Detailed Implementation

[0047] The terminology used in the implementation section of this application is for the purpose of explaining specific embodiments of this application only, and is not intended to limit this application.

[0048] In the field of communication technology, trusted computing can improve the security of communication systems. A communication system incorporating trusted computing is called a trusted computing architecture. This architecture enhances system security by introducing secure and trusted chips into the hardware platform. Secure and trusted chips can be, for example, chips conforming to the Trusted Platform Module (TPM) standard. TPM is an international standard for secure cryptographic processors, designed to process encryption keys within communication system devices using dedicated microcontrollers (secure hardware) integrated into the devices.

[0049] In trusted computing systems, trusted verification (or security verification) based on TPM is a crucial step. During trusted verification, the root of trust (RoT) in the measured device performs trusted measurements (or security measurements) on the hardware and software integrity of the device, generating corresponding trusted measurement reports. The root of trust is the foundation upon which a system can guarantee security and trustworthiness. It is a module whose behavior is always predictable, a component containing one or more specific security functions such as measurement, storage, reporting, verification, or updating. The root of trust includes one or more of highly reliable hardware, firmware, and software.

[0050] After the root of trust generates a trust measurement report, it transmits the trust measurement report to the corresponding verification end. The verification end performs trust verification on the measured device based on the trust measurement report to determine whether the measured device is trustworthy and whether the function of the trusted computing system has been maliciously tampered with.

[0051] Referring to Figure 1, a schematic diagram of a trusted computing architecture provided by related technologies is shown. The device being measured in this trusted computing architecture is a server. The server includes a computing component and a trusted protection component. The motherboard in the computing component supports the operation of application software, a trusted software base (TSB) agent based on openEular, a basic input / output system (BIOS), a central processing unit (CPU), and its associated software and hardware. In Figure 1, the server's built-in BMC board (or simply BMC) is used as the trusted protection component. The BMC board supports the operation of TSB, a trusted platform control module (TPCM), and a trusted cryptography module (TCM) chip. The TPCM firmware can serve as the server's root of trust, and the TCM chip can serve as the server's cryptographic root.

[0052] The Trusted Protection Component (TPCM) performs trust measurements on the CPU and its associated software and hardware within the computing components. For example, the TPCM firmware on the BMC board acts as the root of trust, initiating a trust measurement on the computing components, including the CPU. The TSB Agent on the CPU side performs trust measurements on the firmware, operating system (OS), and software, generates a trust measurement report, and sends it back to the BMC board. The TPCM firmware then sends the received trust measurement report to the Trusted Management Center, which performs trust verification on the computing components based on the trust measurement report.

[0053] The aforementioned technologies are designed for trust verification in single-server scenarios and are difficult to apply to heterogeneous or large-scale computing devices. This is because these technologies do not differentiate between device types or processor types when performing trust measurements and generating trust measurement reports. For example, when performing trust measurements, these technologies assume the measured device is a CPU-based device and do not distinguish between different CPUs. Therefore, if two measured devices have the same software version, the generated trust measurement reports will also be identical, making it impossible to distinguish the correspondence between different trust measurement reports and different measured devices.

[0054] Furthermore, if these technologies are applied to large-scale computing clusters, the root of trust in each measured device within the cluster needs to generate a trust measurement report, and each trust measurement report needs to be transmitted to the Trust Management Center. Due to the large number of measured devices in a large-scale computing cluster, and the fact that each device may be measured multiple times and generate multiple trust measurement reports, the communication cost to the Trust Management Center is high. Additionally, the Trust Management Center requires significant resources to perform trust verification based on the received trust measurement reports, placing high performance demands on the Trust Management Center.

[0055] This application provides a method for processing a trusted measurement report. This method can be applied to scenarios with trusted verification requirements, such as single-server scenarios, heterogeneous computing devices, or large-scale computing clusters, and reduces the communication cost of the verification device used to perform trusted verification of the trusted measurement report. Referring to Figure 2, a schematic diagram of an implementation scenario of the trusted measurement report processing method provided in this application is shown. This implementation scenario includes a measured device 21, which includes a trusted root for performing trusted measurement and generating a trusted measurement report. There can be multiple measured devices 21, which can be various independent devices capable of trusted measurement, such as personal computers (PCs), servers, embedded devices, mobile devices, or network devices. The measured device 21 can also be a processor within the device, which can be various types of processors such as CPUs, DPUs, GPUs, or NPUs. Alternatively, the measured device 21 can also be one or more components or modules within the processor used to host application software or application systems. The types of multiple measured devices 21 can be the same or different. Referring to Figure 3, a schematic diagram of trusted verification in a heterogeneous cluster provided in this application is shown. In a heterogeneous cluster, there are multiple devices to be measured, such as CPU72, NPU73 and DPU75 in Figure 3. Taking CPU72 as an example, the devices to be measured may include application software, open source Euler and BIOS modules in CPU72.

[0056] Referring again to Figure 2, this implementation scenario also includes a verification device 22 for verifying the trusted measurement report. The verification device 22 can be, for example, the aforementioned trusted management center. In one possible implementation, the verification device 22 can be located in the cloud. In this implementation scenario, the device being measured 21 and the verification device 22 are connected via a protective component 23. The connection between the protective component 23 and the device being measured 21, and between the protective component 23 and the verification device 22, can be a wired or wireless connection. The protective component 23 can be a device or module with computing and forwarding functions, and it resides in the same trusted computing system as multiple devices being measured 21. For example, the protective component 23 can be the aforementioned BMC board.

[0057] Referring to Figure 4, a flowchart of a trust measurement report processing method provided in an embodiment of this application is shown. This method can be applied to the aforementioned protective component 23, and includes, but is not limited to, the following steps S301 to S303.

[0058] S301, the protective component acquires multiple first trusted measurement reports of multiple measured devices, the first trusted measurement reports including the device information of the corresponding measured device.

[0059] The first trust measurement report is a report generated after performing a trust measurement on the measured device. The device information can be the information of the measured device corresponding to the first trust measurement report. The device information can be, for example, the identifier and type of the measured device, the type of processor within the measured device, or the port address, etc.

[0060] The embodiments of this application do not limit the content and format of device information. Taking the use of two-bit binary numbers to represent device type as an example, CPU=00, DPU=01, GPU=10, NPU=11 can be defined, and different numbers can be used to represent different device types. Correspondingly, different numbers or characters can also be used to represent the identifiers of different devices.

[0061] Referring to Figure 5, a schematic diagram of a first trust measurement report provided in an embodiment of this application is shown. The first trust measurement report shown in Figure 5 includes a report header, device information, level-1 (L1) log information, Ubot (a bootloader) log information, root file system (Rootfs) log information, and BIOS log information. Figure 5 is merely an example of a first trust measurement report, and this application embodiment does not limit the content of the first trust measurement report to other contents besides device information.

[0062] Optionally, the first trust measurement report can be generated by the protection component or by the root of trust in the measured device. Regardless of which device generates the first trust measurement report, the protection component must receive the trust measurement report sent by the measured device. The trust measurement report sent by the measured device can be a first trust measurement report including device information or a third trust measurement report excluding device information.

[0063] In one possible implementation, the condition for the measured device to send a first trusted measurement report or a third trusted measurement report to the protection component could be that it receives a measurement request from the protection component. The protection component, in turn, could send a measurement request to the measured device upon receiving a verification request from the verification device.

[0064] For example, the verification device can periodically send verification requests to the protection component, or the verification request can be triggered by a specified event. The period at which the verification device sends verification requests and the specified event can be set based on experience or based on the requirements of trusted measurement. The specified event may be, for example, the addition of a new measured device to the trusted computing system to which the verification device belongs or the activation of a measured device.

[0065] The verification request may include information about the device being measured. The protection component may send a measurement request to the device being measured indicated by the verification request, so that the root of trust in the device receiving the measurement request performs a trust measurement on the device and generates a first trust measurement report or a third trust measurement report. The device being measured indicated by the verification request may be all or some of the devices in the trusted computing system to which the protection component belongs.

[0066] After the root of trust in the measured device receives the measurement request and performs a trust measurement on the measured device, it generates a first trust measurement report or a third trust measurement report and sends it to the protection component. Below, using cases 11 and 12 as examples, we will explain how the protection component obtains multiple first trust measurement reports in two different scenarios: the trust measurement report received by the protection component is either a third trust measurement report or a first trust measurement report.

[0067] Case 11: The trusted measurement report received by the protective component is a third trusted measurement report.

[0068] In scenario 11, the protective component acquires multiple first trusted measurement reports from multiple measured devices, including: receiving multiple third trusted measurement reports; adding device information to the multiple third trusted measurement reports to obtain multiple first trusted measurement reports. The multiple third trusted measurement reports are generated by trusted roots among the multiple measured devices, and the device information added to any third trusted measurement report is the information of the measured device to which the trusted root that generated any third trusted measurement report belongs.

[0069] In this embodiment, before the protective component adds device information to multiple third trusted measurement reports and obtains multiple first trusted measurement reports, the method further includes: for any third trusted measurement report, determining the device information to be added to any third trusted measurement report based on the mapping relationship between port information and device information and the port information of the port receiving any third trusted measurement report. The mapping relationship can be sent by the verification device or statically configured by personnel at the protective component.

[0070] For any third-party trusted measurement report, the protection component can record the port information of the port receiving the report, such as the port address, port number, or port identifier. Then, it searches for device information matching the recorded port information within the mapping between port information and device information. The protection component adds the found device information to the third-party trusted measurement report to obtain a first-party trusted measurement report.

[0071] In this manner, the protective component determines the device information of the multiple third trust measurement reports received, and adds the determined device information to the corresponding third trust measurement reports to obtain multiple first trust measurement reports.

[0072] Referring to Figure 6, a schematic diagram of adding device information according to an embodiment of this application is shown. The third trust measurement report received by the protection component does not include device information. After determining the device information, the protection component adds the device information to the third trust measurement report to obtain a first trust measurement report including the device information. The description of the first trust measurement report can be found in Figure 5, and will not be repeated here. This embodiment of the application does not limit the location where the device information is added to the third trust measurement report. For example, in Figure 6, the device information can be added between the report header and the L1 log information in the third trust measurement report, or between the L1 log information and the Ubot log information, or in other locations in the third trust measurement report.

[0073] In this embodiment of the application, the device information corresponding to each third trust measurement report can be determined efficiently and accurately based on the mapping relationship between port information and device information, thereby realizing the acquisition of the first trust measurement report including device information.

[0074] Case 12: The trusted measurement report received by the protective component is the first trusted measurement report.

[0075] In scenario 12, the protective component can acquire multiple first trust measurement reports by receiving multiple first trust measurement reports that include device information. The device information in each of the multiple first trust measurement reports is added by a trust root that generated the multiple first trust measurement reports, and the device information in any one of the first trust measurement reports is the information of the measured device to which the trust root that generated any trust measurement report belongs.

[0076] The trusted root within each measured device generates a first trusted measurement report containing device information, so that the trusted measurement report received by the protection component is the first trusted measurement report containing device information, thereby improving the efficiency of the protection component in obtaining multiple first trusted measurement reports.

[0077] S302, the protective component aggregates multiple first trust measurement reports to obtain a second trust measurement report, and the data volume of the second trust measurement report is less than the sum of the data volumes of the multiple first trust measurement reports.

[0078] This application does not limit the method for aggregating multiple first trust measurement reports in its embodiments. For example, the protection component can aggregate multiple first trust measurement reports in the order in which they are acquired to obtain a second trust measurement report. If the first trust measurement reports are generated by the protection component, then the order in which the protection component generates multiple first trust measurement reports is the same as the order in which it acquires multiple first trust measurement reports. If the first trust measurement reports are generated by a root of trust, then the order in which the protection component receives multiple first trust measurement reports is the same as the order in which it acquires multiple first trust measurement reports.

[0079] For example, the protective component can aggregate multiple first trust measurement reports according to the device type corresponding to multiple first trust measurement reports to obtain a second trust measurement report. The number of obtained second trust measurement reports is at least one, and the device type corresponding to the first trust measurement reports that result in any one of the second trust measurement reports is the same.

[0080] Here, the device type corresponding to any first trust measurement report refers to the type of the measured device to which the trust root of the device that generates any trust measurement report or the third trust measurement report corresponding to any trust measurement report belongs. Before aggregating according to the device types corresponding to multiple first trust measurement reports, the protection component can determine the device type corresponding to each first trust measurement report. Optionally, the protection component can obtain the device types corresponding to multiple first trust measurement reports according to the method shown in either case 21 or case 22 below.

[0081] Case 21: Device information in multiple first trust measurement reports includes device type.

[0082] In scenario 21, before the protective component aggregates multiple first trust measurement reports according to the device types corresponding to the multiple first trust measurement reports to obtain a second trust measurement report, it can read the device types in the multiple first trust measurement reports. Since the multiple first trust measurement reports carry the device types of the corresponding measured devices, the protective component can easily and efficiently determine the device types corresponding to the multiple first trust measurement reports by reading the device types in the multiple first trust measurement reports.

[0083] It should be understood that the device information in the first trust measurement report may also include other information besides the device type, such as the device identifier. However, regardless of what kind of device information is included, when the device information includes the device type, the protective component can obtain the device type corresponding to multiple first trust measurement reports in accordance with the method in case 21.

[0084] Case 22: Device information in multiple first trust measurement reports includes device identifiers.

[0085] In scenario 22, before the protective component aggregates multiple first trust measurement reports according to the device type corresponding to the multiple first trust measurement reports to obtain a second trust measurement report, it can read the device identifier in the multiple first trust measurement reports; and determine the device type corresponding to the multiple first trust measurement reports based on the mapping relationship between the device identifier and the device type and the device identifier.

[0086] The mapping relationship between device identifier and device type can be sent from the verification device to the protective component, or it can be statically configured by personnel at the protective component. For any first trust measurement report, the protective component reads the device identifier in the first trust measurement report and searches for the device type that matches the read device identifier in the mapping relationship between device identifier and device type, recording the device type corresponding to any first trust measurement report. In this embodiment, based on the mapping relationship between device identifier and device type, the device type can be accurately determined even when the device information in the first trust measurement report includes the device identifier but not the device type.

[0087] After obtaining the device type corresponding to the multiple first trust measurement reports according to the method shown in case 21 or case 22 above, the protection component can aggregate the multiple first trust measurement reports according to the device type corresponding to the multiple first trust measurement reports.

[0088] The aggregation algorithm used by the protective component in aggregating multiple first trust measurement reports according to their corresponding device types or the order in which they are acquired is not limited in the embodiments of this application. For example, the aggregation algorithm could be a Merkle Tree algorithm, which can also be called a hash binary tree algorithm.

[0089] Referring to Figure 7, a schematic diagram of a report aggregation process provided in an embodiment of this application is shown. The aggregation algorithm used in Figure 7 is a hash algorithm. Report 1 to Report N are N first trust measurement reports. The N first trust measurement reports need to be aggregated into one second trust measurement report. The N first trust measurement reports can be first trust measurement reports of the same device type, or first trust measurement reports obtained in a similar order.

[0090] During the aggregation process, reports 1 through N are aggregated in pairs using a specific hash algorithm in multiple rounds. Each round generates a new report containing information from both input reports. For example, in the first round, reports 1 and 2 form a pair, and the hash algorithm is used to aggregate them, resulting in report 1&2, which contains information from both reports 1 and 2. Reports 3 and 4 form a pair, and the hash algorithm is used to aggregate them, resulting in report 3&4, which contains information from both reports 3 and 4. And so on, with reports N-1 and N forming a pair, and the hash algorithm is used to aggregate them, resulting in report N-1&N, which contains information from both reports N-1 and N.

[0091] In the second round of aggregation, reports 1 & 2 and reports 3 & 4 are grouped together. A hash algorithm is used to aggregate reports 1 & 2 and reports 3 & 4 to obtain reports 1 & 2 & 3 & 4. ... Reports N-3 & N-2 and reports N-1 & N are grouped together. A hash algorithm is used to aggregate reports N-3 & N-2 and reports N-1 & N to obtain reports N-3 & N-2 & N-1 & N.

[0092] This process continues, with multiple rounds of aggregation for reports 1 through N, until the final N reports are aggregated into a single overall report containing information from all N reports (i.e., the second credibility measurement report). When a round requires the aggregation of an odd number of reports, the unaggregated report is skipped and proceeds directly to the next round of aggregation.

[0093] During the aggregation process, the hash algorithm selected in each round of aggregation can be a cryptographic hash algorithm to ensure that the output information generated by different inputs is unique. For example, a cryptographic hash algorithm can be combined with the commercial cryptographic algorithm SM3.

[0094] This application embodiment achieves the aggregation of multiple first trust measurement reports into a single report, reducing the communication frequency and cost between the protection component and the verification device. Furthermore, the computational resources required for the verification device to verify the second trust measurement report are less than those required to verify multiple first trust measurement reports. Therefore, the trust measurement report processing method provided in this application embodiment also reduces the performance requirements of the verification device and improves the overall performance of trust verification in cluster scenarios. Moreover, the second trust measurement report includes device information, improving the compatibility of trust measurement with heterogeneous clusters, eliminating the performance bottleneck of cluster-level trust measurement, and realizing the practicality and maintainability of trust measurement.

[0095] S303, the protective component sends a second credibility measurement report to the verification device. The second credibility measurement report is used by the verification device to verify multiple measured devices.

[0096] After receiving the second trust measurement, the verification device verifies the second trust measurement report to determine whether the device being measured corresponding to the second trust measurement report is trustworthy. The verification device uses different methods for different formats of the second trust measurement report, and the format of the second trust measurement report may be related to the format of the first trust measurement report.

[0097] Taking the second trust measurement report as an example, which is obtained by aggregating the first trust measurement reports shown in Figure 5 or Figure 6, the format of the second trust measurement report can be the same as that of the first trust measurement report. That is, the second trust measurement report also includes a report header, device information, LI log information, Ubot log information, Rootfs log information, and BIOS log information. Each type of information included in the second trust measurement report can indicate the corresponding type of information in the first trust measurement report from which the second trust measurement report was aggregated. For example, if the second trust measurement report is obtained by aggregating the first trust measurement reports 1 through 5, then the LI log information in the second trust measurement report is obtained by aggregating the L1 log information from the first trust measurement reports 1 through 5. Therefore, the L1 log information in the second trust measurement report can indicate the L1 log information of the first trust measurement reports 1 through 5.

[0098] During the verification process of the second credibility measurement report, the verification device can verify each type of information included in the report. For example, for any type of information, the verification device can compare the information of that type with a template for that type of information. If the information of that type matches the corresponding template, it means that the information of that type is not abnormal; if the information of that type does not match the corresponding template, it means that the information of that type is abnormal.

[0099] After the verification device verifies the various types of information included in the second trust measurement report according to the above method, if all types of information are normal, then the second trust measurement report is normal, and it can be determined that the multiple first trust measurement reports that are aggregated to obtain the second trust measurement report are normal. However, if one or more types of information are abnormal, then the second trust measurement report is abnormal, and it can be determined that one or more of the multiple first trust measurement reports that are aggregated to obtain the second trust measurement report are abnormal, indicating that the measured device corresponding to one or more of the first trust measurement reports is abnormal.

[0100] Therefore, in the event of an anomaly in the second credibility measurement report, the verification device can send a tracing request to the protection component, instructing the protection component to identify the abnormal device based on the anomaly in the second credibility measurement report. Thus, in this embodiment, the protection component can receive the tracing request sent by the verification device; determine the anomaly report among multiple first credibility measurement reports based on the tracing request; and determine the abnormal device corresponding to the anomaly report based on the anomaly report.

[0101] The tracing request may include an identifier of the abnormal second trusted measurement report, which may be a label or similar identifier. The protection component determines the abnormal second trusted measurement report based on this identifier, and further determines the first trusted measurement report from which the abnormal second trusted measurement report was aggregated. The first trusted measurement report from which the abnormal second trusted measurement report was aggregated can be identified as an abnormal report. Since the first trusted measurement report includes device information corresponding to it, the abnormal device that generated the abnormal report can be identified based on the device information included in the abnormal report, thus achieving tracing.

[0102] In this embodiment of the application, since device information is added to the first trust measurement report, the source can be traced based on the device information in the first trust measurement report to identify the attacked abnormal device and achieve more accurate and fine-grained device management.

[0103] The following two complete examples further illustrate the processing method of the trusted measurement report provided in this application. Referring to Figure 3, a schematic diagram of trusted verification in a heterogeneous cluster provided in this application embodiment is shown. In the heterogeneous cluster, there are multiple devices to be measured, including multiple computing devices (shown as CPU72, NPU73, and DPU75 in Figure 3; the description of each computing device can be found in the description of the computing components in Figure 1). Each computing device has its own (hardware) root of trust. When trusted verification of multiple computing devices is required, each computing device generates a corresponding trusted measurement report based on its own root of trust. These trusted measurement reports include, for example, CPU reports 1-X, NPU reports 1-Y, and DPU reports 1-Z shown in Figure 3.

[0104] The root of trust in each computing device sends the generated trust measurement report to the protection component 74 of the trusted computing system. Protection component 74 is also the security protection component in the above method embodiment. Protection component 74 can be implemented by a BMC chip, and the report root can be the TPCM in the BMC. Protection component 74 aggregates the received trust measurement reports into a comprehensive report, which can also be called a verification report, i.e., the second trust measurement report in the above method embodiment. Protection component 74 sends the comprehensive report to the Trust Management Center 71, which is also the verification device in the above method embodiment. Trust Management Center 71 verifies the received comprehensive report. If all measured devices are secure (not attacked), the comprehensive report passes verification. If one or more measured devices are insecure or abnormal (attacked), the comprehensive report fails verification, and Trust Management Center 71 will issue a task to trace the attack source.

[0105] Referring to Figure 8, a schematic diagram of the trusted verification process in a trusted computing system provided by an embodiment of this application is shown. A trusted verification request is initiated by a remote trusted management center (i.e., the verification device) and distributed via the network to the protection component BMC (i.e., the protection component) in the computing power cluster. The protection component BMC then distributes the request to various system components (i.e., the devices being measured or computing components), including the CPU, GPU, and XPU shown in the figure. Each system component's trusted root performs trusted measurement and generates a trusted measurement report, which is then transmitted back to the protection component BMC. The protection component BMC aggregates the trusted measurement reports and sends the aggregated overall report back to the remote trusted management center, which then verifies the overall report.

[0106] In summary, the second trust measurement report sent to the verification device in this application embodiment is a converged trust measurement report. The data volume of the second trust measurement report is less than the sum of the data volumes of multiple non-converged first trust measurement reports, thus reducing the amount of data transmitted with the verification device and reducing the communication cost with the verification device.

[0107] The foregoing has described the trust measurement report processing method provided in the embodiments of this application. Corresponding to the above method, the embodiments of this application also provide a protection component. This protection component is used to execute the trust measurement report processing method executed by the protection component in Figure 4 through the various modules shown in Figure 9. As shown in Figure 9, the protection component provided in the embodiments of this application includes the following modules.

[0108] The acquisition module 901 is used to acquire multiple first trusted measurement reports of multiple measured devices, and the first trusted measurement reports include device information of the corresponding measured devices; the aggregation module 902 is used to aggregate multiple first trusted measurement reports to obtain a second trusted measurement report, and the data volume of the second trusted measurement report is less than the sum of the data volumes of multiple first trusted measurement reports; the sending module 903 is used to send the second trusted measurement report to the verification device, and the second trusted measurement report is used by the verification device to verify multiple measured devices.

[0109] In one possible implementation, the acquisition module 901 is used to receive multiple third trusted measurement reports sent by multiple measured devices, the multiple third trusted measurement reports being generated by trusted roots among the multiple measured devices; add device information to the multiple third trusted measurement reports to obtain multiple first trusted measurement reports, the added device information being the information of the measured device to which the trusted root that generated the third trusted measurement report belongs.

[0110] In one possible implementation, the apparatus further includes a determining module; the determining module is configured to, for any third trust measurement report, determine the device information to be added to any third trust measurement report based on the mapping relationship between port information and device information and the port information of the port receiving the third trust measurement report.

[0111] In one possible implementation, the acquisition module 901 is used to receive multiple first trust measurement reports, the multiple first trust measurement reports including device information, the device information being added by the trust root that generated the multiple first trust measurement reports, and the device information being the information of the measured device to which the trust root belongs.

[0112] In one possible implementation, the aggregation module 902 is used to aggregate multiple first trust measurement reports according to the device type corresponding to the multiple first trust measurement reports to obtain a second trust measurement report. The number of second trust measurement reports is at least one, and the device type corresponding to the first trust measurement reports to which any second trust measurement report is aggregated is the same.

[0113] In one possible implementation, the device information includes the device type; the acquisition module 901 is also used to read the device type from multiple first trust measurement reports.

[0114] In one possible implementation, the device information includes a device identifier; the acquisition module 901 is further configured to read the device identifier from multiple first trust measurement reports; and determine the device type corresponding to the multiple first trust measurement reports based on the mapping relationship between the device identifier and the device type and the device identifier.

[0115] In one possible implementation, the apparatus further includes a receiving module; the receiving module is further configured to receive a tracing request sent by the verification device; the determining module is further configured to determine an anomaly report among multiple first trust measurement reports based on the tracing request; and determine the anomaly device corresponding to the anomaly report based on the anomaly report.

[0116] It should be understood that the protective component provided in Figure 9 has the same beneficial effects as the reliable measurement report processing method provided in Figure 4 when it performs its function, and will not be repeated here. Furthermore, the protective component provided in Figure 9 is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, and will not be repeated here.

[0117] Referring to Figure 10, Figure 10 shows a schematic diagram of the structure of an exemplary trust measurement report processing device 1000 of this application. The trust measurement report processing device 1000 includes at least one processor 1001, a memory 1003, and at least one network interface 1004.

[0118] The processor 1001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a GPU, a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits or application-specific integrated circuits (ASICs), programmable logic devices (PLDs), other general-purpose processors or other programmable logic devices, discrete gates, transistor logic devices, discrete hardware components, or any combination thereof used to implement the scheme of this application. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor. It is worth noting that the processor can be a processor supporting an advanced reduced instruction set machine (RISC) machine (ARM) architecture. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of this application. A processor can also be a combination of components that perform computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.

[0119] Optionally, the trust measurement report processing device 1000 also includes a bus 1002. The bus 1002 is used to transmit information between the components of the trust measurement report processing device 1000. The bus 1002 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 1002 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one line is used in Figure 10, but this does not mean that there is only one bus or one type of bus.

[0120] The memory 1003 may be, for example, volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache.

[0121] By way of example, but not limitation, many forms of ROM and RAM are available. For example, ROM is a compact disc read-only memory (CD-ROM). RAM includes, but is not limited to, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0122] The memory 1003 can also be other types of storage devices capable of storing static information and instructions. Alternatively, it can be other types of dynamic storage devices capable of storing information and instructions. It can also be other optical disc storage, optical disk storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. The memory 1003 may exist independently and be connected to the processor 1001 via bus 1002. The memory 1003 may also be integrated with the processor 1001.

[0123] Network interface 1004 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), or wireless local area network (WLAN). Network interface 1004 may include wired network interfaces and wireless network interfaces. Specifically, network interface 1004 can be an Ethernet interface, such as Fast Ethernet (FE), Gigabit Ethernet (GE), Asynchronous Transfer Mode (ATM), WLAN, cellular network, or combinations thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In some embodiments of this application, network interface 1004 can be used by the trust measurement report processing device 1000 to communicate with other devices.

[0124] In specific implementations, as some embodiments, processor 1001 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG10. Each of these processors may be a single-core processor or a multi-core processor. Here, processor may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0125] In specific implementations, as some embodiments, the trust measurement report processing device 1000 may include multiple processors, such as processor 1001 and processor 1005 shown in FIG10. Each of these processors may be a single-core processor or a multi-core processor. Here, a processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0126] In some embodiments, memory 1003 is used to store program instructions 1010 for executing the scheme of this application, and processor 1001 can execute the program instructions 1010 stored in memory 1003. That is, the trust measurement report processing device 1000 can implement the method provided in the method embodiment, i.e., the method shown in FIG4, through processor 1001 and program instructions 1010 in memory 1003. Program instructions 1010 may include one or more software modules. Optionally, processor 1001 itself may also store program instructions for executing the scheme of this application.

[0127] In specific implementation, the trust measurement report processing device 1000 of this application can correspond to the first network element device for executing the above method. The processor 1001 in the trust measurement report processing device 1000 reads the instructions in the memory 1003, so that the trust measurement report processing device 1000 shown in FIG10 can execute all or part of the steps in the method embodiment.

[0128] The trust measurement report processing device 1000 can also correspond to the protective component shown in FIG9 above. Each functional module in the protective component shown in FIG9 is implemented by the software of the trust measurement report processing device 1000. In other words, the functional modules included in the protective component shown in FIG9 are generated by the processor 1001 of the trust measurement report processing device 1000 after reading the program instructions 1010 stored in the memory 1003.

[0129] In the method shown in Figure 4, each step is completed through integrated logic circuits in the hardware or instructions in the software form of the processor in the trust measurement report processing device 1000. The steps of the method embodiments disclosed in this application can be directly implemented by the hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. Since the storage medium is located in memory, the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method embodiments; to avoid repetition, these will not be described in detail here.

[0130] In an exemplary embodiment, referring to FIG11, a system for processing a trusted measurement report is provided. The system includes a protection component, multiple measured devices (shown as an example of one measured device in FIG11), and a verification device. The protection component is used to acquire multiple first trusted measurement reports from the multiple measured devices, each first trusted measurement report including device information of the corresponding measured device. The protection component is also used to aggregate the multiple first trusted measurement reports to obtain a second trusted measurement report, and send the second trusted measurement report to the verification device. The data volume of the second trusted measurement report is less than the sum of the data volumes of the multiple first trusted measurement reports. The verification device is used to receive the second trusted measurement report and verify the multiple measured devices based on the second trusted measurement report.

[0131] In one possible implementation, the device being measured is used to send a third trusted measurement report to the protection component. The third trusted measurement report is generated by the root of trust in the device being measured. The protection component is used to receive multiple third trusted measurement reports sent by multiple devices being measured, and add the device information of the corresponding device being measured to the multiple third trusted measurement reports to obtain multiple first trusted measurement reports. The added device information is the information of the device being measured to which the root of trust that generated the third trusted measurement report belongs.

[0132] In another possible implementation, the device being measured is used to add device information to the obtained third trusted measurement report through the trusted root within the device being measured to obtain a first trusted measurement report, and send the first trusted measurement report to the protection component. The device information is the information of the device being measured to which the trusted root belongs. The protection component is used to receive multiple first trusted measurement reports sent by multiple devices being measured.

[0133] In one possible implementation, the multiple metric devices include one or more of a CPU, DPU, NPU, or GPU; the protection component is a BMC; and the verification device is a Trusted Management Center.

[0134] The functions and execution methods of each component in the trust measurement report processing system can be described in the example above, and will not be repeated here.

[0135] In an exemplary embodiment, a computer program (product) is provided, comprising: computer program code, which, when executed by a computer, causes the computer to perform the trust measurement report processing method in the above method embodiments.

[0136] In an exemplary embodiment, a computer-readable storage medium is provided that stores a program or instructions, and when the program or instructions are run on a computer, the method for processing the trust measurement report in the above method embodiment is executed.

[0137] In an exemplary embodiment, a chip is provided, including a processor for calling and executing instructions stored in a memory, causing a computer with the chip installed to perform the trust measurement report processing method in the above method embodiments.

[0138] In an exemplary embodiment, another chip is provided, including: an input interface, an output interface, a processor, and a memory. The input interface, output interface, processor, and memory are connected through an internal connection path. The processor is used to execute code in the memory. When the code is executed, a computer with the chip installed executes the trust measurement report processing method in the above method embodiment.

[0139] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk).

[0140] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items with substantially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor does it limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," etc., to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another.

[0141] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0142] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple second devices means two or more second devices. The terms "system" and "network" are often used interchangeably herein.

[0143] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0144] It should also be understood that the term "and / or" as used herein refers to and covers any and all possible combinations of one or more of the associated listed items. The term "and / or" describes an association between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " in this application generally indicates that the preceding and following related objects are in an "or" relationship.

[0145] It should also be understood that the terms “if” and “if” can be interpreted as meaning “when” or “upon”, or “in response to determination” or “in response to detection”. Similarly, depending on the context, the phrases “if determination…” or “if detection [the stated condition or event]” can be interpreted as meaning “when determination…”, or “in response to determination…”, or “when detection [the stated condition or event]” or “in response to detection [the stated condition or event]”.

[0146] The above description is merely an embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A method for processing a credibility measurement report, characterized in that, The method includes: The protective component acquires multiple first trusted measurement reports from multiple measured devices, wherein the first trusted measurement report includes device information of the corresponding measured device; The protective component aggregates the multiple first trust measurement reports to obtain a second trust measurement report, wherein the data volume of the second trust measurement report is less than the sum of the data volumes of the multiple first trust measurement reports; The protective component sends the second trust measurement report to the verification device, and the second trust measurement report is used by the verification device to verify the plurality of measured devices.

2. The method according to claim 1, characterized in that, The protective component acquires multiple first-credible measurement reports from multiple measured devices, including: Receive multiple third-trusted measurement reports sent by the multiple measured devices, wherein the multiple third-trusted measurement reports are generated by the trust root among the multiple measured devices; Add the corresponding device information of the measured device to the plurality of third trust measurement reports to obtain the plurality of first trust measurement reports. The added device information is the information of the measured device to which the trust root that generated the third trust measurement report belongs.

3. The method according to claim 2, characterized in that, Before adding the corresponding device information of the measured device to the plurality of third trustworthy measurement reports to obtain the plurality of first trustworthy measurement reports, the method further includes: For any third-trust measurement report, the device information to be added to the third-trust measurement report is determined based on the mapping relationship between port information and device information and the port information of the port receiving the third-trust measurement report.

4. The method according to claim 1, characterized in that, The protective component acquires multiple first-credible measurement reports from multiple measured devices, including: The system receives multiple first trusted measurement reports sent by the multiple measured devices. The multiple first trusted measurement reports include device information, which is added by the trusted root that generated the multiple first trusted measurement reports. The device information is the information of the measured device to which the trusted root belongs.

5. The method according to any one of claims 1-4, characterized in that, The protective component aggregates the multiple first trust measurement reports to obtain a second trust measurement report, including: According to the device type corresponding to the plurality of first trust measurement reports, the plurality of first trust measurement reports are aggregated to obtain a second trust measurement report. The number of second trust measurement reports is at least one, and the device type corresponding to the first trust measurement reports that are aggregated to obtain any second trust measurement report is the same.

6. The method according to claim 5, characterized in that, The device information includes the device type; Before aggregating the multiple first trust measurement reports according to their corresponding device types to obtain the second trust measurement report, the method further includes: Read the device type from the plurality of first trust metric reports.

7. The method according to claim 6, characterized in that, The device information includes a device identifier; Before aggregating the multiple first trust measurement reports according to their corresponding device types to obtain the second trust measurement report, the method further includes: Read the device identifier from the plurality of first trust measurement reports; Based on the mapping relationship between device identifier and device type, and the device identifier, the device type corresponding to the plurality of first trust measurement reports is determined.

8. The method according to any one of claims 1-7, characterized in that, The method further includes: Receive the tracing request sent by the verification device; Based on the source tracing request, identify the abnormal reports among the plurality of first trust measurement reports; Based on the anomaly report, determine the abnormal device corresponding to the anomaly report.

9. The method according to any one of claims 1-8, characterized in that, The protective component is a baseboard management controller (BMC).

10. A protective component, characterized in that, The protective component includes: The acquisition module is used to acquire multiple first trusted measurement reports of multiple measured devices, wherein the first trusted measurement report includes device information of the corresponding measured device; The aggregation module is used to aggregate the multiple first trust measurement reports to obtain a second trust measurement report, wherein the data volume of the second trust measurement report is less than the sum of the data volumes of the multiple first trust measurement reports; The sending module is used to send the second trust measurement report to the verification device, and the second trust measurement report is used by the verification device to verify the plurality of measured devices.

11. The protective component according to claim 10, characterized in that, The acquisition module is used to receive multiple third-trusted measurement reports sent by the multiple measured devices, wherein the multiple third-trusted measurement reports are generated by the trust root among the multiple measured devices; Add the corresponding device information of the measured device to the plurality of third trust measurement reports to obtain the plurality of first trust measurement reports. The added device information is the information of the measured device to which the trust root that generated the third trust measurement report belongs.

12. The protective component according to claim 10, characterized in that, The acquisition module is used to receive the plurality of first trusted measurement reports sent by the plurality of measured devices. The plurality of first trusted measurement reports include device information, which is added by the trusted root that generated the plurality of first trusted measurement reports. The device information is the information of the measured device to which the trusted root belongs.

13. The protective component according to any one of claims 10-12, characterized in that, The aggregation module is used to aggregate the multiple first trust measurement reports according to the device types corresponding to the multiple first trust measurement reports to obtain the second trust measurement report. The number of the second trust measurement reports is at least one, and the device types corresponding to the first trust measurement reports that are aggregated to obtain any second trust measurement report are the same.

14. A processing device for a credibility measurement report, characterized in that, The device includes a processor coupled to a memory; the memory stores at least one instruction, which is loaded and executed by the processor to enable the trust measurement report processing device to implement the trust measurement report processing method of any one of claims 1-9.

15. A system for processing trust measurement reports, characterized in that, The system includes protective components, multiple measurement devices, and verification devices; The protective component is used to acquire multiple first trusted measurement reports of the multiple measured devices, wherein the first trusted measurement report includes device information of the corresponding measured device. The protective component is also used to aggregate the plurality of first trust measurement reports to obtain a second trust measurement report, and send the second trust measurement report to the verification device. The data volume of the second trust measurement report is less than the sum of the data volumes of the plurality of first trust measurement reports. The verification device is configured to receive the second trust measurement report and verify the plurality of measured devices based on the second trust measurement report.

16. The system according to claim 15, characterized in that, The measured device is used to send a third trusted measurement report to the protection component, the third trusted measurement report being generated by the trusted root in the measured device; The protection component is used to receive multiple third trusted measurement reports sent by the multiple measured devices, and add the corresponding device information of the measured device to the multiple third trusted measurement reports to obtain the multiple first trusted measurement reports. The added device information is the information of the measured device to which the trusted root of the third trusted measurement report belongs.

17. The system according to claim 15, characterized in that, The device being measured is configured to add device information to the obtained third trusted measurement report through the trusted root within the device being measured, thereby obtaining the first trusted measurement report, and send the first trusted measurement report to the protection component. The device information is the information of the device being measured to which the trusted root belongs. The protective component is used to receive the plurality of first trusted measurement reports sent by the plurality of measurement devices.

18. The system according to any one of claims 15-17, characterized in that, The plurality of metric devices include one or more of a central processing unit (CPU), a data processing unit (DPU), a neural network processing unit (NPU), or a graphics processing unit (GPU).

19. The system according to any one of claims 15-18, characterized in that, The protective component is a baseboard management controller (BMC).

20. The system according to any one of claims 15-19, characterized in that, The verification device is a trusted management center.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction, which is loaded and executed by a processor to implement the processing method for a trust measurement report as described in any one of claims 1-9.

22. A computer program product, characterized in that, The computer program product includes a computer program / instruction that is executed by a processor to enable the computer to implement the processing method for the trust measurement report as described in any one of claims 1-9.

Citation Information

Patent Citations

  • File processing method, file processing server, file aggregation server and device

    CN112749129A

  • Distributed message queue stream verification

    US20170310628A1

  • Devices for Measuring and / or Reporting in a Wireless Communication Network

    US20230189382A1

  • System and method for enforcing a third-party factory test

    US8214692B1