Data protection method and apparatus, and device
By obtaining the integrity measurement report of the data access device through the data storage device, the hardware and software environment is verified, which solves the problem of insufficient security during data transmission and realizes data processing and efficient verification in a secure environment.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2025-09-24
- Publication Date
- 2026-04-23
AI Technical Summary
In the existing verification process between data access devices and data storage devices, the data storage device cannot guarantee that the data will be processed in a secure environment after being transmitted to the data access device, which poses a risk of data eavesdropping, theft, or leakage.
The data storage device obtains the integrity measurement report of the data access device, and verifies the hardware and software environment of the data access device based on the report, including hardware integrity and software integrity, and uses signature information and memory isolation technology to ensure the security of data during transmission.
This effectively ensures that data is processed in a secure environment after being transmitted to the data access device, thereby improving the security of data transmission and the efficiency of verification.
Smart Images

Figure CN2025123788_23042026_PF_FP_ABST
Abstract
Description
A data protection method, apparatus and equipment
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411445883.7, filed on October 15, 2024, entitled “A Data Protection Method, Apparatus and Device”, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of communication technology, and in particular to a data protection method, apparatus and device. Background Technology
[0004] After a data access device retrieves data from a data storage device, it processes the retrieved data. The retrieved data exists in plaintext format within the data access device's memory. Data stored in plaintext format in memory is vulnerable to being eavesdropped on, stolen, or leaked by malicious programs.
[0005] Currently, in the authentication process between data access devices and data storage devices, such as the Challenge Handshake Authentication Protocol (CHAP) authentication process, the data storage device only verifies the data access device using the key certificate provided by the data access device. In this authentication method, the key certificate can only prove the identity of the data access device, that is, that the data access device is a "correct" device, but it cannot guarantee that the data transmitted from the data storage device to the data access device is not easily eavesdropped, stolen, or leaked. Summary of the Invention
[0006] This application provides a data protection method, apparatus, and device to ensure the security of data transmitted from the data storage device to the data access device.
[0007] Firstly, embodiments of this application also provide a data protection method, executed by a data storage device, wherein the data storage device is capable of acquiring a first integrity measurement report. The first integrity measurement report indicates the data processing environment within a data access device, and the data processing environment indicates the hardware and / or software environment within the data access device. Embodiments of this application do not limit the manner in which the data storage device acquires the first integrity measurement report. For example, the data storage device may exchange information with a data access device, allowing the data storage device to acquire the first integrity measurement report from the data access device. Alternatively, the data access device may send the first integrity measurement report to another device (such as a trusted third-party organization), allowing the data storage device to acquire the first integrity measurement report from that other device.
[0008] After obtaining the first integrity measurement report, the data storage device uses the first integrity measurement report to understand the data processing environment in the data access device and verifies the data access device based on the first integrity measurement report.
[0009] After the data access device has been verified, the data storage device receives and processes the data access request sent by the data access device. The data access request is used to request access to the data in the data storage device.
[0010] Through the above method, the data access device can provide a first integrity measurement report to the data storage device, so that the data storage device can learn about the data processing environment inside the data access device from the first integrity measurement report, thereby ensuring that the data in the data storage device is processed in a relatively safe environment after being transmitted to the data access device, effectively ensuring data security.
[0011] In one possible implementation, the first integrity measurement report is generated by the hardware of the data access device. Generating the first integrity measurement report by the hardware in the data access device ensures that the generation method of the first integrity measurement report cannot be easily tampered with or attacked by malicious software, thereby guaranteeing the reliability of the first integrity measurement report.
[0012] In one possible implementation, the data processing environment includes some or all of the following:
[0013] The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates data access requests.
[0014] Using the above method, the data processing environment includes a hardware environment and / or a software environment. The first integrity measurement report can reflect the security of the data access device from the hardware and / or software level. The data access device is verified based on the first integrity measurement report, that is, the hardware and software of the data access device are verified, and the security of the data access device can be measured from different dimensions.
[0015] In one possible implementation, the target application possesses memory isolation properties. Memory isolation means that the target application has a target memory space configured within the data access device, which can only be accessed by the target application. Other applications within the data access device cannot access this target memory space; these other applications can be the operating system, virtual machine, computing instance, etc., on the data access device.
[0016] Through the above method, the memory isolation attribute ensures that the target application can only process data within the target memory space, which can better guarantee data security. The data access device can reflect the memory isolation attribute of the target application through the first integrity measurement report, so that the data storage device can determine that the target application can achieve "true" memory isolation.
[0017] In one possible implementation, the first integrity measurement report includes first signature information, which is generated by the data access device signing the first integrity measurement report using its own key (such as a root key within the hardware). When the data storage device verifies the data access device based on the first integrity measurement report, it can verify the first signature information.
[0018] The above method utilizes the first signature information to ensure the integrity of the first integrity measurement report and the ownership of the first integrity measurement report.
[0019] In one possible implementation, the data storage device may send a first challenge value to the data access device. The first integrity measurement report acquired by the data storage device, carrying the first challenge value, can guarantee the validity of the first integrity measurement report.
[0020] In one possible implementation, the first integrity measurement report includes a first hardware integrity report and / or a first program integrity report. The first hardware integrity report is used to characterize information about the hardware in the data access device, and the first program integrity report is used to characterize the startup process and / or running status of the target application in the data access device.
[0021] Using the above method, the data storage device can understand whether the hardware on the data access device side is trustworthy through the first hardware integrity report, and determine whether the startup process and running status of the target application in the data access device are normal through the first program integrity report.
[0022] In one possible implementation, the first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device; the first program integrity report includes a first startup metric value and / or a first running metric value, which is generated based on the startup process of the target application and the first running metric value is generated based on the running status of the target application.
[0023] The embodiments of this application do not limit the method of generating the first hardware metric. For example, the first hardware metric includes hardware information of the data access device (such as the processor model), and may also include information related to the firmware program running on the hardware (such as the hash value of the firmware on the processor, where the hash value of the firmware is the hash value after hashing the firmware).
[0024] By using the above method, the hardware information of the data access device, the startup process of the target application, and the running status are characterized by the measurement values (such as the first hardware measurement value, the first startup measurement value, and the first running measurement value). The representation method is simpler and effectively simplifies the first integrity measurement report.
[0025] In one possible implementation, when the data storage device verifies the data access device based on the first integrity metric report, it may perform the following three operations:
[0026] Step 1: Compare the first hardware metric value with the first reference hardware metric value to determine whether the first hardware metric value meets the first reference hardware metric value. If it does, the data storage device determines that the hardware of the data access device is trustworthy; otherwise, the verification fails. The first reference hardware metric value is a metric value generated based on information about trustworthy hardware, and it corresponds to a reference hardware metric value pre-configured in the data storage device in this embodiment of the application.
[0027] Step 2: Compare the first startup metric value with the first reference startup metric value to determine whether the first startup metric value meets the first reference startup metric value. If it does, the data storage device determines that the startup process of the target application of the data access device is normal; otherwise, it is abnormal. The first reference startup metric value is generated based on the normal startup process of the target application.
[0028] Step 3: Compare the first operational metric value with the first reference operational metric value to determine if the first operational metric value meets the first reference operational metric value. If it does, the data storage device determines that the target application of the data access device is running normally; otherwise, it is not. The first reference operational metric value is generated based on the normal operating status of the target application.
[0029] The data access device's hardware, the target application's startup process, and the target application's running state are partially or entirely trustworthy, and the data access device has been verified.
[0030] The above method verifies the data access device by comparing the measurement values. This verification method is simpler, faster, and improves verification efficiency.
[0031] In one possible implementation, the data storage device can determine the identity information of the target application based on a first integrity measurement report. This application embodiment does not limit the method by which the data storage device determines the identity information of the target application based on the first integrity measurement report. For example, the data storage device assigns identity information to the target application after verifying the first integrity measurement report. Alternatively, the data storage device obtains information related to the target application (such as a first startup measurement value or a second running measurement value) from the first integrity measurement report and generates identity information for the target application based on this information. The data storage device can control data access requests based on the identity information, that is, determine whether it can process the data access request.
[0032] By assigning identity information to target applications using the above method, different target applications can be distinguished, making it easier to differentiate the data that different target applications need to access. Then, when a data access request is received, it can be determined whether the data requested by the data access request is allowed to be accessed by the target application.
[0033] In one possible implementation, the data storage device can generate a second integrity measurement report, which indicates the data storage environment within the data storage device, and the data storage environment indicates the hardware environment and / or software environment within the data storage device.
[0034] The data storage device can provide a second integrity measurement report, such as by sending the second integrity measurement report directly to the data access device; or by sending the second integrity measurement report to other devices (such as a trusted third party), from which the data access device can obtain the second integrity measurement report.
[0035] Using the above method, the data storage device can verify its own data storage environment through the second integrity measurement report, so that the data access device can verify the data storage device based on the second integrity measurement report, ensuring that the data storage device can securely store the data of the data access device.
[0036] In one possible implementation, the second integrity measurement report is generated by the hardware of the data storage device. The hardware-generated second integrity measurement report is reliable, further ensuring the accuracy of the verification results obtained by the data access device when verifying the data storage device based on the second integrity measurement report.
[0037] In one possible implementation, the data storage environment includes some or all of the following:
[0038] The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is the application deployed on the data storage device that needs to be called when storing data.
[0039] Using the above method, the data storage environment includes a hardware environment and / or a software environment. The second integrity measurement report can reflect the security of the data access device from the hardware and / or software level. The data storage device is verified based on the second integrity measurement report, that is, the hardware and software of the data storage device are verified, and the security of the data storage device can be measured from different dimensions.
[0040] In one possible implementation, the storage application possesses memory isolation properties. Memory isolation means that the storage application has its own dedicated memory space within the data storage device, which can only be accessed by the storage application. Other applications within the data storage device cannot access this memory space; these other applications can be the operating system running on the data storage device, as well as some higher-level management applications.
[0041] By employing the above method, because the storage application possesses memory isolation properties, the operations performed by the storage application during data storage are secure and not easily interfered with by malicious programs, ensuring that data can be securely stored in the data storage device. The data storage device can reflect the memory isolation properties of the storage application through this second integrity metric report, so that the data access device can determine that the storage application can achieve "true" memory isolation.
[0042] In one possible implementation, the second integrity measurement report includes second signature information. This second signature information is generated by the data storage device signing the second integrity measurement report using its own key (such as a root key within the hardware). This allows the data access device to verify the second signature information when authenticating the data storage device based on the second integrity measurement report.
[0043] The above method utilizes the second signature information to ensure the integrity of the second integrity measurement report and its ownership.
[0044] In one possible implementation, before generating the first integrity measurement report, the data storage device receives a second challenge value sent by the data access device. When generating the second integrity measurement report, the data storage device includes the second challenge value in the second integrity measurement report to ensure its validity.
[0045] In one possible implementation, the second integrity measurement report includes a second hardware integrity report and a second program integrity report. The second hardware integrity report is used to characterize information about the hardware in the data storage device, and the second program integrity report is used to characterize the startup process and / or running status of the stored application in the data storage device.
[0046] The above method enables the data access device to understand whether the hardware on the data storage device side is trustworthy through the first hardware integrity report, and to determine whether the startup process and running status of the stored application in the data storage device are normal through the first program integrity report.
[0047] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value and / or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0048] By using the above method, the hardware information of the data storage device, the startup process of the storage application, and the running status are characterized by the measurement values (such as the second hardware measurement value, the second startup measurement value, and the second running measurement value). The representation method is simpler and effectively simplifies the second integrity measurement report.
[0049] In one possible implementation, the storage application includes some or all of the following:
[0050] Data integrity procedures, identity mapping procedures;
[0051] The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the target application's identity information.
[0052] Through the above method, the identity mapping procedure ensures that the data storage device accurately identifies the target application using its identity information, and achieves data isolation for the target application within the data storage device using this identity information. The data integrity procedure guarantees that the data storage device can completely protect the data accessed by the target application.
[0053] In one possible implementation, the data storage device receives a data processing request from a data access device, the data processing request being used to request the execution of a target operation on data belonging to a target application. After executing the target operation on the data belonging to the target application, the data storage device provides an operation credential to the data access device, the operation credential indicating that the target operation has been completed, and the operation credential is generated based on the process of executing the target operation on the data required for access by the target application.
[0054] Using the above method, the data storage device can perform target operations on data belonging to the target application upon request from the data access device; and the operation credentials are used to verify that the data storage device has actually performed the target operation.
[0055] In one possible implementation, the data storage device may acquire the first integrity measurement report during the connection establishment process with the data access device, and then verify the data access device based on the first integrity measurement report. Alternatively, the data storage device may acquire the first integrity measurement report after establishing a connection with the data access device. For example, the data storage device may acquire the first integrity measurement report periodically, and after each acquisition, verify the data access device based on the first integrity measurement report.
[0056] The above method provides a flexible way for data storage devices to obtain the first integrity measurement report, making it suitable for different application scenarios.
[0057] Secondly, this application also provides a data protection method, which can be executed by a data access device. The beneficial effects are described in the relevant description of the first aspect and will not be repeated here. In this method: the data access device generates a first integrity measurement report; the data access device provides the first integrity measurement report to a data storage device. The first integrity measurement report is used to indicate the data processing environment within the data access device. This application does not limit the manner in which the data access device provides the first integrity measurement report to the data storage device. For example, the data access device can directly send the first integrity measurement report to the data storage device. Alternatively, the data access device can provide the first integrity measurement report to the data storage device through other devices (such as a trusted third party).
[0058] The data access device obtains the verification result, which indicates that the data storage device has successfully verified the data access device.
[0059] The data access device sends a data access request to the data storage device. The data access request is used to request access to the data in the data storage device.
[0060] The predefined verification interaction methods between the data access device and the data storage device differ, and therefore, the methods by which the data access device obtains the verification results also differ. This application does not limit the method by which the data access device obtains the verification results. For example, after the data storage device successfully verifies the data access device, it can send the verification result to the data access device. Alternatively, if the data storage device successfully verifies the data access device, it can continue to interact with the data access device; if the verification fails, the data storage device may stop sending information to the data access device. If the data access device receives information from the data storage device after the data storage device has provided a first integrity measurement report, it can consider itself to have obtained the verification result.
[0061] In one possible implementation, the first integrity metric report is generated by the hardware of the data access device.
[0062] In one possible implementation, the data processing environment includes some or all of the following:
[0063] The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates data access requests.
[0064] In one possible implementation, the target application has memory isolation properties.
[0065] In one possible implementation, the first integrity measurement report includes first signature information.
[0066] In one possible implementation, the first integrity measurement report carries a first challenge value. The data access device receives the first challenge value sent by the data storage device and carries the first challenge value in the first integrity measurement report when generating the first integrity measurement report.
[0067] In one possible implementation, the first integrity measurement report includes a first hardware integrity report and a first program integrity report. The first hardware integrity report is used to characterize information about the hardware in the data access device, and the first program integrity report is used to characterize the startup process and / or running status of the target application in the data access device.
[0068] In one possible implementation, the first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device; the first program integrity report includes a first startup metric value and a first running metric value, which is generated based on the startup process of the target application and the first running metric value is generated based on the running status of the target application.
[0069] In one possible implementation, the data access device may also obtain a second integrity measurement report, which is used to indicate the data storage environment within the data storage device. The way in which the data access device obtains the second integrity measurement report is similar to the way in which the data storage device obtains the first integrity measurement report, as detailed in the foregoing description.
[0070] The data access device verifies the data storage device based on the second integrity measurement report. After the data storage device passes the verification based on the second integrity measurement report, the data access device sends a data access request to the data storage device.
[0071] In one possible implementation, the second integrity metric report is generated by the hardware of the data storage device.
[0072] In one possible implementation, the data storage environment includes some or all of the following:
[0073] The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is the application deployed on the data storage device that needs to be called when storing data.
[0074] In one possible implementation, the storage application has the property of memory isolation.
[0075] In one possible implementation, the second integrity measurement report includes second signature information.
[0076] In one possible implementation, the data access device sends a second challenge value to the data storage device. The second challenge value is carried in a second integrity metric report obtained by the data access device.
[0077] In one possible implementation, the second integrity measurement report includes a second hardware integrity report and / or a second program integrity report. The second hardware integrity report is used to characterize information about the hardware in the data storage device, and the second program integrity report is used to characterize the startup process and / or running status of the stored application in the data storage device.
[0078] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value and / or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0079] In one possible implementation, when the data access device verifies the data storage device based on the second integrity metric report, it can perform the following three operations:
[0080] Step 1: Compare the second hardware metric value with the second reference hardware metric value to determine whether the second hardware metric value meets the second reference hardware metric value. If it does, the data access device determines that the hardware of the data storage device is trustworthy; otherwise, the verification fails. The second reference hardware metric value is a metric value generated based on information about trustworthy hardware, and it corresponds to the reference hardware metric value pre-configured in the data access device in this embodiment.
[0081] Step 2: Compare the second startup metric value with the second reference startup metric value to determine whether the second startup metric value meets the second reference startup metric value. If it does, the data access device determines that the startup process of the storage application of the data storage device is normal; otherwise, it is abnormal. The second reference startup metric value is generated based on the normal startup process of the storage application.
[0082] Step 3: Compare the second operational metric with the second reference operational metric to determine if the second operational metric meets the second reference operational metric. If it does, the data access device determines that the storage application of the data storage device is operating normally; otherwise, it is not. The second reference operational metric is generated based on the normal operating status of the storage application.
[0083] The data storage device's hardware, the startup process of the storage application, and the running state of the storage application are partially or entirely trustworthy, and the data storage device has been verified.
[0084] The above method verifies the data access device by comparing the measurement values. This verification method is simpler and faster, effectively ensuring improved verification efficiency.
[0085] In one possible implementation, the storage application includes some or all of the following:
[0086] Data integrity procedures, identity mapping procedures;
[0087] The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the target application's identity information.
[0088] In one possible implementation, the data access device sends a data processing request to the data storage device, the data processing request being used to request the execution of a target operation on data belonging to the target application.
[0089] The data access device obtains operation credentials from the data storage device and audits the executed target operation based on the operation credentials. The operation credentials indicate that the target operation has been completed, and are generated based on the process of performing the target operation on data belonging to the target application.
[0090] In one possible implementation, when the data access device provides the first integrity measurement report, it may do so during the process of establishing a connection with the data storage device, or periodically after establishing a connection with the data storage device.
[0091] Thirdly, embodiments of this application also provide a data protection system, which includes a data access device and a data storage device. The beneficial effects are described in the first aspect and will not be repeated here. In this data transmission system:
[0092] A data storage device is configured to: acquire a first integrity measurement report, the first integrity measurement report indicating the data processing environment within the data access device, the data processing environment indicating the hardware environment and / or software environment within the data access device; verify the data access device based on the first integrity measurement report; and, after the data access device has been verified, receive and process a data access request sent by the data access device, the data access request being used to request access to data in the data storage device.
[0093] A data access device is used to generate and provide a first integrity measurement report to the data storage device; obtain a verification result, which indicates that the data storage device has passed the verification of the data access device; and send a data access request to the data storage device, which is used to request access to data in the data storage device.
[0094] In one possible implementation, the first integrity metric report is generated by the hardware of the data access device.
[0095] In one possible implementation, the data processing environment includes some or all of the following:
[0096] The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that needs to access data in the data storage device.
[0097] The target application has memory isolation properties.
[0098] In one possible implementation, the data storage device determines the identity information of the target application based on the first integrity measurement report; and controls the data access request based on the identity information.
[0099] In one possible implementation, the data access device signs the first integrity measurement report to generate first signature information. The first integrity measurement report includes the first signature information.
[0100] When the data storage device verifies the data access device based on the first integrity measurement report, it verifies the first signature information.
[0101] In one possible implementation, the data storage device sends a first challenge value to the data access device. The data access device then includes the first challenge value in the first integrity measurement report it generates.
[0102] In one possible implementation, the first integrity measurement report includes a first hardware integrity report and / or a first program integrity report. The first hardware integrity report is used to characterize information about the hardware in the data access device, and the first program integrity report is used to characterize the startup process and / or running status of the target application in the data access device.
[0103] In one possible implementation, the first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device; the first program integrity report includes a first startup metric value and / or a first running metric value, which is generated based on the startup process of the target application and the first running metric value is generated based on the running status of the target application.
[0104] In one possible implementation, when the data storage device verifies the data access device based on the first integrity metric report, it compares a first hardware metric value with a first reference hardware metric value, wherein the first reference hardware metric value is a metric value generated based on information about trusted hardware; the data storage device compares a first startup metric value with the first reference startup metric value, and compares a first running metric value with the first reference running metric value, wherein the first reference startup metric value is generated based on the normal startup process of the target application, and the first reference running metric value is generated based on the normal operating state of the target application.
[0105] In one possible implementation, the data storage device generates a second integrity measurement report, which indicates the data storage environment within the data storage device, and the data storage environment indicates the hardware environment and / or software environment within the data storage device; and provides the second integrity measurement report to the data access device.
[0106] In one possible implementation, the second integrity metric report is generated by the hardware of the data storage device.
[0107] In one possible implementation, the data storage environment includes some or all of the following:
[0108] The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is the application deployed on the data storage device that needs to be called when storing data.
[0109] In one possible implementation, the storage application has the property of memory isolation.
[0110] In one possible implementation, the data storage device signs the second integrity measurement report to generate second signature information. The second integrity measurement report includes the second signature information.
[0111] When the data access device verifies the data storage device based on the second integrity measurement report, it verifies the second signature information.
[0112] In one possible implementation, the data access device sends a second challenge value to the data storage device. Upon receiving the second challenge value, the data storage device includes it in a second integrity metric report.
[0113] In one possible implementation, the second integrity measurement report includes a second hardware integrity report and / or a second program integrity report. The second hardware integrity report is used to characterize information about the hardware in the data storage device, and the second program integrity report is used to characterize the startup process and / or running status of the stored application in the data storage device.
[0114] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value and / or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0115] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value and / or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0116] In one possible implementation, when verifying the data storage device, the data access device compares a second hardware metric with a second reference hardware metric to determine whether the second hardware metric meets the second reference hardware metric. The second reference hardware metric is a metric generated based on information about trusted hardware. The data access device also compares a second startup metric with a second reference startup metric to determine whether the second startup metric meets the second reference startup metric. Furthermore, the data access device compares a second running metric with a second reference running metric to determine whether the second running metric meets the second reference running metric. The second reference startup metric is generated based on the normal startup process of the target application. The second reference running metric is generated based on the normal operating state of the target application.
[0117] The data storage device is verified if one or more of the following conditions are met:
[0118] 1. The second hardware metric satisfies the second reference hardware metric.
[0119] 2. The second startup metric satisfies the second reference startup metric.
[0120] 3. The second operating metric satisfies the second reference operating metric.
[0121] In one possible implementation, the storage application includes some or all of the following:
[0122] Data integrity procedures, identity mapping procedures;
[0123] The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the target application's identity information.
[0124] In one possible implementation, the data access device sends a data processing request to the data storage device, the data processing request being used to request the execution of a target operation on data belonging to the target application.
[0125] The data storage device receives a data processing request and, after performing a target operation on data belonging to the target application, provides an operation credential to the data access device. The operation credential indicates that the target operation has been completed and is generated based on the process of performing the target operation on the data belonging to the target application. The data access device obtains the operation credential and audits the executed target operation based on it.
[0126] In one possible implementation, the data storage device may obtain the first integrity measurement report during the process of establishing a connection with the data access device, or it may obtain the first integrity measurement report periodically.
[0127] Fourthly, this application also provides a data storage device that has the function of implementing the behavior in the method example of the first aspect described above. The beneficial effects can be found in the description of the first aspect and will not be repeated here. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the data storage device includes a second hardware security module and a second verification module. Optionally, it may also include a stored procedure management module and a stored application program. These modules can execute the corresponding functions in the method example of the first aspect described above, as detailed in the method example. In this data storage device:
[0128] The second verification module is used to obtain a first integrity measurement report, which indicates the data processing environment within the data access device. The data processing environment indicates the hardware and / or software environment within the data access device. The data access device is verified based on the first integrity measurement report.
[0129] The storage application is used to receive and process data access requests sent by the data access device after the second verification module has verified the data access device. The data access requests are used to request access to data in the data storage device.
[0130] In one possible implementation, the first integrity metric report is generated by the hardware of the data access device.
[0131] In one possible implementation, the data processing environment includes some or all of the following:
[0132] The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates data access requests.
[0133] In one possible implementation, the target application has memory isolation properties.
[0134] In one possible implementation, the first integrity measurement report includes first signature information, and when the first verification module verifies the data access device based on the first integrity measurement report, it verifies the first signature information.
[0135] In one possible implementation, the first integrity measurement report carries a first challenge value, and the first verification module sends the first challenge value to the data access device before obtaining the first integrity measurement report.
[0136] In one possible implementation, the first integrity metric report includes one or more of the following:
[0137] First Hardware Integrity Report, First Program Integrity Report;
[0138] The first hardware integrity report is used to characterize the hardware information in the data access device, and the first program integrity report is used to characterize the startup process or running status of the target application in the data access device.
[0139] In one possible implementation, the first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device; the first program integrity report includes a first startup metric value or a first running metric value, which is generated based on the startup process of the target application and the first running metric value is generated based on the running status of the target application.
[0140] In one possible implementation, the first verification module may obtain a first integrity measurement report during the process of establishing a connection with the data access device; the first verification module may also periodically obtain the first integrity measurement report.
[0141] In one possible implementation, the first verification module verifies the data access device based on a first integrity measurement report, performing one or more of the following:
[0142] Operation 1: Compare the first hardware metric value with the first reference hardware metric value.
[0143] Step 2: Compare the first startup metric value with the first reference startup metric value.
[0144] Step 3: Compare the first running metric value with the first reference running metric value.
[0145] Among them, the first reference hardware metric is a metric generated based on information about trusted hardware, the first reference startup metric is generated based on the normal startup process of the target application, and the first reference running metric is generated based on the normal running state of the target application.
[0146] In one possible implementation, the storage application determines the identity information of the target application based on the first integrity metric report, and controls data access requests based on the identity information.
[0147] In one possible implementation, the second hardware security module can generate a second integrity measurement report, which indicates the data storage environment within the data storage device, specifying the hardware and / or software environment within the data storage device. The second verification module can provide the second integrity measurement report, such as by providing it to a data access device.
[0148] In one possible implementation, the second hardware security module is hardware.
[0149] In one possible implementation, the data storage environment includes some or all of the following:
[0150] The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is the application deployed on the data storage device that needs to be called when storing data.
[0151] In one possible implementation, the storage application has the property of memory isolation.
[0152] In one possible implementation, the second integrity measurement report includes second signature information.
[0153] In one possible implementation, the second integrity metric report carries a second challenge value, and the second verification module can receive the second challenge value sent by the data access device.
[0154] In one possible implementation, the second integrity measurement report includes one or more of the following:
[0155] Second hardware integrity report, second program integrity report;
[0156] The second hardware integrity report is used to characterize the hardware information in the data storage device, and the second program integrity report is used to characterize the startup process or running status of the stored application in the data storage device.
[0157] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0158] In one possible implementation, the storage application includes some or all of the following:
[0159] Data integrity procedures, identity mapping procedures;
[0160] The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the target application's identity information.
[0161] In one possible implementation, the apparatus further includes a stored procedure management module that receives a data processing request from a data access device, the data processing request being used to request the execution of a target operation on data that a target application needs to access.
[0162] After performing the target operation on the data required by the target application, the stored procedure management module provides an operation credential to the data access device. This operation credential is used by the data access device to audit the executed target operation. The operation credential can be used to indicate that the target operation has been completed, and it is generated based on the process of performing the target operation on the data required by the target application.
[0163] Fifthly, embodiments of this application also provide a data access device that has the function of implementing the behavior in the method example of the second aspect described above. The beneficial effects can be found in the description of the second aspect and will not be repeated here. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the structure of the data access device includes a first hardware security module, a first verification module, and optionally, an application management module and a target application. In this data access device:
[0164] The first hardware security module is used to generate a first integrity measurement report, which is used to indicate the data processing environment within the data access device.
[0165] The first verification module is used to provide a first integrity measurement report; obtain verification results, and the verification results indicate that the data storage device has verified the data access device according to the first integrity measurement report.
[0166] The target application is used to send a data access request to the data storage device, which is used to request access to data in the data storage device.
[0167] In one possible implementation, the first hardware security module is the hardware of the data access device.
[0168] In one possible implementation, the data processing environment includes some or all of the following:
[0169] The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates data access requests.
[0170] In one possible implementation, the target application has memory isolation properties.
[0171] In one possible implementation, the first integrity measurement report includes first signature information.
[0172] In one possible implementation, the first integrity measurement report carries a first challenge value, and the first verification module receives the first challenge value sent by the data storage device before generating the first integrity measurement report.
[0173] In one possible implementation, the first integrity metric report includes one or more of the following:
[0174] First Hardware Integrity Report, First Program Integrity Report;
[0175] The first hardware integrity report is used to characterize the hardware information in the data access device, and the first program integrity report is used to characterize the startup process or running status of the target application in the data access device.
[0176] In one possible implementation, the first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device; the first program integrity report includes a first startup metric value or a first running metric value, which is generated based on the startup process of the target application and the first running metric value is generated based on the running status of the target application.
[0177] In one possible implementation, the first verification module may provide a first integrity measurement report during the process of establishing a connection with the data storage device; or it may periodically provide a first integrity measurement report to the data storage device.
[0178] In one possible implementation, the first verification module obtains a second integrity measurement report before the target application sends a data access request to the data storage device. The second integrity measurement report indicates the data storage environment within the data storage device, which in turn indicates the hardware and / or software environment within the data storage device. The first verification module verifies the data storage device based on the second integrity measurement report.
[0179] In one possible implementation, the second integrity metric report is generated by the hardware of the data storage device.
[0180] In one possible implementation, the data storage environment includes some or all of the following:
[0181] The hardware of the data storage device and the storage applications within the data storage device.
[0182] Among them, the storage application is the application deployed on the data storage device that needs to be called when storing data.
[0183] In one possible implementation, the storage application has the property of memory isolation.
[0184] In one possible implementation, the second integrity measurement report includes second signature information.
[0185] In one possible implementation, the second integrity metric report carries a second challenge value, which the first verification module sends to the data storage device before obtaining the first integrity metric report.
[0186] In one possible implementation, the second integrity measurement report includes one or more of the following:
[0187] Second hardware integrity report, second program integrity report.
[0188] The second hardware integrity report is used to characterize the hardware information in the data storage device, and the second program integrity report is used to characterize the startup process and running status of the stored application in the data storage device.
[0189] In one possible implementation, the second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device; the second program integrity report includes a second startup metric value or a second running metric value, which is generated based on the startup process of the storage application and the second running metric value is generated based on the running status of the storage application.
[0190] In one possible implementation, the first verification module verifies the data storage device based on the second integrity metric report, which includes one or more of the following:
[0191] The first and second hardware metrics satisfy the second reference hardware metric.
[0192] The second item, the second startup metric, satisfies the second reference startup metric.
[0193] The third item and the second operating metric value satisfy the second reference operating metric value.
[0194] The second reference hardware metric is generated based on information about trusted hardware; the second reference startup metric is generated based on the normal startup process of the storage application; and the second reference running metric is generated based on the normal running state of the storage application.
[0195] In one possible implementation, the storage application includes some or all of the following:
[0196] Data integrity procedures, identity mapping procedures.
[0197] The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the target application's identity information.
[0198] In one possible implementation, the data access device further includes an application management module; the application management module sends a data processing request to the data storage device, the data processing request being used to request the execution of a target operation on the data required by the target application; the application management module obtains an operation credential from the data storage device, and audits the executed target operation based on the operation credential. The operation credential can be used to indicate that the target operation has been completed, and the operation credential is generated based on the process of executing the target operation on the data required by the target application.
[0199] Sixthly, this application also provides a computing device, which includes a processor and a memory, and may further include a communication interface. The processor executes program instructions in the memory to perform the method provided by the first aspect or any possible implementation thereof. Alternatively, the processor executes program instructions in the memory to perform the method provided by the second aspect or any possible implementation thereof. The memory is coupled to the processor and stores computer program instructions and data necessary for determining data transmission. The communication interface is used for communicating with other devices.
[0200] In a seventh aspect, this application provides a computing device system comprising at least one computing device. Each computing device includes a memory and a processor. The processor of at least one computing device is configured to access code in the memory to execute the method provided by the first aspect or any possible implementation thereof, or the processor of at least one computing device is configured to access code in the memory to execute the method provided by the second aspect or any possible implementation thereof.
[0201] Eighthly, this application provides a computer-readable storage medium that, when executed by a computing device, allows the computing device to perform the method provided in the first aspect or any possible implementation thereof, or to perform the method provided in the second aspect or any possible implementation thereof. The storage medium stores computer program instructions. The storage medium includes, but is not limited to, volatile memory, such as random access memory, and non-volatile memory, such as flash memory, hard disk drive (HDD), and solid-state drive (SSD).
[0202] Ninthly, this application provides a computer device program product, which includes computer program instructions. When executed by a computing device, the computing device performs the method provided in the first aspect or any possible implementation thereof, or performs the method provided in the second aspect or any possible implementation thereof. The computer program product can be a software installation package. When it is necessary to use the method provided in the first aspect or any possible implementation thereof, or when it is necessary to use the method provided in the second aspect or any possible implementation thereof, the computer program product can be downloaded and executed on the computing device.
[0203] In a tenth aspect, this application also provides a computer chip connected to a memory, the chip being used to read and execute computer program instructions stored in the memory, to execute the methods in the first aspect and various possible implementations of the first aspect, or to execute the methods in the second aspect and various possible implementations of the second aspect. Attached Figure Description
[0204] Figure 1 is a schematic diagram of a Merkle tree provided in this application;
[0205] Figure 2 is a schematic diagram of a data protection system provided in this application;
[0206] Figure 3A is a schematic diagram of the structure of a data access device provided in this application;
[0207] Figure 3B is a schematic diagram of a data storage device provided in this application;
[0208] Figure 4 is a schematic diagram of a data protection method provided in this application;
[0209] Figure 5 is a schematic diagram of the structure of a data access system provided in this application;
[0210] Figure 6 is a schematic diagram of a data protection method provided in this application;
[0211] Figures 7A and 7B are schematic diagrams illustrating the deployment of a data access device and a data storage device provided in this application.
[0212] Figures 8 and 9 are schematic diagrams of the structure of a computing device provided in an embodiment of this application. Detailed Implementation
[0213] Before introducing a data transmission method provided in the embodiments of this application, some concepts involved in the embodiments of this application should be clarified:
[0214] (1) Transport layer security (TLS).
[0215] The TLS protocol is built on top of the TCP protocol at the transport layer and serves the application layer. It encrypts application layer messages before handing them over to TCP for transmission.
[0216] The TLS protocol stipulates that both communicating parties must encrypt the transmitted data, ensure the integrity of the data during transmission, and authenticate each other.
[0217] The TLS protocol consists of two layers. The first layer is the TLS record protocol, which specifies the use of a symmetric key to encrypt transmitted data. The second layer is the TLS handshake protocol, which mainly consists of four parts: the handshake protocol, the cipher specification change protocol, the warning protocol, and the application data protocol.
[0218] The handshake protocol defines how the communicating parties negotiate the data encryption algorithm and share the key. The cryptographic specification change protocol defines how to notify the other party of the key change if one party changes its key. The warning protocol defines how to transmit an error (or failure) to the other party when one party encounters it. The application data protocol defines how one party conveys application data carried by TLS to the other party.
[0219] (2) Data encryption algorithm.
[0220] Data encryption algorithms include symmetric encryption algorithms and asymmetric encryption algorithms.
[0221] The characteristic of symmetric encryption algorithms is that the same key is used for both encrypting and decrypting data.
[0222] Asymmetric encryption algorithms are characterized by using different keys for encrypting and decrypting data. These different keys are typically divided into a public key and a private key. Data encrypted with the public key can be decrypted using the private key, and vice versa. Generally speaking, the public key is public and can be obtained by any device or apparatus, while the private key is not public and can only be known and kept by the owner of the key.
[0223] (3) Signature and verification.
[0224] Signing the data to be sent (such as the first integrity measurement report or the second integrity measurement report involved in the embodiments of this application) is a method to ensure data integrity and non-repudiation. Signing and signature verification are essentially asymmetric encryption algorithms.
[0225] A signature is a string generated by the sender of data based on the data to be sent and their own private key. For example, the sender extracts a portion of the data to be sent, then encrypts that portion using their private key to generate a string.
[0226] The sender of the data sends the data and its signature to the receiver, who can verify the received data signature (i.e., check the signature) to determine the integrity of the received data.
[0227] On one hand, this string is generated based on the sender's private key, and the data signature is non-repudiable, meaning the sender cannot deny sending signed data to the receiver. The receiver uses the sender's public key to verify the data signature, thus confirming the sender's signing of the data. On the other hand, this string is generated based on the data to be sent. After verifying the data signature using the sender's public key, the receiver can also generate a new string using the received data. By comparing the new string with the verified data signature, the receiver can determine whether the received data has been tampered with or is intact.
[0228] In this embodiment, the data access device can sign the first integrity measurement report, thus the first integrity measurement report includes signature information. For ease of explanation, the signature information of the first integrity measurement report is referred to as the first signature information. The data storage device can sign the second integrity measurement report, thus the second integrity measurement report includes signature information. For ease of explanation, the signature information of the second integrity measurement report is referred to as the second signature information.
[0229] (4) Merkle tree and Merkle tree path.
[0230] A Merkle tree is a tree-like data structure based on a hash algorithm. Each non-leaf node contains a combination of the hash values of its child nodes, and the hash value of the root node uniquely identifies all the data contained in the entire tree.
[0231] As shown in Figure 1, the formation process of a Merkle tree is as follows: First, the data is divided into multiple small data blocks, and the hash value of each data block is calculated. The hash value of each data block is the lowest-level node (i.e., the leaf node) in the Merkle tree. Two adjacent leaf nodes are treated as a string, and the hash value of this string is calculated to form an intermediate node. These two leaf nodes are the two child nodes of the intermediate node. It can be seen that an intermediate node contains the hashes of the two child nodes below it. Hashting two adjacent leaf nodes at the lowest level yields multiple intermediate nodes. Using a similar method, adjacent intermediate nodes among these multiple intermediate nodes are hashed to obtain multiple intermediate nodes at the next higher level, ultimately forming an "inverted tree." The root position of this tree will generate a hash value, which can be called the root hash or the root of the Merkle tree.
[0232] Figure 1 illustrates an example of a four-level Merkle tree. Nodes 1, 2, 3, 4, 5, 6, 7, and 8 are leaf nodes at the bottom level (the fourth level). The hash values of nodes 1, 2, 3, 4, 5, 6, 7, and 8 are H1, H2, H3, H4, H5, H6, H7, and H8, respectively. Nodes 9, 10, 11, and 12 are intermediate nodes at the third level of the Merkle tree. The hash value H9 of node 9 is the hash of nodes 1 and 2; the hash value H9 of node 10 is the hash of nodes 3 and 4; the hash value H11 of node 11 is the hash of nodes 5 and 6; and the hash value H12 of node 12 is the hash of nodes 7 and 8. Nodes 13 and 14 are intermediate nodes at the second level of the Merkle tree. The hash value H13 of node 13 is the hash of nodes 9 and 10, and the hash value H14 of node 14 is the hash of nodes 11 and 12. Node 15 is a node in the first level of this Merkle tree, and is the root of the Merkle tree. The hash value H15 of node 15 is the hash of nodes 13 and 14.
[0233] As can be seen from the formation process of a Merkle tree, there is a correspondence between nodes in any two adjacent levels. For example, a leaf node corresponds to an intermediate node in its upper level, and the hash value represented by that intermediate node is generated based on the leaf node. Similarly, an intermediate node corresponds to an intermediate node in its upper level, and the hash value represented by that intermediate node is generated based on that intermediate node.
[0234] For example, in the Merkle tree shown in Figure 1, the Merkle tree path of node 1 includes nodes 2, 9, 10, 13, and 14.
[0235] As can be seen from the formation process of this Merkle tree, if any leaf node changes, then the root of the Merkle tree will also change, and the root of the Merkle tree can uniquely identify the Merkle tree.
[0236] Merkel trees have the following characteristics:
[0237] 1. Tree structure, the most common structure is binary tree, but it can also be multi-branch tree. Merkle tree has all the characteristics of tree structure.
[0238] 2. The leaf nodes of the Merkle tree can be set according to actual needs. For example, in the Merkle tree used in this application embodiment, any leaf node is used to represent the hash value of metadata that requires support for hidden transmission (such as the aforementioned requirement two or requirement three).
[0239] 3. Merkle trees are calculated layer by layer from bottom to top. That is, each intermediate node is calculated based on the combination of two adjacent child nodes, the root node is calculated based on the combination of two intermediate nodes, and the leaf nodes are the foundation of the Merkle tree.
[0240] In this embodiment of the application, a Merkle tree can be generated in the data storage device for the data that the target application needs to access. When generating the Merkle tree for the data that the target application needs to access, the data is divided into multiple small data blocks, and a hash value is generated for each data block. The hash value of each data block is the lowest level node (i.e., the leaf node) in the Merkle tree. Two adjacent leaf nodes form an intermediate node, and this process is pushed upwards layer by layer until the root of the Merkle tree is generated.
[0241] Furthermore, in the embodiments of this application, "and / or" represents three possible situations. Taking A and / or B as an example, A and / or represents: A, B, and A and B.
[0242] Figure 2 is a schematic diagram of a data protection system structure provided in an embodiment of this application. The data protection system includes a data access device 100 and a data storage device 200.
[0243] This data protection system involves authentication between the data access device 100 and the data storage device 200. Authentication between the data access device 100 and the data storage device 200 is manifested as follows:
[0244] 1. The data storage device 200 verifies the data access device 100 to verify whether the data processing environment of the data access device 100 is complete.
[0245] For the data storage device 200, the data access device 100 accesses the data storage device 200 to read data from the data storage device 200 and process the read data. The data storage device 200 expects the data access device 100 to securely process the data after acquiring it, and it is its expectation that the data will not be stolen during the data processing. Therefore, before providing data storage services to the data access device 100, the data storage device 200 can verify the data processing environment of the data access device 100 to ensure the security of the data on the data access device 100 side.
[0246] The data processing environment refers to the "environment" within the data access device 100 where data is processed. From the perspective of the internal structure of the data access device 100, this "data processing environment" includes a hardware "environment" and / or a software "environment." The hardware environment can be understood as the hardware of the data access device 100, and the software environment can be understood as the target application 130 on the data access device 100. Therefore, the complete representation of the data processing environment involves both hardware-level security and software-level security.
[0247] In this embodiment of the application, the integrity of the data processing environment is manifested in some or all of the following: the hardware of the data access device 100 is in a trusted state, and the target application 130 of the data access device 100 is in a trusted state.
[0248] The hardware of the data access device 100 can be a processor, memory, network card, etc. The hardware being in a trusted state means that the source of the hardware (such as the hardware manufacturer) is legitimate and the hardware version is correct.
[0249] The hardware being in a trusted state ensures the security of data processing, storage, and transmission operations performed by the hardware within the data access device 100. The target application 130 of the data access device 100 can be understood as a software module deployed on the data access device 100 for processing data. This target application 130 can generate data access requests to access data in the data storage device 200. From the user's perspective, the target application 130 is the software module run by the data access device 100 to complete the user's computing tasks. In this embodiment, the target application 130 has memory isolation properties. Memory isolation means that the startup and operation of the target application 130 need to be executed in an isolated memory space. Here, "isolation" means that this memory space can only be used by the target application 130, and other applications deployed on the data access device 100 cannot access this memory space. For ease of explanation, this isolated memory space is referred to as the target memory space.
[0250] The data access device 100 can deploy different target applications 130, each of which processes different data or in different ways.
[0251] This application does not limit the specific presentation of the target application 130. For example, the target application 130 may be file management software deployed on the data access device 100. Another example is that the target application 130 may be database software deployed on the data access device 100. Yet another example is that the target application 130 may be a computing instance such as a virtual machine or container deployed on the data access device 100.
[0252] The target application 130 being in a trusted state means that the startup process and subsequent operation of the target application 130 are normal. Further clarification of "normal": A normal startup process means that the version (e.g., software version), startup parameters, etc., of the target application 130 are correct, and the various operations involved in the startup process are executed sequentially without any violations. The various operations involved in the startup process are those required by the target application 130 from creation to execution, such as reading and executing computer program instructions. A normal post-startup operation of the target application 130 means that the target application 130 runs normally after startup, without any anomalies during operation (especially no data leakage or other anomalies).
[0253] Since the target application 130 is a type of "software," its startup and operation processes both depend on the target memory space within the data access device 100. For example, when starting the target application 130, after the various hardware components of the data access device 100 are powered on, the processor within the data access device 100 runs basic software modules such as firmware and the operating system. The processor within the data access device 100 copies the computer program instructions related to the target application 130 into the target memory space. The processor within the data access device 100 then runs the computer program instructions related to the target application 130, thus starting the target application 130. When running the target application 130, the target application 130 accesses the target memory space to obtain data to be processed and stores the processed data in the target memory space.
[0254] It can be seen that the trusted state of the target application 130 can be reflected in the fact that the target memory space is truly isolated, such as the computer program instructions related to the target application 130 in the target memory space being complete, or the data in the target memory space of the target application 130 not being tampered with or accessed by other applications during the operation of the target application 130.
[0255] The fact that the target application 130 is in a trusted state ensures that the processing of data by the target application 130 is secure, and that data is not easily leaked during the data processing process, thus effectively ensuring data security.
[0256] In order for the data storage device 200 to verify the data access device 100, the data access device 100 needs to have the following specific characteristics:
[0257] Feature 1: The data access device 100 can provide a first integrity measurement report.
[0258] The first integrity measurement report is used to indicate the data processing environment of the data access device 100. In view of the description of the integrity of the data processing environment, the first integrity measurement report includes a first hardware integrity report and / or a first program integrity report.
[0259] The first hardware integrity report is used to characterize the hardware information of the data access device 100. The first program integrity report is used to characterize the startup process and / or running status of the target application 130. The generation method of the first hardware integrity report and the first program integrity report is described below and will not be repeated here.
[0260] The data access device 100 can provide a first integrity measurement report to the data storage device 200 so that the data storage device 200 can verify the data access device 100 based on the first integrity measurement report.
[0261] Feature 2: The data access device 100 is equipped with a first hardware security module 140.
[0262] The so-called "first hardware security module 140" is a hardware module deployed in the data access device 100, which can be used to generate a first integrity measurement report. In other words, the generation method of the first integrity measurement report in the data access device 100 is embedded in the first hardware security module 140; the generation method of the first integrity measurement report embedded in the first hardware security module 140 cannot be tampered with. The generation method of the first integrity measurement report can be burned into the first hardware security module 140. The generation method of the first integrity measurement report can be understood as a piece of code, which is directly burned into the first hardware security module 140. This code will not be modified. The generation method of the first integrity measurement report can also run on the first hardware security module 140 in the form of firmware. The firmware form ensures that the generation method of the first integrity measurement report cannot be modified.
[0263] In other words, as long as the data access device 100 has the first hardware security module 140 deployed within it, the first hardware security module 140 can automatically generate a first integrity measurement report for the data access device 100. That is, on the data access device 100 side, the first integrity measurement report is generated by the hardware of the data access device. Therefore, the reliability of the first integrity measurement report is guaranteed.
[0264] This application does not limit the specific form of the first hardware security module 140. For example, the first hardware security module 140 may be a piece of circuit logic built into the processor within the data access device 100. As another example, the first hardware security module 140 may include a piece of circuit logic within the processor of the data access device 100 and a trusted platform module (TPM) located outside the processor. The TPM can be understood as a module that provides data storage space (e.g., the TPM contains hardware registers), and the data stored in the TPM has high security. The TPM may store the data required by the data security module to generate the first integrity measurement report (e.g., the key used to sign the first integrity measurement report) and the measurement values in the first integrity measurement. The processor may store the measurement values in the first integrity measurement report (e.g., hardware measurement values, first startup measurement values, first running measurement values) in an extended manner in the hardware registers of the TPM.
[0265] As can be seen from the above description of the first hardware security module 140, it is the basis for the data storage device 200 to complete the verification of the data access device 100. Due to the existence of the first hardware security module 140, the data access device 100 can provide a reliable and effective first integrity measurement report. Thus, when the data storage device 200 verifies the data access device 100 based on the first integrity measurement report, it can gain a true understanding of the data processing environment within the data access device 100 through the report.
[0266] 2. The data access device 100 verifies the data storage device 200 to verify whether the data storage environment of the data storage device 200 is complete.
[0267] Data storage device 200 provides data storage services to data access device 100, and can provide data storage space for data access device 100. Data access device 100 expects the data stored on data storage device 200 to be secure, not leaked, and not stolen; that is, data access device 100 requires data storage device 200 to provide reliable data storage services. To this end, data access device 100 can verify data storage device 200 to determine whether the data storage environment of data storage device 200 is complete and whether it can securely store data.
[0268] The data storage environment refers to the "environment" within the data storage device 200 where data is stored. In this embodiment, the data storage environment refers to the "environment" within the data storage device 200 where data is stored. From the perspective of the internal structure of the data storage device 200, the "data storage environment" includes a hardware "environment" and / or a software "environment." The hardware environment can be the hardware within the data storage device 200. The software environment is the application running on the data storage device 200, such as the storage application 230 mentioned below. Therefore, the complete representation of the data storage environment includes both hardware-level security and software-level security.
[0269] In this embodiment of the application, the integrity of the data storage environment is manifested in some or all of the following: the hardware of the data storage device 200 is in a trusted state, and the storage application 230 of the data storage device 200 is in a trusted state.
[0270] The hardware of the data storage device 200 can be a processor, memory, network card, etc. The hardware being in a trusted state means that the source of the hardware (such as the hardware manufacturer) is legitimate and the hardware version is correct.
[0271] The fact that the hardware is in a trusted state ensures that the hardware used to store data in the data storage device 200 is secure and can prevent data leakage due to hardware issues.
[0272] Storage application 230 is an application that needs to be called during the data storage process in data storage device 200. This application embodiment does not limit the specific function of storage application 230; any application that needs to be called during data storage is applicable to this application embodiment.
[0273] The following are some examples of storage applications 230:
[0274] Application 1: Identity Mapping Program.
[0275] The identity mapping program can identify different target applications 130 and assign identity information to each. Within the data storage device 200, data can be stored based on the identity information of the target applications 130. For example, the data accessed by a target application 130 can be labeled with the identity information specific to that target application, thus distinguishing the data accessed by different target applications 130. This isolates the data accessed by different target applications 130, storing it in different data storage spaces. Each target application 130 has a corresponding data storage space within the data storage device 200, and the data accessed by a target application 130 can only be stored in its corresponding storage space.
[0276] The data storage device 200 manages data access requests based on the identity information of the target application 130. Managing data access requests means that the data storage device 200 determines whether it can process the data access request. In other words, after receiving a data access request, the data storage device 200 checks whether the target application 130 that initiated the request can access the data requested. For example, the data storage device 200 determines whether the data requested in the request is identified by the identity identifier of the target application 130. If so, the data storage device 200 can process the data access request; otherwise, the data storage device 200 does not process the data access request.
[0277] Application 2: Data Encryption / Decryption Program.
[0278] The data encryption / decryption program can encrypt and decrypt data, and can encrypt and store data within the data storage device 200 to ensure data storage security. When the target application 130 needs to obtain data, the data encryption / decryption program can decrypt the encrypted data and send it back to the target application 130.
[0279] Application 3: Data Integrity Procedure.
[0280] The data integrity program is used to completely preserve the data that the target application 130 needs to access; that is, the data saved by calling the data integrity program is complete and without any omissions. The data that the target application 130 needs to access includes data read from and written to the data storage device 200. There are many ways to ensure data integrity using the data integrity program. For example, the data integrity program can maintain the integrity of the data that the target application 130 needs to access by generating a Merkle tree.
[0281] This introduces the concept of "confidential storage." Data storage device 200 can provide confidential storage services, which are data storage services with higher security and reliability. Data storage device 200 can implement confidential storage through the hardware and software (e.g., storage application 230) included in the device. The security provided by confidential storage is not limited to authentication and data encryption / decryption, but also includes data isolation and data integrity maintenance. In addition, confidential storage can provide other functions to ensure data security.
[0282] The trusted state of storage application 230 is manifested in the security of storage application 230 running on data storage device 200. Storage application 230 running on data storage device 200 possesses memory isolation properties; for an explanation of memory isolation, please refer to the foregoing description, which will not be repeated here. The trusted state of storage application 230 can be understood as the memory space used by storage application 230 within data storage device 200 being truly isolated; that is, the computer program instructions related to storage application 230 in the memory space are intact, and the data in the memory space of target application 130 is not tampered with or accessed by other applications during its execution.
[0283] In order to ensure that the data access device 100 can authenticate the data storage device 200, the data storage device 200 needs to have the following specific characteristics:
[0284] Feature 1: Data storage device 200 can provide a second integrity measurement report.
[0285] The second integrity measurement report is used to indicate the integrity of the data storage environment of the data storage device 200. In view of the description regarding the integrity of the data storage environment, the second integrity measurement report includes a second hardware integrity report and / or a second program integrity report.
[0286] The second hardware integrity report is used to characterize information about the hardware of the data storage device 200. The second program integrity report is used to characterize the startup process and / or running status of the storage application 230 running on the data storage device 200. The generation methods of the second hardware integrity report and the second program integrity report are described below and will not be repeated here.
[0287] The data storage device 200 can provide a second integrity measurement report to the data access device 100 so that the data access device 100 can verify the data storage device 200 based on the second integrity measurement report.
[0288] Feature 2: The data storage device 200 is equipped with a second hardware security module 240.
[0289] The so-called "second hardware security module 240" is a hardware module deployed in the data storage device 200, which can be used to generate a second integrity measurement report. In other words, the generation method of the second integrity measurement report in the data storage device 200 is embedded in the second hardware security module 240; for an explanation of this embedding, please refer to the aforementioned explanation of the first hardware security module 140, which will not be repeated here. The generation method of the second integrity measurement report embedded in the second hardware security module 240 cannot be tampered with.
[0290] In other words, as long as the data storage device 200 has the second hardware security module 240 deployed within it, the second hardware security module 240 can automatically generate a second integrity measurement report for the data storage device 200. That is, the second integrity report is generated by the hardware within the data storage device 200, thus ensuring the reliability of the second integrity measurement report.
[0291] The embodiments of this application do not limit the specific form of the second hardware security module 240. The specific form of the second hardware security module 240 is similar to that of the first hardware security module 140, and can be found in the foregoing description, which will not be repeated here.
[0292] Similar to the first hardware security module 140, the second hardware security module 240 forms the basis for the data access device 100 to verify the data storage device 200. Due to the existence of the second hardware security module 240, the data storage device 200 can provide a reliable and effective second integrity measurement report. Thus, when the data access device 100 verifies the data storage device 200 based on the second integrity measurement report, it can gain a true understanding of the operational status of the data storage device 200 through the report.
[0293] Based on the functionality of the storage application 230 deployed on the data storage device 200, the data storage device 200 may also include some or all of the following features:
[0294] Feature 3: Data storage device 200 supports identity mapping for different target applications 130.
[0295] When an identity mapping program is deployed on the data storage device 200, the identity mapping program configures identity information for the target application 130. Each target application 130 has a unique identity information, and different target applications 130 have different identity information. That is, a single identity information can uniquely point to a single target application 130. For any target application 130, when storing data that the target application 130 needs to access, the data storage device 200 can label the data that the target application 130 needs to access with the identity information of the target application 130 to indicate that the data belongs to the target application 130.
[0296] Feature 4: Data storage device 200 sets up data isolation for different target applications 130.
[0297] Since the data storage device 200 can store data that needs to be accessed from different target applications 130, data isolation can be achieved at the target application 130 level on the data storage device 200 side. That is, the data that needs to be accessed from different target applications 130 is isolated from each other, and a target application 130 cannot access the data that other target applications 130 need to access if it does not have the necessary access permissions.
[0298] Furthermore, the data storage device 200 also supports data sharing between different target applications 130. The data storage device 200 allows target applications 130 to set access permissions for their own data. That is, a target application 130 can instruct the data storage device 200 to set access permissions for data belonging to that target application 130, where data belonging to that target application 130 refers to data that identifies the target application 130. For example, the data access permission could indicate that any target application 130 is allowed to access it; in other words, any target application 130 has access to the data. Or, for example, the data access permission could indicate that one or more target applications 130 are allowed to access it; in other words, one or more target applications 130 have access to the data.
[0299] When a target application 130 sends a data access request to the data storage device 200 to request access to data belonging to another target application 130, the data storage device 200 determines whether the data can be accessed by the target application 130 based on data access permissions. If it determines that the data can be accessed by the target application 130, it accesses the data according to the data access request; otherwise, it rejects the data access request.
[0300] By setting data isolation for different target applications 130, the data storage device 200 can ensure that the target data application cannot be accessed by other applications, thereby further ensuring the security of the data on the data storage device 200 side.
[0301] Feature 5: Data storage device 200 provides reliable data lifecycle management.
[0302] Data storage device 200 is responsible for the entire data lifecycle from storage to deletion. During this data lifecycle, a user or target application 130 can instruct data storage device 200 to perform various operations (such as the target operations in this embodiment) on the data required by the target application 130, such as storing data, modifying data access permissions, changing data ownership, and deleting data. Reliable data lifecycle management means that all operations performed on data belonging to the target application 130 are executed. Operation credentials can be used to indicate that the target operations on data belonging to the target application 130 have been executed, thereby ensuring the security of data belonging to the target application 130 within data storage device 200.
[0303] Figure 3A shows a schematic diagram of the structure of a data access device 100 provided in an embodiment of this application. From a functional perspective, the data access device 100 includes a first verification module 110, an application management module 120, a first hardware security module 140, and a target application 130.
[0304] The first hardware security module 140 is used to generate a first integrity measurement report. The generation of the first integrity measurement report within the data access device 100 is performed by the first hardware security module 140.
[0305] Application management module 120 is responsible for managing target application 130. This module can be used to start target application 130, monitor its running status, and shut it down. For example, when target application 130 is a virtual machine, application management module 120 includes QEMU (quick emulator) and a virtual machine monitor (VMM). When target application 130 is a container, application management module 120 can be a container engine. Application management module 120 also maintains the memory isolation of target application 130. That is, application management module 120 configures an independent target memory space for target application 130, which is not shared with other applications deployed within the data access device 100. Within this target memory space, application management module 120 starts target application 130 and ensures that target application 130 runs within this memory space (i.e., data generated by target application 130 during operation is stored in this target memory space). The application management module 120 can also release the target memory space when closing the target application 130.
[0306] The first verification module 110 interacts with the data storage device 200 to assist the data storage device 200 in verifying data access. The first verification module 110 provides a first integrity measurement report to the data storage device 200. For example, in this embodiment, the first verification module 110 can initiate a first verification request carrying the first integrity measurement report to the data storage device 200. The first verification module 110 can also interact with the data storage device 200 to verify it. The first verification module 110 obtains a second integrity measurement report from the data storage device 200. For example, in this embodiment, the first verification module 110 can receive a second verification request carrying the second integrity measurement report initiated by the data storage device 200. After obtaining the second integrity measurement report, the first verification module 110 verifies the data storage device 200 based on the second integrity measurement report.
[0307] Target application 130 is an application deployed on the data access device 100 that runs to complete the user's computing tasks. Target application 130 is a module of the data access device 100 that needs to access the data storage device 200. For example, target application 130 can trigger the generation of a data access request, which requests access to data in the data storage device 200, such as reading data from the data storage device 200 or writing data to the data storage device 200. Target application 130 has memory isolation properties within the data access device 100, meaning that target application 130 is configured with a target memory space within the data access device 100, which is accessible only to target application 130 and cannot be accessed by other applications.
[0308] Figure 3B shows a schematic diagram of the structure of a data storage device 200 provided in an embodiment of this application. From a functional perspective, the data storage device 200 includes a second verification module 210, a storage program management module 220, a second hardware security module 240, and a storage application program 230.
[0309] The second hardware security module 240 is used to generate a second integrity measurement report. The generation of the second integrity measurement report inside the data storage device 200 is performed by the second hardware security module 240.
[0310] The stored application management module 220 is responsible for managing the stored application 230. This module can be used to start the stored application 230, monitor its running status, and shut it down. The stored application management module 220 also maintains the memory isolation of the stored application 230. That is, the stored application management module 220 configures an independent memory space for the stored application 230, which is not shared with other applications deployed within the data storage device 200. Within this memory space, the stored application management module 220 starts the stored application 230 and ensures that the stored application 230 runs within this memory space (i.e., data generated by the stored application 230 during its operation is stored in this memory space).
[0311] In addition, the stored procedure management module 220 performs data lifecycle management functions, such as performing operations to store data, change data access permissions, determine data ownership (i.e., transfer data from one target application 130 to another), and delete data (e.g., when the storage management module determines that the target application 130 is closed, it deletes the data belonging to that target application 130). The stored procedure management module 220 can also generate operation credentials, which indicate that the operation performed on the data has been completed.
[0312] The second verification module 210 interacts with the data access device 100 to assist the data access device 100 in verifying data storage. The second verification module 210 provides a second integrity measurement report to the data storage device 200. For example, in this embodiment, the second verification module 210 can initiate a second verification request carrying the second integrity measurement report to the data storage device 200. The second verification module 210 can also interact with the data access device 100 to verify the data storage device. The second verification module 210 obtains a first integrity measurement report from the data access device 100. For example, in this embodiment, the second verification module 210 can receive a first verification request carrying the first integrity measurement report initiated by the data access device 100. After obtaining the first integrity measurement report, the first verification module 110 verifies the data storage device 200 based on the first integrity measurement report.
[0313] Storage application 230 is an application deployed on the data access device 100 that runs to store data. Storage application 230 includes, but is not limited to, identity mapping programs, data encryption / decryption programs, and data integrity programs. Storage application 230 is an application that needs to be called by the data storage device 200 when storing data. For details on the specific functions of storage application 230, please refer to the foregoing description; it will not be repeated here. Storage application 230 has memory isolation characteristics within the data storage device 200; that is, within the data storage device 200, storage application 230 is configured with independent memory space, which can only be accessed by storage application 230, and other applications cannot access this memory space.
[0314] The module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0315] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device (which may be a personal computer, mobile phone, or network device, etc.) or processor to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0316] Figure 4 illustrates a data protection method according to an embodiment of this application. This verification method includes two verification processes: one is the verification process between the data storage device 200 and the data access device 100, as detailed in steps 401-403; the other is the verification process between the data access device 100 and the data flow device, as detailed in steps 404-406. These two verification processes are independent and not dependent on each other. In practical applications, the data access device 100 and the data storage device 200 can perform either verification process or both. The embodiment shown in Figure 4 only illustrates the example of the data access device 100 and the data storage device 200 performing both verification processes.
[0317] Step 401: The data access device 100 generates a first integrity measurement report; the data access device 100 generates a first integrity measurement report. The first integrity measurement report includes a first hardware integrity report and / or a first program integrity report.
[0318] The generation methods of the first hardware integrity report and the first program integrity report are explained below.
[0319] (1) First hardware integrity report.
[0320] The data access device 100 detects the hardware system of the data access device 100 and obtains information about each hardware component in the hardware system, such as version, manufacturer, and configuration parameters of each hardware component.
[0321] For example, the data access device 100 can obtain information such as the processor's model and manufacturer by detecting the processor. The data access device 100 can obtain information such as the memory's size and model by detecting the memory.
[0322] The first hardware integrity report includes a first hardware metric, which is generated based on information about the hardware within the data access device 100.
[0323] It should be noted that the first hardware metric value is the content of the hardware of the data access device 100 that can characterize the first hardware integrity report. Although named as a first hardware metric "value", it does not limit the specific form of the first hardware metric value, nor does it limit the way the first metric value is generated. For example, the first hardware metric value can be a set of information, such as the first hardware metric value including hardware information (such as hardware signals) and related information of the firmware program running on the hardware (this related information can be the hash value after hashing the firmware program). For another example, the first hardware metric value is the hash value after hashing the hardware information and the firmware program.
[0324] The firmware information is primarily obtained through measurements of the firmware. Since firmware is programmed into the hardware and cannot be easily altered, it can be considered a "special" type of hardware information. In other words, the first hardware integrity measurement report records basic information about the device itself or that is programmed or embedded in it. Therefore, this hardware information can be understood as a "special" hardware measurement value.
[0325] There are many ways for the data access device 100 to generate a first hardware integrity report, and the embodiments of this application do not limit the generation method of the first hardware integrity report. For example, the data access device 100 has a preset format for the first hardware integrity report, which describes the location of hardware information (optionally, also including information related to the firmware program running on the hardware) in the first hardware integrity report. The data access device 100 can arrange the hardware information according to the format of the first hardware integrity report to obtain the first hardware integrity report. As another example, the data access device 100 has a preset format for the first hardware integrity report, which describes the processing method of the hardware information (such as hashing and the hash function called) and the location of the first hardware metric value obtained after processing in the first hardware integrity report. The data access device 100 can process the hardware information according to the format of the first hardware integrity report and arrange the obtained hardware metric value according to the format of the first hardware integrity report to obtain the first hardware integrity report.
[0326] For example, the format of the first hardware integrity report requires recording the processor's configuration information and the BootLoader firmware information used to start the system. The data access device 100 will then detect and obtain hardware information such as the processor version, factory ID, and physical memory protection level through hardware instructions (see Table 1 for detailed examples of field descriptions), and obtain firmware information such as BL1 / BL2 through hardware measurement operations. This information will then be placed into the corresponding fields of the first hardware integrity report according to the prescribed format.
[0327] (2) First procedure integrity report.
[0328] The first program integrity report needs to reflect the startup process and / or the running status of the target application 130. For ease of explanation, the parameters reflecting the startup process of the target application 130 in the first program integrity report are referred to as first startup metrics, and the parameters reflecting the running status of the target application 130 in the first program integrity report are referred to as first running metrics. In other words, the first program integrity report includes first startup metrics and / or first running metrics.
[0329] Similar to the first hardware metric, although the names of the first startup metric and the first running metric also contain "value", there are no restrictions on the specific form and presentation of the first startup metric and the first running metric.
[0330] The first startup metric can characterize the startup process of the target application 130. This application embodiment does not limit the specific form of the first startup metric. For example, the first startup metric may be a configuration parameter necessary for the startup process of the target application 130. Alternatively, the first startup metric may be a hash value of computer program instructions related to the target application 130; that is, the hash value obtained by hashing the computer program instructions related to the target application 130 is the first startup metric.
[0331] Similarly, the first runtime metric can characterize the running state of the target application 130, and the embodiments of this application do not limit the specific form of the first runtime metric. For example, the first runtime metric is a parameter necessary for the running process of the target application 130. As another example, the first startup metric is the hash value of all information in the target memory space of the target application 130, that is, all information in the target memory space of the target application 130 is treated as a whole, hashed, and the resulting hash value is the first runtime metric.
[0332] The data access device 100 acquires the first startup metric during the startup process of the target application 130, acquires the first running metric during the running process of the target application 130, and then generates the first program integrity report.
[0333] The data access device 100 generates a first hardware integrity report and a first program integrity report, which is also a first integrity measurement report, and signs the first integrity measurement report. When signing the first integrity measurement report, the data access device 100 can use a key built into the data access device 100. This built-in key can be a root key built into the hardware (such as a processor) of the data access device 100, or a key derived from that root key. Since the root key or keys derived from it only exist in the hardware, they are not easily tampered with.
[0334] After obtaining the first integrity measurement report, the data access device 100 saves the first integrity measurement report. In this embodiment, the generation and saving of the first hardware integrity report, the first program integrity report, the first integrity measurement report, and the first hardware security module 140 can be performed. The first hardware security module 140 includes a secure storage space, and the information stored in the secure storage space can only be accessed by the first hardware security module 140. The first hardware security module 140 can save the generated first integrity measurement report in the secure storage space.
[0335] Step 402: In a scenario where the data storage device 200 needs to verify the data access device 100, the data access device 100 sends a first verification request to the data storage device 200. The first verification request is used to request the data storage device 200 to verify the data access device 100. The first verification request carries a first integrity measurement report. Optionally, the first integrity measurement report carries first signature information.
[0336] There are many scenarios in which the data storage device 200 needs to be authenticated by the data access device 100. Two scenarios are listed here:
[0337] Scenario 1: The data access device 100 and the data storage device 200 establish a connection for the first time.
[0338] When data access device 100 needs to access data storage device 200 to read or write data, data access device 100 needs to establish a connection with the storage device. For data storage device 200, it needs to verify not only the identity of data access device 100—to confirm its compliance or that it is not a malicious device—but also the data processing environment of data access device 100 to ensure that the data provided by data storage device 200 to data access device 100 can be processed by data access device 100 under relatively secure conditions. During the connection establishment process with data storage device 200, data access device 100 completes the verification of data access device 100 by data storage device 200.
[0339] Taking the establishment of a TLS connection between data access device 100 and data storage device 200 as an example, during the establishment of the TLS connection, they exchange certificates based on the TLS handshake protocol and verify each other. Data access device 100 can include a first integrity measurement report in the extended field of its own certificate and transmit its own certificate to data storage device 200.
[0340] Scenario 2: After the data access device 100 and the data storage device 200 establish a connection.
[0341] After a connection is established between the data access device 100 and the data storage device 200, the data access device 100 can interact with the data storage device 200, writing data to or reading previously written data. Considering that the data processing environment of the data access device 100 may change after the connection is established (e.g., the data access device 100 is attacked by malware), the data storage device 200 can verify the data access device 100 after the connection is established. For example, the data storage device 200 can periodically verify the data access device 100. That is, the data access device 100 can periodically provide a first integrity measurement report to the data storage device 200 (e.g., periodically initiate a first verification request), and the data storage device 200 can periodically obtain the first integrity measurement report. Only when the verification is successful can the data storage device 200 continue to allow access from the data access device 100. It should be noted that in this scenario, the data access device 100 needs to periodically generate a first integrity metric report. Specifically, the data access device 100 needs to periodically generate a first program integrity report to record a first startup metric value that characterizes the current running state of the target application 130.
[0342] The above are merely examples. In practical applications, there are many scenarios where the data storage device 200 needs to verify the data access device 100. For instance, the data storage device 200 can instruct the data access device 100 to provide a first integrity measurement report based on the current access frequency of the data access device 100, thereby verifying the data access device 100.
[0343] Step 403: The data storage device 200 receives the first verification request, obtains the first integrity measurement report, and verifies the data access device 100 based on the first integrity measurement report.
[0344] Upon receiving the first verification request, the data storage device 200 acquires a first integrity measurement report. When verifying the data access device 100 based on the first integrity measurement report, the data storage device 200 may first verify the first signature information of the first integrity measurement report. For explanations regarding signatures and verification, please refer to the foregoing description; further details will not be repeated here. After the signature verification of the first integrity measurement report is successful, the data storage device 200 can parse the first integrity measurement report to understand the data processing environment of the data access device 100, and then verify the data access device 100.
[0345] This application embodiment also provides a mechanism to ensure the validity of the first integrity measurement report. This mechanism relies on challenge values exchanged between the data storage device 200 and the data access device 100. The data storage device 200 can periodically or irregularly send challenge values to the data access device 100. After receiving the challenge value, the data access device 100 can carry the challenge value in the information or messages it sends to the data storage device 200, thereby indicating the validity of the information and messages. That is, the messages and information sent by the data access device 100 to the data storage device 200 can carry the challenge value most recently obtained from the data storage device 200. After receiving the message or information, the data storage device 200 determines whether the challenge value carried in the message or information is the most recently sent challenge value to the data access device 100; if so, the message or information is valid; otherwise, the message or information is invalid.
[0346] For example, data storage device 200 can send a first challenge value to data access device 100. Upon receiving the first challenge value, if data access device 100 subsequently needs to provide a first integrity measurement report to data storage device 200, it can include the first challenge value in the first integrity measurement report. After obtaining the first integrity measurement report, data storage device 200 can determine whether the first integrity measurement report contains the first challenge value. If the first integrity measurement report contains the first challenge value, it indicates that the first integrity measurement report is valid; otherwise, the first integrity measurement report is invalid.
[0347] The process by which the data storage device 200 verifies the data access device 100 based on the first integrity measurement report includes some or all of the following three verification operations: one verification operation verifies whether the hardware of the data access device 100 is in a trusted state based on the first hardware integrity report; one verification operation verifies whether the startup process of the target application 130 of the data access device 100 is normal based on the first program integrity report; and one verification operation verifies whether the running status of the target application 130 of the data access device 100 is normal based on the first program integrity report. The latter two verification operations are performed to determine whether the target application is in a trusted state. These three verification operations will be described in detail below.
[0348] Verification Operation 1: For the first hardware integrity report in the first integrity measurement report, the data storage device 200 verifies whether the hardware of the data access device 100 is in a trusted state by parsing the first hardware integrity report.
[0349] The first hardware integrity report includes a first hardware metric value and a configured reference hardware metric value on the data storage device 200 side. This reference hardware metric value is generated based on information about trusted hardware, where "trusted hardware" refers to hardware that the data storage device 200 side considers secure. In this embodiment, the reference hardware metric value pre-configured on the data storage device 200 side can also be referred to as the first reference hardware metric value. The presentation and generation methods of the first reference hardware metric value are similar to those of the first hardware metric value, except that the first reference hardware metric value is generated based on information about trusted hardware, while the first hardware metric value is generated based on the hardware of the data access device 100.
[0350] The data storage device 200 compares the first hardware metric value with the first reference hardware metric value to determine whether the first hardware metric value meets the first reference hardware metric value, thereby determining whether the hardware of the data access device 100 is trustworthy.
[0351] The presentation of the first hardware metric and the first reference hardware metric are different, and the specific meaning of the first hardware metric satisfying the first reference hardware metric is different. This satisfaction can be understood as the first hardware metric belonging to the first reference hardware metric or being the same as the first reference hardware metric.
[0352] For example, the data storage device 200 compares a first hardware metric value with a first reference hardware metric value to determine whether the first hardware metric value is consistent with the first reference hardware metric value. If they are consistent, it indicates that the hardware of the data access device 100 is in a trusted state; otherwise, it indicates that the hardware of the data access device 100 is not in a trusted state. As another example, the first reference hardware metric value represents the range of values for hardware metric values generated by trusted hardware. The data storage device 200 compares the first hardware metric value with the first reference hardware metric value to determine whether the first hardware metric value belongs to the range of values represented by the first reference hardware metric value. If it does, it indicates that the hardware of the data access device 100 is trusted; otherwise, it indicates that the hardware of the data access device 100 is untrustworthy.
[0353] Verification Operation 2: For the first program integrity report in the first integrity measurement report, the data storage device 200 verifies whether the startup process of the application of the data access device 100 is normal by parsing the first program integrity report.
[0354] When the first program integrity report includes a first startup metric, it is compared with a configured reference startup metric on the data storage device 200 side. This reference startup metric is generated based on the normal startup process of the target application 130. In this embodiment, the reference startup metric pre-configured on the data storage device 200 side can also be referred to as the first reference startup metric. The presentation and generation methods of the first reference startup metric are similar to those of the first startup metric, except that the first reference startup metric is generated based on the normal startup process of the target application 130, while the first startup metric is generated based on the startup process of the target application 130 in the data access device 100 (the startup process of the target application 130 in the data access device 100 may be normal or abnormal).
[0355] The data storage device 200 compares the first startup metric value with the first reference startup metric value to determine whether the first startup metric value meets the reference first startup metric value, thereby determining whether the startup of the data access device 100 is reliable.
[0356] The first startup metric and the reference startup metric are presented in different forms, and the specific meaning of the first startup metric satisfying the reference startup metric is different. This satisfaction can be understood as the first startup metric belonging to the reference startup metric or being the same as the reference startup metric. The way the data storage device 200 compares the first startup metric with the reference startup metric is similar to the way the data storage device 200 compares the first hardware metric with the first reference hardware metric; for details, please refer to the foregoing description, which will not be repeated here.
[0357] Verification Operation 3: For the first program integrity report in the first integrity measurement report, the data storage device 200 verifies whether the target application 130 of the data access device 100 is running normally by parsing the first program integrity report.
[0358] When the first program integrity report includes a first operational metric, it is compared with a configured reference operational metric on the data storage device 200 side. This reference operational metric is generated based on the normal operating state of the target application 130. In this embodiment, the reference operational metric pre-configured on the data storage device 200 side can also be referred to as the first reference operational metric. The presentation and generation methods of the first reference operational metric are similar to those of the first operational metric, except that the first reference operational metric is generated based on the normal operating process of the target application 130, while the first operational metric is generated based on the operating process of the target application 130 in the data access device 100 (the operating process of the target application 130 in the data access device 100 may be normal or abnormal).
[0359] The data storage device 200 compares the first operating metric value with the first reference operating metric value to determine whether the first operating metric value meets the reference first operating metric value, thereby determining whether the operation of the data access device 100 is reliable.
[0360] The presentation of the first operating metric and the reference operating metric differs, and the specific meaning of the first operating metric satisfying the reference operating metric differs as well. This satisfaction can be understood as the first operating metric belonging to the reference operating metric or being identical to the reference operating metric. The method by which the data storage device 200 compares the first operating metric with the reference operating metric is similar to the method by which the data storage device 200 compares the first hardware metric with the first reference hardware metric; for details, please refer to the foregoing description, which will not be repeated here.
[0361] Data storage device 200 determines whether the startup process of target application 130 is normal through verification operation 2, and determines whether the running state of target application 130 is normal through verification operation 3. If the startup process and / or the running state is normal, target application 130 is determined to be trustworthy or in a trustworthy state. In practical applications, since a normal startup process and / or a normal running state represent three possible scenarios, the data storage device 200 determines which scenario the target application 130 is trustworthy based on the actual scenario. For example, data storage device 200 pre-configures a second verification strategy, which describes how to verify the data access device 100 based on the first integrity metric report. This second verification strategy can indicate under which scenarios the target application 130 is considered trustworthy, and under which scenarios the hardware is trustworthy. The second verification strategy will be described in detail below and will not be repeated here.
[0362] The data storage device 200 has performed the above verification operation and can determine that the hardware of the data access device 100 is in a trusted state, the startup process of the target application 130 is normal, or the running state of the target application 130 is normal. Therefore, the data storage device 200 has successfully verified the data access device 100.
[0363] After the data access device 100 is successfully verified, the data storage device 200 can receive access from the data access device 100 (i.e., the target application 130), receive and process the data access request initiated by the target application 130, and can also perform subsequent steps (such as steps 404 to 406) to realize the verification of the data storage device 200 by the data access device 100. After the data access device 100 successfully verifies the data storage device 200, data interaction can be performed between the data access device 100 and the data storage device 200.
[0364] Step 404: Data storage device 200 generates a second integrity measurement report.
[0365] The generation methods for the second hardware integrity report and the second program integrity report are explained below.
[0366] (1) Second hardware integrity report.
[0367] The data storage device 200 detects the hardware system of the data storage device 200 and obtains information about each piece of hardware in the hardware system, such as version, manufacturer, and configuration parameters of each hardware component.
[0368] The second hardware integrity report includes a second hardware metric, which is generated based on information about the hardware within the data access device 100.
[0369] The meaning and generation method of the second hardware metric value are similar to those of the first hardware metric value. The difference is that the first hardware metric value is for the data access device 100, while the second hardware metric value is for the data storage device 200. For details, please refer to the foregoing explanation; further elaboration is omitted here.
[0370] The data storage device 200 generates the second hardware integrity report in a similar manner to the data access device 100, as detailed in the foregoing description, and will not be repeated here.
[0371] (2) Second procedure integrity report.
[0372] The second program integrity report needs to reflect the startup process and / or running status of the storage application 230. For ease of explanation, the parameters reflecting the startup process of the storage application 230 in the second program integrity report are referred to as second startup metrics, and the parameters reflecting the running status of the storage application 230 in the second program integrity report are referred to as second running metrics. In other words, the second program integrity report includes second startup metrics and / or second running metrics.
[0373] Similar to the first hardware metric, although the names of the second startup metric and the second running metric also contain "value", there are no restrictions on the specific form and presentation of the second startup metric and the second running metric.
[0374] The meaning and generation method of the second startup metric are similar to those of the first startup metric, except that the first startup metric is for the target application 130, while the second startup metric is for the storage application 230. For details, please refer to the foregoing explanation; further elaboration is omitted here.
[0375] The meaning and generation method of the second running metric are similar to those of the first running metric, except that the first running metric is for the target application 130, while the second running metric is for the storage application 230. For details, please refer to the foregoing explanation; further elaboration is omitted here.
[0376] The data storage device 200 acquires the second startup metric during the startup of the storage application 230, acquires the second running metric during the operation of the storage application 230, and then generates the second program integrity report.
[0377] The data storage device 200 generates a second hardware integrity report and a second program integrity report, which is also a second integrity measurement report. The second integrity measurement report is then signed, and this second integrity measurement report carries second signature information. The method by which the data storage device 200 signs the second integrity measurement report is similar to the method by which the data access device 100 signs the first integrity measurement report; for details, please refer to the foregoing description, which will not be repeated here.
[0378] After obtaining the second integrity measurement report, the data storage device 200 saves the second integrity measurement report. In this embodiment, the generation and saving of the second hardware integrity report and the second program integrity report, as well as the second integrity measurement report, can be performed by the second hardware security module 240. The second hardware security module 240 includes a secure storage space, and the information stored in this secure storage space can only be accessed by the second hardware security module 240. The second hardware security module 240 can save the generated second integrity measurement report in this secure storage space.
[0379] Step 405: In a scenario where the data access device 100 needs to verify the data storage device 200, the data storage device 200 sends a second verification request to the data access device 100. The second verification request is used to request the data access device 100 to verify the data storage device 200, and the second verification request carries a second integrity measurement report.
[0380] The scenarios in which data access device 100 needs to verify data storage device 200 are similar to those in which data storage device 200 needs to verify data access device 100. That is, when data access device 100 and data storage device 200 first connect, data access device 100 can verify data storage device 200. After the connection is established, data access device 100 can periodically verify data storage device 200. The difference is that the purpose of data access device 100's verification of data storage device 200 is to ensure that data storage device 200 can provide reliable data storage services, and that the data required by target application 130 can be securely and completely stored in data storage device 200, making it difficult to be stolen or lost. For details, please refer to the foregoing description; it will not be repeated here.
[0381] Taking the establishment of a TLS connection between data access device 100 and data storage device 200 as an example, during the establishment of the TLS connection, they exchange certificates based on the TLS handshake protocol and verify each other. Data storage device 200 can include a second integrity measurement report in the extended field of its own certificate and transmit its own certificate to data access device 100.
[0382] Step 406: The data access device 100 receives the second verification request, obtains the second integrity measurement report, and verifies the data storage device 200 based on the second integrity measurement report.
[0383] Upon receiving the second verification request, the data access device 100 obtains the second integrity measurement report. When verifying the data storage device 200 based on the second integrity measurement report, the data access device 100 may first verify the second signature information of the second integrity measurement report. For explanations regarding signatures and verification, please refer to the foregoing description; further details will not be repeated here. After the signature verification of the second integrity measurement report is successful, the data access device 100 can parse the second integrity measurement report to understand the data storage environment of the data storage device 200, and then verify the data storage device 200.
[0384] Similar to the method for ensuring the validity of the first integrity measurement report, this application embodiment also provides a mechanism for ensuring the validity of the second integrity measurement report. This mechanism relies on challenge values exchanged between the data storage device 200 and the data access device 100. The data access device 100 can periodically or irregularly send challenge values to the data storage device 200. After receiving the challenge value, the data storage device 200 can carry the challenge value in the information or messages it sends to the data access device 100, thereby indicating the validity of the information and messages. That is, the messages and information sent by the data storage device 200 to the data access device 100 can carry the challenge value most recently obtained from the data access device 100. After receiving the message or information, the data access device 100 determines whether the challenge value carried in the message or information is the challenge value most recently sent to the data storage device 200; if so, the message or information is valid; otherwise, the message or information is invalid.
[0385] For example, data access device 100 can send a second challenge value to data storage device 200. Upon receiving the second challenge value, if data storage device 200 subsequently needs to provide a second integrity measurement report to data access device 100, it can include the second challenge value in the second integrity measurement report. After obtaining the second integrity measurement report, data access device 100 can determine whether the report contains the second challenge value. If the report contains the second challenge value, it is considered valid; otherwise, it is invalid.
[0386] The process by which the data access device 100 verifies the data storage device 200 based on the second integrity measurement report includes some or all of the following three verification operations: one verification operation verifies whether the hardware of the data storage device 200 is in a trusted state based on the second hardware integrity report; one verification operation verifies whether the startup process of the storage application 230 of the data storage device 200 is normal based on the second program integrity report; and one verification operation verifies whether the running status of the storage application 230 of the data storage device 200 is normal based on the second program integrity report. The latter two verification operations are performed to determine whether the storage application 230 is in a trusted state. These three verification operations will be described in detail below.
[0387] Verification Operation 1: For the second hardware integrity report in the second integrity measurement report, the data access device 100 verifies whether the hardware of the data storage device 200 is in a trusted state by parsing the second hardware integrity report.
[0388] The second hardware integrity report includes a second hardware metric. A second reference hardware metric is configured on the data access device 100 side. The second reference hardware metric is generated based on information about trusted hardware. The presentation format and generation method of the second reference hardware metric are similar to those of the second hardware metric.
[0389] The way in which the data access device 100 compares the second hardware metric value with the second reference hardware metric value is similar to the way in which the data storage device 200 compares the first hardware metric value with the first reference hardware metric value. For details, please refer to the foregoing description, which will not be repeated here.
[0390] If the second hardware metric satisfies the second reference hardware metric, it is determined whether the hardware of the data storage device 200 is trustworthy; otherwise, it is not trustworthy. For the meaning of "satisfies," please refer to the aforementioned related explanations, which will not be repeated here.
[0391] Verification Operation 2: For the second program integrity report in the second integrity measurement report, the data access device 100 verifies whether the startup process of the application of the data storage device 200 is normal by parsing the second program integrity report.
[0392] When the second program integrity report includes a second startup metric, a second reference startup metric is configured on the data access device 100 side. This first reference startup metric is generated based on the normal startup process of the stored application 230. The presentation format and generation method of the second reference startup metric are similar to those of the second startup metric.
[0393] The way in which the data access device 100 compares the second startup metric value with the second reference startup metric value is similar to the way in which the data storage device 200 compares the first startup metric value with the first reference startup metric value. For details, please refer to the foregoing description, which will not be repeated here.
[0394] If the second startup metric meets the second reference operating metric, the startup process of the storage application 230 is determined to be normal; otherwise, it is abnormal. For the meaning of "meets," please refer to the aforementioned related explanations, which will not be repeated here.
[0395] Verification Operation 3: For the second program integrity report in the second integrity measurement report, the data access device 100 verifies whether the storage application 230 of the data storage device 200 is running normally by parsing the second program integrity report.
[0396] When the second program integrity report includes a second operational metric, a second reference operational metric is configured on the data access device 100 side. This first reference operational metric is generated based on the normal operating status of the storage application 230. The presentation format and generation method of the second reference operational metric are similar to those of the second operational metric.
[0397] The way in which the data access device 100 compares the second operating metric value with the second reference operating metric value is similar to the way in which the data storage device 200 compares the first operating cabinet metric value with the first reference operating metric value. For details, please refer to the foregoing description, which will not be repeated here.
[0398] If the second operating metric meets the second reference operating metric, the storage application 230 is determined to be operating normally; otherwise, it is not. For the meaning of "meets," please refer to the aforementioned related explanations, which will not be repeated here.
[0399] Data access device 100 determines whether the startup process of storage application 230 is normal through verification operation 2, and determines whether the running state of storage application 230 is normal through verification operation 3. If the startup process and / or the running state is normal, it determines that storage application 230 is trustworthy or in a trustworthy state. In practical applications, since a normal startup process and / or a normal running state represent three possible scenarios, the data access device 100 determines which scenario it considers the storage application 230 trustworthy based on the actual scenario. For example, data access device 100 pre-configures a first verification policy, which describes how to verify the data storage device 200 based on a second integrity metric report. This first verification policy can indicate under which scenarios the storage application 230 is considered trustworthy, and under which scenarios the hardware is trustworthy. The first verification policy will be described in detail below and will not be repeated here.
[0400] After performing the above verification operation, the data access device 100 can determine that the hardware of the data storage device 200 is in a trusted state, the startup process of the storage application 230 is normal, or the storage application 230 is running normally. In this case, the data access device 100 has successfully verified the data storage device 200.
[0401] After successfully authenticating the data storage device 200, the data access device 100 can receive access from the data storage device 200 (i.e., the storage application 230). If the data storage device 200 does not authenticate the data access device 100 (i.e., the data access device 100 and the data storage device 200 have only completed the authentication of the data access device 200, but the authentication of the data storage device 200 to the data access device 100 has not yet been initiated), the data access device 100 can also perform the aforementioned steps (such as steps 401 to 403) to realize the authentication of the data storage device 200 to the data access device 100. After the data storage device 200 successfully authenticates the data access device 100, data interaction can occur between the data storage device 200 and the data access device 100.
[0402] For example, target application 130 can initiate a data access request, which data access device 100 sends to data storage device 200.
[0403] On the data storage device 200 side, the data storage device 200 can receive and process the data access request, such as reading data from the data storage device 200 and feeding the data back to the target application 130. Alternatively, it can write data to the data storage device 200.
[0404] In this embodiment of the application, an identity mapping program is deployed on the data storage device 200. For a description of this identity mapping program, please refer to the foregoing content; it will not be repeated here. The data storage device 200 manages data access requests based on this identity identifier, that is, it determines whether the data access request needs to be processed, whether it can access the data indicated in the data access request, and in other words, whether the target application 130 has the necessary access permissions.
[0405] In this embodiment, the data storage device 200 has the feature of providing data lifecycle management. The data storage device 200 can provide the user with operation credentials to prove that the data storage device 200 has completed the operation instructed by the user during the data lifecycle management process. Specifically, see steps 407 to 410.
[0406] Step 407: Data access device 100 detects that the user performs a target operation on target application 130.
[0407] As described in the description of target application 130, target application 130 is deployed to complete the user's computing tasks. Here, we will first explain the deployment method of target application 130.
[0408] The data access device 100 provides a computing task distribution interface to users, through which users can distribute computing tasks to the data access device 100.
[0409] When the data access device 100 obtains the computing task from the computing task distribution interface, the data access device 100 launches the target application 130, which is used to complete the computing task.
[0410] The computation task distribution interface represents a function provided by the data access device 100 to the user, that is, the data access device 100 supports the user in distributing computation tasks. This application embodiment does not limit the specific form of the computation task distribution interface. For example, the computation task distribution interface can be a visual interface, in which the user can configure the specific content of the computation task through operations. Another example is that the computation task distribution interface can be a command with a set format. The user distributes the computation task by issuing the command with the set format to the data access device 100.
[0411] Since the target application 130 in this embodiment has memory isolation properties, the computing task distribution interface supports configuring memory isolation. For example, the computing task distribution interface can provide users with an option for memory isolation. When the user configures memory isolation through the computing task distribution interface, the data access device 100 configures an independent target memory space for the target application 130, ensuring that the target application 130 starts and runs within the target memory space. As another example, the computing task distribution interface only supports the distribution of confidential computing tasks. A confidential computing task is a computing task whose completion process requires isolation. That is, the computing task distributed by the user through the computing task distribution interface is a confidential computing task. After receiving the confidential computing task, the data access device 100 configures an independent target memory space for the target application 130, ensuring that the target application 130 starts and runs within the target memory space.
[0412] After the target application 130 runs on the data access device 100, the user can view the running status of the target application 130 through the data access device 100. In this embodiment, the data access device 100 also supports the user changing the running status of the target application 130. For example, the user can choose to close the target application 130 through the data access device 100. Another example is that the user can transfer the computing tasks performed by one target application 130 to another target application 130 through the data access device 100; this essentially means pausing or suspending the target application 130. Yet another example is that the user can change the access permissions of the data required by the target application 130 through the data access device 100, such as allowing other target applications 130 to access the data required by the target application 130. This embodiment does not limit the specific implementation method of the user changing the running status of the target application 130; for example, the user can change the running status of the target application 130 through a visual interface or commands.
[0413] Step 408: The data access device sends a notification message to the data storage device 200, which instructs the target operation to be performed on the data belonging to the target application 130.
[0414] When a user chooses to close the target application 130 via data access device 100, the data belonging to the target application 130 also needs to be deleted synchronously. Upon detecting that the user has closed the target application 130, data access device 100 can send a notification message to data storage device 200 to notify the deletion of the data belonging to the target application 130.
[0415] When a user selects to transfer a computing task from one target application 130 to another application via data access device 100, the data belonging to target application 130 needs to be transferred to the other target application 130. Upon detecting the user's operation to transfer the computing task, data access device 100 can send a notification message to data storage device 200, informing it that the data belonging to target application 130 will be transferred to the other target application 130.
[0416] When a user changes the access permissions of data belonging to the target application 130 via data access device 100, the access permissions of that data belonging to the target application 130 stored on the data storage device 200 also need to be changed. Upon detecting that the user has changed the access permissions of the data belonging to the target application 130, data access device 100 can send a notification message to data storage device 200 to notify the user of the change in the target application's data access permissions.
[0417] Step 409: After receiving the notification message, the data storage device 200 performs the target operation on the data belonging to the target application 130.
[0418] When a notification message is used to notify the deletion of data belonging to the target application 130, the data storage device 200 deletes the data belonging to the target application 130.
[0419] When a notification message is used to notify that data belonging to target application 130 is transferred to another target application 130, the data storage device 200 can mark the data belonging to target application 130 with the identity information of the other target application 130. The data storage device 200 can also set the data storage space that the other target application 130 is allowed to access, and the data storage space is the storage space where the data belonging to target application 130 is located.
[0420] When a notification message is used to notify a change in the data access permissions of a target data application, the data storage device 200 sets the access permissions for the data belonging to the target application 130. Subsequently, when other applications access the data belonging to the target application 130, the data storage device 200 can determine whether the other applications have the access permissions based on the set access permissions for the data belonging to the target application 130.
[0421] Step 410: The data storage device 200 provides an operation credential to the data access device 100. This operation credential is used to indicate that the target operation has been completed.
[0422] The data storage device 200 can generate an operation certificate based on the process of performing the target operation. This operation certificate can be computer program instructions required to perform the target operation, or configuration parameters necessary for performing the target operation. The data storage device 200 can sign the operation certificate.
[0423] For example, when the data storage device 200 executes a target operation, it can treat the selected computation instructions for executing the target operation as a whole, hash the selected computation instructions to obtain a hash value, which can be used as an operation credential. The data storage device 200 can then use a key built into its hardware to sign the hash value.
[0424] Step 411: The data access device 100 audits the executed target operation based on the operation credential. That is, it analyzes the operation credential to determine whether the target operation was actually executed or executed correctly.
[0425] The data access device 100 can determine whether the contents of the operation certificate are correct, such as whether the computer program instructions required to perform the target operation in the operation certificate are correct, or whether the configuration parameters required to perform the target operation in the operation certificate are correct.
[0426] The foregoing description uses the example of displaying operation credentials to the user. In practical applications, when the target application 130 performs data operations, such as modifying its own data access permissions, storing data, or changing data ownership, the data storage device 200, under the instruction of the target application 130, performs data operations on the data that the target application 130 needs to access. The data storage device 200 can also provide operation credentials to the target application. The specific implementation process is similar to the execution method of steps 408 to 411 mentioned above, except that: on the data access device 100 side, the target application 130 triggers the data access device 100 to generate a notification message. After receiving the operation credentials, the data access device 100 transmits the operation credentials to the target application 130.
[0427] In this embodiment, the data storage device 200 is able to maintain data integrity. The method by which the data storage device 200 maintains data integrity is described below:
[0428] In the data storage device 200, for any target application 130, the data storage device 200 (i.e., the data integrity program of the data storage device 200) can divide the data required by the target application 130 into data block granularities and calculate the hash value of each data block. This application embodiment does not limit the method of calculating the hash value of the data block. For example, the data storage device 200 can directly hash the data block using a hash algorithm to generate the hash value of the data block. Another example is that the data storage device 200 obtains a first key from the data access device 100, which may be a key derived by the data access device 100 based on its root key. The data storage device 200 then uses a hash algorithm to hash the data block and the first key, and the resulting hash value is the hash value of the data block.
[0429] The data storage device 200 organizes the hash values of each data block into a tree structure, forming a Merkle Tree.
[0430] In the embodiment shown in Figure 4, the example is that the data access device 100 directly provides a first integrity measurement report to the data storage device 200, and the data storage device 200 directly provides a second integrity measurement report to the data access device 100. This embodiment does not limit the method by which the data access device 100 obtains the first integrity measurement report; for example, the data access device 100 can obtain the first integrity measurement report from other devices. Similarly, this embodiment does not limit the method by which the data storage device 200 obtains the second integrity measurement report; for example, the data storage device 200 can obtain the second integrity measurement report from other devices.
[0431] In this embodiment, the data storage device 200 can verify the data processing environment of the data access device 100 through a first integrity measurement report to ensure that the data processing environment of the data access device 100 is secure, thereby ensuring that the data obtained by the data access device 100 from the data storage device 200 is not easily stolen or leaked. The data access device 100 can verify the data storage environment of the data storage device 200 through a second integrity measurement report to ensure that the data storage device 200 can guarantee data security and reduce the possibility of data theft or exposure. Furthermore, the data storage device 200 can further verify that the target operation performed on the data belonging to the target application 130 has been executed through operation credentials, thereby ensuring that the target operation performed on the data belonging to the target application 130 is actually executed. The data storage device 200 can more easily organize the data required by the target application 130 by constructing a Merkle tree, ensuring the integrity of the data required by the target application 130.
[0432] The data verification method shown in Figure 4 can be combined with remote proof technology. The process of implementing the data verification method shown in Figure 4 based on remote proof is explained below.
[0433] Remote attestation is a technique used in network communication where one end verifies whether the other end is in the expected operational state. This technology has wide applications in applied cryptography, system security, and confidential computing. In a remote attestation scenario, an independent verification server can be set up. Users can obtain remote attestation services through the verification server, compare the received metric for operational status with a reference value configured on the verification server, and determine whether they are in the expected operational state based on the comparison result.
[0434] Figure 5 shows an architecture diagram of another data protection system provided in this application embodiment. The data protection system includes a data access device 100, a data storage device 200, and a storage client 300 deployed close to the data access device 100.
[0435] The features of the data access device 100 and the data storage device 200 can be found in the foregoing description. They will not be repeated here.
[0436] The storage client 300 is a client deployed on the data access device 100 side of the data storage device 200. Data interaction between the data access device 100 and the data storage device 200 can be achieved through the storage client 300. For example, the data access device 100 (i.e., the target application 130) establishes a connection with the data server through the storage client 300. The data access device 100 sends a connection command to the storage client 300, which instructs to establish a connection with the data storage device 200. When the storage client 300 receives the connection command, it sends a connection establishment request to the data storage device 200 according to the connection command. This connection establishment request requests to establish a connection with the data storage device. For another example, when the data access device 100 needs to access data in the data storage device 200, the data access device 100 can send a data access command to the storage client 300, which instructs to access the data in the data storage device 200. Upon receiving the data access instruction, the storage client 300 sends a data access request to the data storage device 200, which requests access to the data in the data storage device 200. In other words, during the connection establishment and data access process, the storage client 300 can act as an intermediary between the data access device 100 and the data storage device 200.
[0437] In this embodiment of the application, the storage client 300 can trigger the verification process. For example, when the data access device 100 is mounted to the storage client 300, the storage client 300 can send a verification start message to the data access device 100. The verification start message is used to instruct the data access device 100 to start the verification process.
[0438] This application does not limit the specific form of the storage client 300. For example, the storage client 300 can be a hardware device, such as a computing device or hardware module deployed close to the data access device 100. Alternatively, the storage client 300 can be a software module, such as running on the data access device 100, allowing the target application 130 to interact with it. For instance, when the target application 130 is a virtual machine, the storage client 300 can be software installed within that virtual machine.
[0439] Figure 5 also illustrates the modules included in the data access device 100 and the data storage device 200. The first verification module 110 of the data access device 100 supports remote authentication. The second verification module 210 of the data storage device 200 also supports remote authentication. The interaction between the first verification module 110 and the second verification module 210 can be a remote authentication-compliant interaction method. The interaction method between the first verification module 110 and the second verification module 210 will be described in the embodiment shown in Figure 6, and will not be repeated here.
[0440] The first verification module 110 supporting remote authentication includes a first secure transmission channel management module 112 and a first measurement verifier 111. The first secure transmission channel management module 112 is used to establish a secure transmission channel with the second verification module 210 and to transmit data with the second verification module 210 based on the secure transmission channel, such as transmitting a first integrity measurement report and a second integrity measurement report (i.e., sending the first integrity measurement report to the second verification module 210 or obtaining the second integrity measurement report from the second verification module 210), and transmitting authentication materials that need to be exchanged during the establishment of the secure transmission channel. For example, when the secure transmission channel is a TLS-based secure transmission channel, the authentication materials are the information required to be exchanged in the TLS protocol.
[0441] The first secure transmission channel management module can also obtain the verification result of the second integrity measurement report from the first measurement verifier 111. The first measurement verifier 111 is used to compare the first integrity measurement report and the first reference measurement value based on the first verification strategy, and then generate a verification result (such as verification passed or verification failed). The first measurement verifier 111 includes three core components: the second reference measurement value, the first verification strategy; optionally, it also includes a first measurement strategy configuration module. The second reference measurement value can be an index built from the second reference measurement values such as the second reference startup measurement value, the second reference running measurement value, and the second reference hardware measurement value preset in the first verification module 110. Since there are multiple second reference measurement values, the first measurement verifier 111 can configure an index for the second reference measurement to quickly locate one or more of the second reference measurement values.
[0442] The first verification strategy specifies the verification method based on the second integrity measurement report. The first verification strategy describes under what conditions the data access device 100 passes verification. For example, if the verification strategy indicates that two of the measurement values in the first integrity measurement report (such as the second startup measurement value, the second operation measurement value, and the first hardware measurement value) are the same as the second reference measurement value, then the verification passes; otherwise, the verification fails. As another example, if the verification strategy indicates that all the measurement values in the first integrity measurement report (such as the second startup measurement value, the second operation measurement value, and the hardware measurement value) are the same as the second reference measurement value, then the verification passes; otherwise, the verification fails.
[0443] The first measurement strategy configuration module is a user-oriented module for configuring verification strategies, meaning that users can configure verification strategies according to their actual needs.
[0444] It should be noted that the description of the internal structure of the first verification module 110 and the second verification module 210 is only provided as an example of supporting remote proof. In fact, if the first verification module 110 and the second verification module 210 do not interact based on remote proof (such as defining a new interaction method between the first verification module 110 and the second verification module 210 that is different from remote proof), the internal structure of the first verification module 110 and the second verification module 210 can also be as shown in Figure 5. The functions of each internal component are the same as those mentioned in the previous description, the only difference being that the first verification module 110 and the second verification module 210 do not interact based on remote proof.
[0445] The second verification module 210 supporting remote authentication includes a second secure transmission channel management module 212 and a second measurement verifier 211. The second secure transmission channel management module 212 is used to establish a secure transmission channel with the first verification module 110 and to transmit data with the first verification module 110 based on the secure transmission channel module, such as transmitting a second integrity measurement report and a second integrity measurement report (i.e., sending a second integrity measurement report to the first verification module 110 or obtaining a first integrity measurement report from the first verification module 110), and transmitting authentication materials that need to be exchanged during the establishment of the secure transmission channel. For example, when the secure transmission is through a TLS secure transmission channel, the authentication materials are the information required to be exchanged in the TLS protocol.
[0446] The second secure transmission channel management module can also obtain the verification result of the first integrity measurement report from the second measurement verifier 211. The second measurement verifier 211 is used to compare the first integrity measurement report and the first reference measurement value based on the second verification strategy, and then generate a verification result (such as verification passed or verification failed). The second measurement verifier 211 includes three core components: the first reference measurement value, the second verification strategy; optionally, it also includes the second measurement strategy configuration. The first reference measurement value can be a first reference startup measurement value, a first reference running measurement value, and a first reference hardware measurement value preset in the second verification module 210. Since there are multiple first reference measurement values, an index can be configured for the first reference measurement in the second measurement verifier 211 to quickly locate one or more of the first reference measurement values.
[0447] The second verification strategy indicates the verification method for the second integrity measurement report. If the verification strategy indicates that the measurement values in the first integrity measurement report (such as the first startup measurement value, the first running measurement value, and the hardware measurement value) are all the same as the first reference measurement value, then the verification passes; otherwise, the verification fails.
[0448] The second measurement strategy configuration module is a user-oriented module for configuring verification strategies, meaning that users can configure verification strategies according to their actual needs.
[0449] Based on the data protection system shown in Figure 5, this application provides a verification method, as shown in Figure 6, which includes the following steps.
[0450] Step 601: The data access device 100 (such as the target application 130) initiates the mounting process through the storage client 300.
[0451] Mounting can be understood as the process by which data access device 100 (target application 130) makes data in data storage device 200 visible. For example, by mounting to data storage device 200, data access device 100 can obtain the structure of the file system on data storage device 200, such as which files exist in the file system and the relationship between files and directories.
[0452] The data access device 100 sends a mount instruction to the storage client 300, indicating that it needs to be mounted onto the data storage device 200. The data client interacts with the data storage device 200 based on a standard protocol interface to achieve the mount. This standard protocol interface is an interface that supports storage protocols, such as the Internet Small Computer System Interface (iSCSI), Nonvolatile Memory Express (NVMe), a file system protocol interface, or an object storage service protocol interface. The file system protocol interface can be a network file system (NFS), a server message block (SMB) / common internet file system (CIFS), and the object storage service protocol can be the S3 protocol.
[0453] Step 602: The storage client 300 sends a verification start message to the data access device 100, which is used to indicate the start of verification.
[0454] During the mounting process, the data access device 100 and the data storage device 200 interact and establish a secure transmission channel. In the initial stage of establishing the secure transmission channel, both parties need to verify each other. In this embodiment, when the storage client 300 receives the mounting command, it can send a verification start message to initiate the verification process.
[0455] Step 603: After receiving the verification start message, the data access device 100 (i.e., the first verification module 110) obtains the first integrity measurement report stored in the data access device 100. The method for generating the first integrity measurement report can be found in the foregoing description and will not be repeated here.
[0456] Step 604: The data access device 100 (i.e., the first verification module 110) sends a first request to the data storage device 200 (i.e., the second verification module 210), which carries a first integrity measurement report.
[0457] It should be noted that the first request is essentially a request carrying a first integrity measurement report, and its function is the same as that of the first verification request. When the data access device 100 and the data storage device 200 interact based on remote authentication, the first request can be a certificate verification request in the TLS protocol, or a message carrying an identity verification certificate. When the data access device 100 and the data storage device 200 interact in other ways, the first request can be a message carrying credentials, which can be credentials that identify the identity of the data access device 100, and the reserved field of the credential can carry the first integrity measurement report. Of course, an interaction method using the first integrity measurement report and a second integrity measurement report for mutual verification can also be defined between the data access device 100 and the data storage device 200. In this case, the first request is the message carrying the first integrity measurement report.
[0458] The transmission of the first integrity measurement report can utilize existing message fields from existing remote attestation methods. For example, it can employ the remote attestation fields used in the ARM Confidential Computing Architecture (ARM CCA). The ARM CCA remote attestation process uses the Remote Attestation Procedures (RATS)-TLS scheme, a transport layer protection scheme based on public key certificates. The public key certificate in the RATS-TLS scheme uses the X.509 certificate format. This X.509 certificate contains an Evidence field, which can be used to carry the first integrity measurement report. This Evidence field also uses the existing measurement report format to separately carry the first hardware integrity report and the first program integrity report within the first integrity measurement report.
[0459] The fields included in the first hardware integrity report are shown in Table 1. Table 1 is only an example. In actual applications, the first hardware integrity report can also be in other formats.
[0460] Table 1
[0461] The fields included in the first program integrity report are shown in Table 2. Table 2 is only an example. In practical applications, the first program integrity report can also be in other formats.
[0462] Table 2
[0463] Step 605: After receiving the first request, the data storage device 200 (second verification module 210) verifies the data access device 100 based on the first integrity measurement report. The verification method can be found in the relevant description in step 403 and will not be repeated here.
[0464] Within the second verification module 210, the second secure transmission channel management module 212 extracts the first integrity measurement report from the first verification request and transmits it to the second measurement verifier. The second measurement verifier verifies the first integrity measurement report based on the second verification strategy. The verification method can be found in step 403 and related descriptions of the second measurement verifier, which will not be repeated here.
[0465] The second secure transmission channel management module 212 obtains the verification result from the second measurement. If the verification result indicates that the verification is successful, the second verification module 210 can execute subsequent steps. Otherwise, the second verification module 210 fails to verify through the data access device 100, and the data storage device 200 does not allow the data access device 100 to access it.
[0466] Step 606: The data storage device 200 (second verification module 210) obtains the second integrity measurement report and sends a second request to the data access device 100 (first verification module 110), the second request carrying the second integrity measurement report.
[0467] After the data access device 100 is verified based on the first integrity metric report, the data storage device 200 executes step 605 so that the data access device 100 verifies the data storage device 200.
[0468] The second request represents a similar meaning to the first request, the only difference being that the measurement report carried in the second request is a second integrity measurement report. Applied to TLS-based remote authentication scenarios, this second request can be understood as, taking a TLS-based secure transmission channel as an example, the message sent by the data storage device 200 to the data access device 100 when providing its own certificate in the TLS handshake protocol. This second integrity measurement report can be stored in a reserved field of its own certificate. The data access device 100 no longer accesses the data storage device 200.
[0469] Step 607: After receiving the second request, the data access device 100 (first verification module 110) verifies the data storage device 200 based on the second integrity measurement report. The verification method can be found in the relevant description in step 405 and will not be repeated here.
[0470] Within the first verification module 110, the first secure transmission channel management module 112 extracts the second integrity measurement report from the second verification request and transmits the second integrity measurement report to the first measurement verifier. The first measurement verifier verifies the second integrity measurement report based on the first verification strategy. The verification method can be found in step 405 and related descriptions of the first measurement verifier, which will not be repeated here.
[0471] The first secure transmission channel management module 112 obtains the verification result from the first measurement. If the verification result indicates that the verification is successful, the first verification module 110 can execute subsequent steps. Otherwise, the first verification module 110 fails to verify through the data access device 100, and the data access device 100 no longer accesses the data storage device 200.
[0472] After the data access device 100 passes the verification based on the second integrity measurement report, it executes step 607 to establish a secure transmission channel between the data access device 100 and the data storage device 200.
[0473] Step 608: After the data access device 100 verifies the data storage device 200, the data access device 100 interacts with the data storage device 200 to establish a secure transmission channel.
[0474] After both parties have successfully verified the data, the data access device 100 and the data storage device 200 can interact to establish the parameters required for a secure transmission channel, thereby completing the construction of a secure transmission channel. For example, according to the description in the TLS protocol, the two parties can negotiate the key, encryption algorithm, etc., used to encrypt data during data transmission. This application embodiment does not limit the method of constructing a secure transmission channel.
[0475] It should be noted that, to highlight the mutual verification process between the data access device 100 and the data storage device 200, this process (i.e., steps 602 to 606) is presented separately. In practical applications, the construction process of a secure transmission channel may include the mutual verification process between the data access device and the data storage device 200. This verification process is executed at the initial stage of constructing the secure transmission channel. The interaction between the data access device 100 and the data storage device 200 in step 607 can be understood as the operation performed to construct the secure transmission channel after both parties have successfully verified each other.
[0476] Step 609: After the sequential transmission channel between the data access device 100 and the data storage device 200 is configured, the data access device 100 (i.e., the target application 130) can access the data storage device 200 through the storage client 300, that is, send a data access request to the data storage device 200.
[0477] The data storage device 200 can configure identity information for the target application 130, isolate the data that the target application 130 needs to access, and maintain the integrity of the target application 130's data. Furthermore, when a user performs a target operation on the target application 130 through the data access device 100, the target operation needs to be synchronized to the data that the target application 130 needs to access. That is, the data storage device 200 also needs to perform the corresponding target operation on the data of the target application. The data storage device 200 can provide the user with operation credentials through the data access device 100 to verify that the target operation has been executed.
[0478] The embodiment shown in Figure 6 mentions that the first verification module 110 and the second verification module 210 verify the integrity measurement report. In this embodiment, from the perspective of the deployment of the first measurement verifier and the second measurement verifier, two verification modes are provided. The two verification modes are described below:
[0479] The first verification mode is the tightly coupled interaction mode.
[0480] As shown in Figure 7A, in this tightly coupled interaction mode: the first verification module 110 is deployed on a computing device, which is the data access device 100. That is, the first secure transmission channel management module 112 and the first measurement verifier in the first verification module 110 are tightly coupled together and deployed within the same computing device. The second verification module 210 is deployed on a computing device, which is the data storage device 200. That is, the second secure transmission channel management module 212 and the second measurement verifier in the second verification module 210 are tightly coupled together and deployed within the same computing device.
[0481] In the tightly coupled interaction mode, the verification process between the data access device 100 and the data storage device 200 is completed based on the direct interaction between them. This mode offers higher verification efficiency and stronger real-time performance.
[0482] The second verification mode is the loosely coupled interaction mode.
[0483] As shown in Figure 7B, in this loosely coupled interaction mode: the first verification module 110 is distributed across two different computing devices. For example, the first secure transmission channel management module 112 within the first verification module 110 is deployed on one computing device, which can be referred to as a data access node. The first metric verifier 111 is deployed on a separate verification server. The second verification module 210 is distributed across two different computing devices, which can be referred to as storage nodes. For example, the second secure transmission channel management module 212 within the second verification module 210 is deployed on one computing device, and the second metric verifier 211 is deployed on a separate verification server.
[0484] In this mode, the verification operations in the data access device 100 and the data storage device 200 are handled by the verification server, while other operations in the data access device 100 are handled by the data access node, and other operations in the data storage device 200 are handled by the storage node.
[0485] In this loosely coupled interaction mode, the data access node can provide a first integrity measurement report to the verification server. The verification server verifies the data access node based on the first integrity measurement report and generates a first verification result. The data access node obtains the first verification result from the verification service. In scenarios where the storage node needs to verify the data access node (for an explanation of such scenarios, please refer to the relevant explanation in step 402, which will not be repeated here), the data access node can send a first verification request to the storage node, which carries the first verification result.
[0486] The storage node can provide a second integrity measurement report to the verification server. The verification server verifies the storage node based on the second integrity measurement report and generates a second verification result. The storage node obtains the second verification result from the verification service. In scenarios where the data access node needs to verify the storage node (for an explanation of such scenarios, please refer to the relevant explanation in step 404, which will not be repeated here), the storage node can send a second verification request to the data access node, which carries the second verification result. In this mode, the verification server can support the configuration of either the first or second verification strategy, has stronger scalability, and is compatible with current mainstream public key systems.
[0487] This application also provides a computing device 800 as shown in FIG8. The computing device 800 includes a bus 801, a processor 802, a communication interface 803, and a memory 804. The processor 802, the memory 804, and the communication interface 803 communicate with each other via the bus 801.
[0488] The processor 802 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0489] The memory 804 can be dynamic random access memory (DRAM). Besides DRAM, the memory 804 can also be other types of random access memory, such as static random access memory (SRAM). Additionally, the memory 804 can also be read-only memory (ROM). For example, read-only memory can be programmable read-only memory (PROM) or erasable programmable read-only memory (EPROM). The memory 804 can also be flash memory, hard disk drive (HDD), or solid-state drive (SSD).
[0490] The memory 804 stores computer program instructions. The processor 802 invokes these computer program instructions to execute the steps performed by the data access device 100 in the method described in FIG4 or FIG6, or invokes these computer program instructions to execute the steps performed by the data storage device 200 in the method described in FIG4 or FIG6. The memory 804 may also include other software modules required for running processes, such as an operating system (e.g., the target application program 130, application management module 120, and first verification module 110 in the data access device 100, or the stored application program 230, stored program management module 220, and second verification module 210 in the data storage device 200). The operating system may be LINUX. TM UNIX TM WINDOWS TM wait.
[0491] This application also provides a computing device system, which includes at least one computing device 900 as shown in FIG. 9. The computing device 900 includes a bus 901, a processor 902, a communication interface 903, and a memory 904. The processor 902, the memory 904, and the communication interface 903 communicate with each other via the bus 901. At least one computing device 900 in the computing device system communicates with each other through a communication path.
[0492] The specific types of processor 902 and memory 904 can be found in the relevant descriptions of processor 902 and memory 904, and will not be repeated here. Processor 902 calls computer program instructions stored in memory 904 to execute some or all of the steps performed by data access device 100 in the method described in FIG4 or FIG6. Alternatively, processor 902 calls computer program instructions stored in memory 904 to execute some or all of the steps performed by data storage device 200 in the method described in FIG4. The memory may also include other software modules required for running processes, such as an operating system. The operating system may be LINUX. TM UNIX TM WINDOWS TM wait.
[0493] At least one computing device 900 in the computing device system establishes communication with each other through a communication network. Each computing device 900 runs any one or more modules of the data access device 100 (such as one or more of the first verification module 110, the target application 130, and the application management module 120).
[0494] At least one computing device 900 in the computing device system establishes communication with each other through a communication network, and each computing device 900 runs any one or more modules in the data storage device 200 (such as one or more of the second verification module 210, storage application program, and storage program management module).
[0495] The descriptions of the processes corresponding to the above-mentioned figures each have their own emphasis. For parts of a process that are not described in detail, please refer to the relevant descriptions of other processes.
[0496] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. A computer program product includes computer program instructions, which, when loaded and executed on a computer, generate entirely or partially the flow or function described in FIG. 4 of this embodiment.
[0497] The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., SSD).
[0498] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data protection method, characterized by, The method is applied to a data storage device and includes: Obtain a first integrity measurement report, which is used to indicate the data processing environment within the data access device, and the data processing environment indicates the hardware environment and / or software environment within the data access device; The data access device is verified based on the first integrity measurement report; After the data access device is verified, the system receives and processes the data access request sent by the data access device, which is used to request access to data in the data storage device.
2. The method of claim 1, wherein, The first integrity metric report is generated by the hardware of the data access device.
3. The method of claim 1 or 2, wherein, The data processing environment includes some or all of the following: The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates the data access request.
4. The method of claim 3, wherein, The target application has memory isolation properties.
5. The method according to any one of claims 1 to 3, characterized in that, The first integrity metric report includes one or more of the following: First Hardware Integrity Report, First Program Integrity Report; The first hardware integrity report is used to characterize the hardware information in the data access device, and the first program integrity report is used to characterize the startup process or running status of the target application in the data access device.
6. The method of claim 5, wherein, The first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device. The first program integrity report includes a first startup metric value or a first running metric value, where the first startup metric value is generated based on the startup process of the target application, and the first running metric value is generated based on the running status of the target application.
7. The method according to any one of claims 1 to 6, characterized in that, The process of obtaining the first integrity measurement report includes: During the process of establishing a connection with the data access device, the first integrity measurement report is obtained; or The first integrity metric report is periodically retrieved.
8. The method of claim 6, wherein, The verification of the data access device based on the first integrity measurement report includes one or more of the following: Compare the first hardware metric value with the first reference hardware metric value; Compare the first startup metric value with the first reference startup metric value; Compare the first operating metric value with the first reference operating metric value; The first reference hardware metric is generated based on information about trusted hardware, the first reference startup metric is generated based on the normal startup process of the target application, and the first reference running metric is generated based on the normal running state of the target application.
9. The method of any one of claims 1-8, wherein, Also includes: The identity information of the target application is determined based on the first integrity measurement report; The data access requests are controlled based on the identity information.
10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: Generate a second integrity measurement report, which indicates the data storage environment within the data storage device, the data storage environment indicating the hardware and / or software environment within the data storage device; Provide the second integrity metric report.
11. The method of claim 10, wherein, The second integrity metric report is generated by the hardware of the data storage device.
12. The method of claim 10 or 11, wherein, The data storage environment includes some or all of the following: The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is an application deployed on the data storage device that needs to be called when storing data.
13. The method of claim 12, wherein, The storage application has memory isolation properties.
14. The method according to any one of claims 12 to 13, characterized in that, The second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device. The second program integrity report includes a second startup metric value or a second running metric value, where the second startup metric value is generated based on the startup process of the storage application, and the second running metric value is generated based on the running status of the storage application.
15. The method according to any one of claims 12 to 14, wherein, The storage application includes some or all of the following: Data integrity procedures, identity mapping procedures; The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the identity information of the target application.
16. A data protection method, characterized by, The method includes: Generate a first integrity measurement report, which is used to indicate the data processing environment within the data access device; Provide the first integrity metric report; Obtain a verification result, the verification result indicating that the data storage device has passed the verification of the data access device according to the first integrity measurement report; A data access request is sent to the data storage device, the data access request being used to request access to data in the data storage device.
17. The method of claim 16, wherein, The first integrity metric report is generated by the hardware of the data access device.
18. The method of claim 16 or 17, wherein, The data processing environment includes some or all of the following: The hardware of the data access device and the target application in the data access device, wherein the target application is an application deployed on the data access device that generates the data access request.
19. The method of claim 18, wherein, The target application has memory isolation properties.
20. The method of claim 18 or 19, wherein, The first integrity metric report includes one or more of the following: First Hardware Integrity Report, First Program Integrity Report; The first hardware integrity report is used to characterize the hardware information in the data access device, and the first program integrity report is used to characterize the startup process or running status of the target application in the data access device.
21. The method of claim 20, wherein, The first hardware integrity report includes a first hardware metric value, which is generated based on information about the hardware in the data access device. The first program integrity report includes a first startup metric value or a first running metric value, where the first startup metric value is generated based on the startup process of the target application, and the first running metric value is generated based on the running status of the target application.
22. The method of any one of claims 16 to 21, wherein, The provision of the first integrity metric report includes: During the process of establishing a connection with the data storage device, the first integrity measurement report is provided; or The first integrity metric report is periodically provided to the storage device.
23. The method of any one of claims 16 to 22, wherein, Before sending the data access request to the data storage device, the method further includes: Obtain a second integrity measurement report, which indicates the data storage environment within the data storage device, the data storage environment indicating the hardware and / or software environment within the data storage device; The data storage device was verified as valid based on the second integrity metric report.
24. The method of claim 23, wherein, The second integrity metric report is generated by the hardware of the data storage device.
25. The method of claim 23 or 24, wherein, The data storage environment includes some or all of the following: The hardware of the data storage device and the storage application in the data storage device, wherein the storage application is an application deployed on the data storage device that needs to be called when storing data.
26. The method of claim 25, wherein, The storage application has memory isolation properties.
27. The method of claim 25 or 26, wherein, The second integrity metric report includes one or more of the following: Second hardware integrity report, second program integrity report; The second hardware integrity report is used to characterize the hardware information in the data storage device, and the second program integrity report is used to characterize the startup process and running status of the storage application in the data storage device.
28. The method of claim 27, wherein, The second hardware integrity report includes a second hardware metric value, which is generated based on information about the hardware in the data storage device. The second program integrity report includes a second startup metric value or a second running metric value, where the second startup metric value is generated based on the startup process of the storage application, and the second running metric value is generated based on the running status of the storage application.
29. The method of any one of claims 25 to 28, wherein, The storage application includes some or all of the following: Data integrity procedures, identity mapping procedures; The data integrity program is used to maintain the integrity of the data that the target application needs to access, and the identity mapping program is used to assign identity information to the target application. The data that the target application needs to access is labeled with the identity information of the target application.
30. A data storage device, comprising: The data storage device includes: The second verification module is used to obtain a first integrity measurement report, which indicates the data processing environment within the data access device, and the data processing environment indicates the hardware environment and / or software environment within the data access device; and to verify the data access device based on the first integrity measurement report. The storage application is configured to receive and process a data access request sent by the data access device after the second verification module has verified the data access device. The data access request is used to request access to data in the data storage device.
31. The apparatus of claim 30, wherein, The first integrity metric report is generated by the hardware of the data access device.
32. A data access device, characterized by The data access device includes: A first hardware security module is used to generate a first integrity measurement report, which is used to indicate the data processing environment within the data access device. A first verification module is configured to provide the first integrity measurement report; obtain a verification result, wherein the verification result indicates that the data storage device has passed the verification of the data access device based on the first integrity measurement report; The target application is used to send a data access request to the data storage device, the data access request being used to request access to data in the data storage device.
33. The apparatus of claim 32, wherein, The first integrity measurement report is generated by the hardware of the data access device.
34. A computing device, comprising: The computing device includes a processor and memory; The memory is used to store computer program instructions; The processor executes computer program instructions in the memory to perform the method as described in any one of claims 1 to 29.
35. A computer-readable storage medium, comprising: When the computer-readable storage medium is executed by a computing device, the computing device performs the method of any one of claims 1 to 29.
Citation Information
Patent Citations
Method for verifying completeness of platform, network device and network system
CN101784051A
Cloud server monitoring method, device and equipment and storage medium
CN111737081A
Application program access method and electronic equipment
CN113468606A
System starting method, system containing trusted computing base software, equipment and medium
CN116484379A
Cross-domain authentication method for trusted access of industrial internet equipment
CN117081734A