Security label loading method and apparatus

By loading security labels only on the first partition in the operating system, the problem of CPU resource consumption caused by the cumbersome security label loading process is solved, resulting in faster startup speed, better user experience, and enhanced operating system security.

WO2026156509A1PCT designated stage Publication Date: 2026-07-30YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
YINWANG INTELLIGENT TECHNOLOGIES CO LTD
Filing Date
2025-01-21
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

In existing technologies, the process of loading security labels for access subjects and objects by the operating system is cumbersome, resulting in excessive CPU resource consumption and affecting startup efficiency and user experience.

Method used

By obtaining the first load manifest file, security labels are loaded only on the first partition of the operating system. The preset security label configurations of the first attribute and the second attribute are used to identify them respectively, thereby reducing CPU load and improving boot speed.

Benefits of technology

It reduces CPU load, improves operating system startup speed and user experience, supports secondary development of the operating system, and enhances security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073789_30072026_PF_FP_ABST
    Figure CN2025073789_30072026_PF_FP_ABST
Patent Text Reader

Abstract

A security label loading method and apparatus, relating to the field of intelligent control. In the method, a first device may compare a preset security label configuration of a writable attribute with a security label configuration of a writable partition of an operating system, determine a security label loading list on the basis of a difference between the configurations, and perform security label loading on a file and / or a target of the writable partition on the basis of the security label loading list. The method can reduce CPU load, improve the startup speed of an operating system, and restore a modified security label in the operating system, thereby improving the security of the operating system and improving user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Security tag loading method and device Technical Field

[0001] This application relates to the field of intelligent control, and in particular to a method and apparatus for loading security tags. Background Technology

[0002] Mandatory access control (MAC) is an access control mechanism based on security policies and enforced by the operating system, which can improve the security of the operating system.

[0003] In related technologies, when the operating system starts up, it needs to load the security tags of the access subject and the access object. However, the security tag loading process is cumbersome and may consume too much central processing unit (CPU) resources, reducing the operating system's startup efficiency and affecting the user experience. Summary of the Invention

[0004] This application provides a method and apparatus for loading security tags, which can reduce CPU resource consumption, improve operating system startup efficiency, and enhance user experience when loading security tags.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] In a first aspect, embodiments of this application provide a security label loading method applied to a first device, comprising: obtaining a first loading manifest file; the first loading manifest file being associated with a preset security label configuration of a first attribute of the currently running version of the operating system and a security label configuration of a first partition in which the operating system is running; the operating system including a first partition and a second partition, the second partition corresponding to a preset security label configuration of a second attribute, the first partition corresponding to a preset security label configuration of a first attribute, and the preset security label configuration of the first attribute and the preset security label configuration of the second attribute being separately identified; and loading security labels for a first element to be configured in the first partition in which the operating system is running, according to the first loading manifest file.

[0007] The target element can be used to indicate files and / or directories in a pre-configured security label setup. The element to be configured can be used to indicate files and / or directories in the operating system that require security label configuration.

[0008] In this way, the preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified respectively. The first device only loads security labels for the first partition in the first loading manifest file and loads the preset security labels of the first attribute. It is not necessary to load all the preset security labels, which reduces CPU load, improves the operating system startup speed, and improves the user experience.

[0009] In one possible implementation, the second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

[0010] In one possible implementation, the first attribute is a read / write attribute, and the first partition is the operating system's read / write partition.

[0011] In one possible implementation, the first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

[0012] In one possible implementation, the first attribute is a write-only attribute and a read-write attribute, and the first partition is a write-only partition and a read-write partition of the operating system.

[0013] In this way, the preset security label configurations for write-only and read-write attributes are identified separately from the preset security label configurations for read-only attributes. The first device only loads security labels for the write-only and read-write partitions in the first loading manifest file, loading only a portion of the security labels instead of all the preset security labels. This reduces CPU load and improves operating system startup speed.

[0014] In one possible implementation, the preset security label configuration of the first attribute of the currently running version of the operating system includes: a first target element and a security label of the first target element; the security label configuration of the first partition on which the operating system is running includes: a first element to be configured and a security label of the first element to be configured.

[0015] In one possible implementation, the first load manifest file is determined by comparing the preset security label configuration of the first attribute of the currently running version of the operating system with the security label configuration of the first partition on which the operating system is running; the first load manifest file includes: the preset security label configuration of the first attribute of the currently running version of the operating system when the first element to be configured is the same as the first target element and the security label of the first element to be configured is different from the security label of the first target element, and the preset security label configuration of the first attribute of the currently running version of the operating system when the first element to be configured is different from the first target element.

[0016] Thus, the first loading manifest file includes a preset security label configuration for the first attribute of the current running version of the operating system, which differs from the security label configuration of the first partition where the operating system is running. When the operating system subsequently loads the security labels from the first loading manifest file, it can restore the security labels in the first partition of the operating system, ensuring that the operating system can restore the security labels of elements whose previous running state did not conform to the expected configuration after startup. This supports secondary development scenarios for the operating system, improves the applicability of the embodiments of this application, and enhances the security of the operating system.

[0017] In one possible implementation, the preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately by a partition information file; the partition information file includes the attribute information of the target element, including the second attribute and the first attribute.

[0018] In this way, the preset security label configuration of the first attribute and the preset security label configuration of the second attribute can be distinguished by the partition information file, which is a simple and efficient classification method.

[0019] In one possible implementation, the method further includes: obtaining a second load file manifest when the upgrade identifier indicates that the operating system is booting for the first time after an upgrade; the second load file manifest is associated with a preset security label configuration of a first attribute of the currently running version of the operating system and a preset security label configuration of a first attribute of the target version; the upgrade identifier is generated after the operating system upgrade is completed; and security labels are loaded onto the first partition where the operating system is running according to the third load file manifest; the third load file manifest is determined by merging the first load file manifest and the second load file manifest. The target version can be used to indicate the target upgrade version, and the preset security label configuration of the first attribute of the target version is the same as the preset security label configuration of the first attribute of the target upgrade version.

[0020] In this way, when the operating system boots for the first time after the upgrade, it only needs to load the third load file list obtained by merging the first and second load file lists. It does not need to load all the preset security labels. This ensures that the operating system loads the security labels in the first partition after the upgrade and restores the security labels in the first partition of the operating system. This reduces CPU consumption, increases the operating system boot efficiency, and improves the user experience.

[0021] In one possible implementation, the pre-configured security label of the first attribute of the currently running version of the operating system includes: a first target element and a security label of the first target element; the pre-configured security label of the first attribute of the target version includes a second target element and a security label of the second target element. This allows the operating system to securely load the first element to be configured based on the security labels of the first and second target elements.

[0022] In one possible implementation, the second load manifest file is determined by comparing the preset security label configuration of the first attribute of the current running version of the operating system with the preset security label configuration of the first attribute of the target version; the second load manifest file includes: the preset security label configuration of the first attribute of the target version when the first target element and the second target element are inconsistent, and the preset security label configuration of the first attribute of the target version when the first target element and the second target element are consistent, but the security label of the first target element is inconsistent with the security label of the second target element.

[0023] In this way, the target elements to be updated and their security labels can be determined during the operating system upgrade, thus obtaining the second load manifest file.

[0024] In one possible implementation, if the second target element in the first load manifest file is the same as the second target element in the second load manifest file, and the security label of the second target element in the first load manifest file is different from the security label of the second target element in the second load manifest file, the third load manifest file includes the security label of the second target element in the second load manifest file, but does not include the security label of the second target element in the first load manifest file.

[0025] In this way, when there is a conflict between the contents of the first and second load manifest files, the default security label configuration in the second load manifest file shall prevail, thereby improving the security of the operating system.

[0026] In one possible implementation, the upgrade identifier becomes invalid after the first boot following an operating system upgrade.

[0027] Thus, the upgrade identifier is valid on the first boot after the upgrade, but invalid on subsequent boots after the operating system upgrade. The operating system can use different differentiated security label list generation mechanisms in different scenarios to improve the efficiency and security of security label loading.

[0028] In one possible implementation, after loading a security label onto the first partition where the operating system runs, based on the third load manifest file, the method further includes: clearing the contents of the third load manifest file.

[0029] In this way, when the operating system is upgraded or restarted, the new content that needs to be loaded can be placed in the third-party manifest file, so that the operating system can load the contents of the third-party manifest file subsequently. There is no need to create a new third-party file, saving time and resources and improving efficiency.

[0030] One possible implementation includes: obtaining a second configurable element and a security label of the second configurable element from a second device, which is the second partition on which the operating system is running.

[0031] In this way, the security label of the second configurable element in the second partition of the operating system is loaded by the second device, avoiding the repeated loading of the security label of the second configurable element in the second partition when the operating system of the first device starts up, thus improving the startup speed of the operating system.

[0032] In one possible implementation, the security label of the second element to be configured is associated with the preset security label configuration of the second attribute of the target version of the operating system and the second element to be configured of the second partition on which the operating system is running.

[0033] In one possible implementation, the security label of the second element to be configured in the second partition of the operating system is the security label of the corresponding third target element; the second element to be configured corresponds to the third target element; the third target element and its security label belong to the preset security label configuration of the second attribute of the target version.

[0034] In one possible implementation, the pre-configured security label of the second attribute of the target version passes the consistency check with the second configurable element of the second partition of the operating system.

[0035] In one possible implementation, the third target element of the second attribute of the target version passes the consistency check with the second configuration element of the second partition of the operating system.

[0036] This ensures that the second configurable element of the operating system is not omitted, thus guaranteeing the security and accuracy of the operating system.

[0037] In one possible implementation, if the consistency check between the preset security label configuration of the second attribute of the target version and the second configurable element of the second partition running the operating system fails, the result of the consistency check includes a fourth target element, which includes a third target element, and the fourth element is inconsistent with the second configurable element.

[0038] In this way, the results of the consistency check can be used to instruct the developers, who can then correct the second element to be configured based on the results, ensuring that no element is omitted.

[0039] In one possible implementation, consistency checks are used to verify whether the third target element is consistent with the second element to be configured.

[0040] Secondly, embodiments of this application provide a security label loading method applied to a second device, comprising: determining a security label for a second element to be configured in the second partition of the operating system based on a preset security label configuration of a second attribute of a target version of the operating system and a second element to be configured in the second partition of the operating system; the operating system includes a first partition and a second partition, the second partition corresponding to a preset security label configuration of the second attribute, the first partition corresponding to a preset security label configuration of the first attribute, and the preset security label configuration of the second attribute and the preset security label configuration of the first attribute being identified separately.

[0041] Thus, by using the preset security label configuration of the second attribute and the second configurable element of the second partition running the operating system, the security label of the second configurable element of the second partition running the operating system can be determined. This eliminates the need to determine the security label of the second configurable element of the second partition running the operating system through all preset security label configurations, reducing the amount of data processed. This improves the efficiency of determining the security label of the second configurable element of the second partition running the operating system.

[0042] In one possible implementation, the second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

[0043] In one possible implementation, the first attribute is a read / write attribute, and the first partition is the operating system's read / write partition.

[0044] In one possible implementation, the first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

[0045] In one possible implementation, the first attribute is a read-write attribute and a write-only attribute, and the first partition includes a read-write partition and a write-only partition.

[0046] Thus, the preset security label configurations for write-only and read-write attributes are identified separately from the preset security label configuration for read-only attributes. The second device can determine the security label of the second element to be configured in the read-only partition based on the preset security label of the read-only attribute.

[0047] In one possible implementation, determining the security label of the second configurable element of the second partition running the operating system, based on the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition running the operating system, includes: performing a consistency check between the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition running the operating system; if the consistency check passes, loading the security label of the second configurable element of the second partition running the operating system based on the preset security label configuration of the second attribute, so as to determine the security label of the second configurable element of the second partition running the operating system.

[0048] This ensures that the second configurable element of the operating system is not omitted, thus guaranteeing the security and accuracy of the operating system.

[0049] One possible implementation includes sending a second configurable element of a second partition on which the operating system is running, along with a security label of the second configurable element, to the first device.

[0050] In this way, the first device can obtain the second configurable element and the security label of the second partition on which the operating system is running. Subsequently, when the operating system of the first device starts up, it can obtain the second configurable element and the security label of the read-only partition of the operating system, without having to load the security label of the read-only partition again, thus improving the efficiency of loading the operating system security label.

[0051] In one possible implementation, the preset security label configuration of the second attribute of the target version includes a third target element and the security label of the third target element.

[0052] In one possible implementation, security labels are loaded onto the second configurable element of the second partition running the operating system according to the preset security label configuration of the second attribute, so as to determine the second configurable element of the second partition running the operating system and the security label of the second configurable element. This includes loading the security label of the corresponding third target element onto the second configurable element, so as to determine the second configurable element of the second partition running the operating system and the security label of the second configurable element.

[0053] In this way, the operating system can load security labels for the elements of the read-only partition to determine the security label for each element.

[0054] In one possible implementation, consistency checks are used to verify whether the third target element is consistent with the second element to be configured.

[0055] One possible implementation includes: if the consistency check fails, indicating the result of the consistency check to the user; the result of the consistency check includes a fourth target element, which includes a third target element, and the fourth element is inconsistent with the second element to be configured.

[0056] In this way, developers can correct the second element to be configured based on the results of the consistency check, so that the second element to be configured is not omitted.

[0057] One possible implementation includes: the preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately through a partition information file; the partition information file includes attribute information of the target element, and the attribute information includes the second attribute and the first attribute.

[0058] In this way, the preset security label configuration of the first attribute and the preset security label configuration of the second attribute can be distinguished by the partition information file, which is a simple and efficient classification method.

[0059] Thirdly, embodiments of this application provide a security label loading device applied to a first device, including a transceiver module for obtaining a first loading manifest file; the first loading manifest file is associated with a preset security label configuration of a first attribute of the current running version of the operating system and a security label configuration of a first partition in which the operating system is running; the operating system includes a first partition and a second partition, the second partition corresponding to a preset security label configuration of a second attribute, the first partition corresponding to a preset security label configuration of a first attribute, and the preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified separately; a processing module is used to load security labels onto a first element to be configured in the first partition in which the operating system is running, according to the first loading manifest file.

[0060] In one possible implementation, the second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

[0061] In one possible implementation, the first attribute is a read / write attribute, and the first partition is the operating system's read / write partition.

[0062] In one possible implementation, the first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

[0063] In one possible implementation, the preset security label configuration of the first attribute of the currently running version of the operating system includes: a first target element and a security label of the first target element; the security label configuration of the first partition on which the operating system is running includes: a first element to be configured and a security label of the first element to be configured.

[0064] In one possible implementation, the first load manifest file is determined by comparing the preset security label configuration of the first attribute of the currently running version of the operating system with the security label configuration of the first partition on which the operating system is running; the first load manifest file includes: the preset security label configuration of the first attribute of the currently running version of the operating system when the first element to be configured is the same as the first target element and the security label of the first element to be configured is different from the security label of the first target element, and the preset security label configuration of the first attribute of the currently running version of the operating system when the first element to be configured is different from the first target element.

[0065] In one possible implementation, the preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately by a partition information file; the partition information file includes the attribute information of the target element, including the second attribute and the first attribute.

[0066] In one possible implementation, the transceiver module is further configured to, when the upgrade identifier indicates that the operating system is being booted for the first time after an upgrade, obtain a second load file manifest; the second load file is associated with the preset security label configuration of the first attribute of the current running version of the operating system and the preset security label configuration of the first attribute of the target version; the upgrade identifier is generated after the operating system upgrade is completed; the processing module is further configured to, according to the third load file manifest, load security labels onto the first partition where the operating system is running; the third load file is determined by merging the first load file manifest and the second load file manifest.

[0067] In one possible implementation, the preset security label configuration of the first attribute of the current running version of the operating system includes: a first target element and a security label of the first target element; the preset security label configuration of the first attribute of the target version includes a second target element and a security label of the second target element.

[0068] In one possible implementation, the second load manifest file is determined by comparing the preset security label configuration of the first attribute of the current running version of the operating system with the preset security label configuration of the first attribute of the target version; the second load manifest file includes: the preset security label configuration of the first attribute of the target version when the first target element and the second target element are inconsistent, and the preset security label configuration of the first attribute of the target version when the first target element and the second target element are consistent, but the security label of the first target element is inconsistent with the security label of the second target element.

[0069] In one possible implementation, if the second target element in the first load manifest file is the same as the second target element in the second load manifest file, and the security label of the second target element in the first load manifest file is different from the security label of the second target element in the second load manifest file, the third load manifest file includes the security label of the second target element in the second load manifest file, but does not include the security label of the second target element in the first load manifest file.

[0070] In one possible implementation, the upgrade identifier becomes invalid after the first boot following an operating system upgrade.

[0071] In one possible implementation, after the first partition where the operating system runs is loaded with a security label based on the third load file manifest, the processing module is also used to: clear the contents of the third load file manifest.

[0072] In one possible implementation, the transceiver module is further configured to obtain from the second device the second configurable element of the second partition on which the operating system is running, and the security label of the second configurable element.

[0073] In one possible implementation, the security label of the second element to be configured is associated with the preset security label configuration of the second attribute of the target version of the operating system and the second element to be configured of the second partition on which the operating system is running.

[0074] In one possible implementation, the security label of the second element to be configured in the second partition of the operating system is the security label of the corresponding third target element; the second element to be configured corresponds to the third target element; the third target element and its security label belong to the preset security label configuration of the second attribute of the target version.

[0075] In one possible implementation, the pre-configured security label of the second attribute of the target version passes the consistency check with the second configurable element of the second partition of the operating system.

[0076] In one possible implementation, if the consistency check between the preset security label configuration of the second attribute of the target version and the second configurable element of the second partition running the operating system fails, the result of the consistency check includes a fourth target element, which includes a third target element, and the fourth element is inconsistent with the second configurable element.

[0077] In one possible implementation, consistency checks are used to verify whether the third target element is consistent with the second element to be configured.

[0078] Fourthly, embodiments of this application provide a security label loading device applied to a second device, comprising: a processing module, configured to determine a security label for a second element to be configured in the second partition of the operating system based on a preset security label configuration of a second attribute of a target version of the operating system and a second element to be configured in the second partition of the operating system; the operating system includes a first partition and a second partition, the second partition corresponding to a preset security label configuration of the second attribute, the first partition corresponding to a preset security label configuration of the first attribute, and the preset security label configuration of the second attribute and the preset security label configuration of the first attribute being identified separately.

[0079] In one possible implementation, the second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

[0080] In one possible implementation, the first attribute is a read / write attribute, and the first partition is the operating system's read / write partition.

[0081] In one possible implementation, the first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

[0082] In one possible implementation, the processing module is further configured to perform a consistency check between the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition where the operating system is running; if the consistency check passes, the security label is loaded onto the second configurable element of the second partition where the operating system is running according to the preset security label configuration of the second attribute of the target version, so as to determine the security label of the second configurable element of the second partition where the operating system is running.

[0083] In one possible implementation, the apparatus further includes a transceiver module for sending a second configurable element of a second partition on which the operating system is running, and a security tag of the second configurable element, to the first device.

[0084] In one possible implementation, the preset security label configuration of the second attribute of the target version includes a third target element and the security label of the third target element.

[0085] In one possible implementation, the processing module is further configured to load the security label of the corresponding third target element onto the second element to be configured, so as to determine the second element to be configured and the security label of the second element to be configured in the second partition where the operating system is running.

[0086] In one possible implementation, consistency checks are used to verify whether the third target element is consistent with the second element to be configured.

[0087] In one possible implementation, the processing module is further configured to indicate the result of the consistency check to the user if the consistency check fails; the result of the consistency check includes a fourth target element, which includes a third target element, and the fourth element is inconsistent with the second element to be configured.

[0088] In one possible implementation, the device further includes a display module for displaying the results of the consistency check.

[0089] In one possible implementation, the preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately by a partition information file; the partition information file includes the attribute information of the target element, including the second attribute and the first attribute.

[0090] Fifthly, embodiments of this application provide a security tag loading device, including at least one processor and a memory, the memory being used to store computer-readable instructions, wherein when at least one processor reads the computer-readable instructions from the memory, the security tag loading device causes the security tag loading device to execute the method described in the first aspect or any possible implementation of the first aspect.

[0091] In a sixth aspect, embodiments of this application provide a security tag loading device, including at least one processor and a memory, the memory being used to store computer-readable instructions, wherein when at least one processor reads the computer-readable instructions from the memory, the security tag loading device causes the security tag loading device to perform the method described in the second aspect or any possible implementation thereof.

[0092] In a seventh aspect, embodiments of this application provide a computer-readable storage medium storing a computer program or instructions that, when executed on a computer, cause the computer to perform the method described in the first aspect or any possible implementation thereof; or to perform the method described in the second aspect or any possible implementation thereof.

[0093] Eighthly, embodiments of this application provide a computer program product including a computer program, which, when run on a computer, causes the computer to perform the method described in the first aspect or any possible implementation thereof; or, to perform the method described in the second aspect or any possible implementation thereof.

[0094] Ninthly, embodiments of this application provide a chip or chip system, the chip or chip system including at least one processor and a communication interface, the communication interface and at least one processor being interconnected via a line, the at least one processor being used to run a computer program or instructions to perform the method described in the first aspect or any possible implementation of the first aspect; or, to perform the method described in the second aspect or any possible implementation of the second aspect.

[0095] In one possible implementation, the chip or chip system described above in this application further includes at least one memory storing instructions. The memory can be an internal storage unit of the chip, such as a register or cache, or it can be a storage unit of the chip itself (e.g., read-only memory, random access memory, etc.).

[0096] In a tenth aspect, embodiments of this application provide a vehicle that includes a security tag loading device as described in the third aspect, or includes a first device that performs the functions described in the first aspect.

[0097] It should be understood that the third to tenth aspects of this application correspond to the technical solutions of the first and / or second aspects of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be repeated here. Attached Figure Description

[0098] Figure 1 is a schematic diagram of the partitioning of an operating system provided in an embodiment of this application;

[0099] Figure 2 is a flowchart of a security tag loading method provided in an embodiment of this application;

[0100] Figure 3 is a flowchart of another security label loading method provided in an embodiment of this application;

[0101] Figure 4 is a schematic diagram of a security tag loading method provided in an embodiment of this application;

[0102] Figure 5 is a schematic diagram of a mandatory access control configuration provided in an embodiment of this application;

[0103] Figure 6 is a schematic diagram of an operating system upgrade scenario provided by an embodiment of this application;

[0104] Figure 7 is a schematic diagram of another security tag loading method provided in the embodiments of this application;

[0105] Figure 8 is a schematic diagram of the software structure of a first device provided in an embodiment of this application;

[0106] Figure 9 is a flowchart of another security label loading method provided in an embodiment of this application;

[0107] Figure 10 is a schematic diagram of a process for obtaining a first loading manifest file according to an embodiment of this application;

[0108] Figure 11 is a schematic diagram of an operating system startup scenario provided by an embodiment of this application;

[0109] Figure 12 is a schematic diagram of a process for obtaining a second loading manifest file according to an embodiment of this application;

[0110] Figure 13 is a schematic diagram of a process for obtaining a third loading manifest file according to an embodiment of this application;

[0111] Figure 14 is a schematic diagram of a mandatory access control configuration compilation provided in an embodiment of this application;

[0112] Figure 15 is a schematic diagram of a consistency verification process provided in an embodiment of this application;

[0113] Figure 16 is a schematic diagram of an interface provided in an embodiment of this application;

[0114] Figure 17 is a flowchart of another security label loading method provided in an embodiment of this application;

[0115] Figure 18 is a flowchart of another security label loading method provided in an embodiment of this application;

[0116] Figure 19A is a flowchart of another security label loading method provided in an embodiment of this application;

[0117] Figure 19B is a flowchart of another security label loading method provided in an embodiment of this application;

[0118] Figure 20 is a structural schematic diagram of another security tag loading device provided in an embodiment of this application;

[0119] Figure 21 is a schematic diagram of another security tag loading device provided in an embodiment of this application;

[0120] Figure 22 is a schematic diagram of a chip system provided in an embodiment of this application. Detailed Implementation

[0121] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0122] In the embodiments of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0123] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple second messages refer to two or more second messages. The terms "system" and "network" are often used interchangeably in this document.

[0124] It should be understood that the terminology used in the descriptions of the various examples in this document is for the purpose of describing the specific examples only and is not intended to be limiting.

[0125] It should also be understood that the term "and / or" as used herein refers to and covers any and all possible combinations of one or more of the associated listed items. The term "and / or" describes an association between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " in this application generally indicates that the preceding and following related objects are in an "or" relationship.

[0126] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0127] It should be understood that the phrases "an embodiment," "an embodiment," and "a possible implementation" used throughout the specification mean that a specific feature, structure, or characteristic related to an embodiment or implementation is included in at least one embodiment of this application. Therefore, the phrases "in an embodiment," "an embodiment," or "a possible implementation" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0128] To facilitate understanding, the relevant terms and concepts involved in the embodiments of this application will be introduced below:

[0129] Mandatory access control (MAC):

[0130] MAC is an access control mechanism enforced by the operating system according to pre-defined security policies. Compared to discretionary access control (DAC), MAC provides more granular and stricter access control and can manage resource access based on complex security policies.

[0131] MAC (Configuration Access Control) can isolate the resource access behavior of various processes, ensuring that each process can only access resources it is explicitly authorized to access, and cannot arbitrarily access the resources of other processes. MAC can also implement the principle of least privilege, granting each process only the minimum privileges required to perform its function. In this way, the harm to the overall system caused by the failure or error of a single process can be reduced or eliminated.

[0132] When implementing MAC in an operating system, it is necessary to determine the subject, object, security context, and access policy of the operating system. The subject can refer to the visitor, which can be a process or service; the object can refer to the operating system resources accessed by the subject, such as configuration files, database files, device characters, or network sockets; the security context refers to the identity identifier of a specific object, which can be collectively referred to as a security label or tag, and can be used to describe the access control attributes of the subject and object. Each subject and object has an associated security context; the access policy refers to the set of rules governing the subject's access to the object, constraining the scope of the subject's access permissions to the object.

[0133] In some examples, when the operating system implements MAC, it needs to pre-configure a mandatory access control configuration. The mandatory access control configuration may include: subject pre-set security label configuration, object pre-set security label configuration, and subject-to-object access policy file. Among them, the subject pre-set security label configuration and the object pre-set security label configuration need to be loaded before the operating system process starts.

[0134] MAC addresses can be used to enhance operating system security. However, operating systems do not provide a mechanism for automatically loading security labels for subjects and objects. Developers need to use corresponding tools or interfaces to load security labels for subjects and objects. This security label loading process needs to be completed during the operating system startup process, which will have a certain impact on the operating system startup speed and the consumption of the central processing unit (CPU).

[0135] In some examples, as shown in Figure 1, the operating system can be divided into read-only partitions, write-only partitions, and read-write partitions according to read and write attributes. Read-only partitions have static attributes and can store some binary files and configuration files, etc. They can be refreshed as a whole when the operating system is upgraded. The security labels of files in read-only partitions can be set offline and the security labels of files in read-only partitions are loaded synchronously during the upgrade process.

[0136] Write-only partitions and read-write partitions have dynamic attributes and can store database files, log files, and directories consisting of multiple files. These files and directories are managed autonomously by the business processes. During operating system operation, the files and directories in write-only partitions and read-write partitions may change. For example, if file 1 is deleted and then recreated, the content of file 1 may not change, but the security label of file 1 may be lost or changed. Therefore, the files and directories in write-only partitions and read-write partitions are not refreshed with operating system upgrades. It is necessary to pre-configure the subject or object identities of the files and directories in write-only partitions and read-write partitions, and load the security labels of target files and directories through pre-configured security label settings before the operating system starts.

[0137] In summary, on platforms and operating systems with mandatory access control enabled, security labels for files and directories in read-only partitions can be set and applied in advance, while security labels for files and directories in read-write and write-only partitions need to be loaded and applied during the operating system boot process. As operating systems become more complex, and the number of files and directories in read-write and read-only partitions increases, the impact of loading the subject and object security labels for files and directories in read-write and read-only partitions on the overall operating system will become increasingly significant.

[0138] In related technologies, the read-only partition of the operating system loads security labels during operating system upgrades. Upon subsequent operating system startup, the files and directories in the read-only partition use the security labels loaded during the operating system upgrade.

[0139] The operating system loads security labels for write-only partitions and read-write partitions during operating system startup.

[0140] In some examples, the operating system can load security labels for files and directories on both write-only and read-write partitions at each boot. Alternatively, the operating system boots into first boot after an upgrade and first boot without an upgrade. The operating system can load security labels for files and directories on write-only and read-write partitions during the first boot after an upgrade, but not during the first boot without an upgrade.

[0141] In some examples, Figure 2(a) shows the process of automatically loading the subject security label and object security label in the read-only partition when the operating system is upgraded. Figure 2(b) shows the process of loading security labels for files and directories in the write-only partition and read-write partition each time the operating system starts.

[0142] As shown in Figure 2(a), developers can pre-configure security labels, which include subject security labels, object security labels, and access policies between subjects and objects in the operating system. Developers can create a root file system (rootfs), which includes the basic files and directory structure required for operating system startup and operation, located on a read-only partition. Then, security labels are loaded onto the root file system using the pre-configured security labels, and the pre-configured security labels are integrated into the root file system. The root file system is then integrated into the operating system software upgrade package. Subsequent operating system upgrades can be performed using the operating system software upgrade package, updating the root file system and completing the operating system upgrade. This automatically upgrades the root file system, completing the loading of subject and object security labels in the read-only partition of the operating system.

[0143] As shown in Figure 2(b), the operating system boots up and loads the pre-configured security label settings integrated in the root file system into the kernel security module. These pre-configured security label settings can be binary files. The operating system mounts the read-only partition, write-only partition, and read-write partition. Security labels are loaded onto the write-only partition and read-write partition using the pre-configured security label settings, and the security labels of files and directories within these partitions are updated. Finally, the business processes within the operating system are started, completing the operating system boot process.

[0144] However, this method loads security labels for all files and directories in both write-only and read-write partitions every time the operating system boots. When these partitions contain a large amount of data, multiple files and / or directories need to be loaded with security labels. Alternatively, when higher security levels are required, more granular protection of operating system resources is needed. The finer the granularity of the security label configuration for files and directories in write-only and read-write partitions, the more thorough the resource access isolation. However, this also means that more security label loading operations need to be performed during the boot process. This may lead to higher CPU load, slower operating system boot times, and a negative impact on user experience.

[0145] In some examples, Figure 3(a) shows the process of automatically loading the subject security label and object security label in the read-only partition during an operating system upgrade. Figure 3(b) shows the process of loading security labels for files and directories in the write-only partition and read-write partition during the first boot after an upgrade.

[0146] During operating system upgrades, the process of automatically loading the subject security label and object security label in the read-only partition along with the operating system upgrade is shown in Figure 2(a) above. The operating system can be upgraded using an operating system software upgrade package, which updates the root file system. After the operating system upgrade is complete, an upgrade flag file can be created to instruct the operating system to complete the upgrade.

[0147] As shown in Figure 3(b), the operating system boots and loads the pre-configured security label settings integrated in the root file system into the kernel security module. These pre-configured security label settings can be binary files. The operating system mounts the read-only partition, write-only partition, and read-write partition. The operating system can determine whether this boot is the first boot after an upgrade. If the operating system includes an upgrade flag file, it indicates that this is the first boot after an upgrade. If this is the first boot after an upgrade, the operating system loads security labels onto the write-only partition and read-write partition using the pre-configured security label settings, updating the security labels of files and directories in these partitions. The upgrade flag file is deleted, and then the business processes within the operating system are started, completing the operating system boot process. (The last sentence is a repetition of the previous one and can be omitted.)

[0148] However, this method does not load security labels on the write-only partition and read-write partition of the operating system when it is not the first time it is upgraded, which reduces the stability of the operating system. Furthermore, if the security labels of files and / or directories in the write-only partition and read-write partition are lost or modified, they cannot be recovered.

[0149] To address the aforementioned issues, this application proposes a security tag loading method. A first device can compare a preset security tag configuration for writable attributes with the security tag configuration of the writable partition in the operating system, determine a security tag loading list based on the differences, and load security tags onto files and / or targets in the writable partition according to the security tag loading list.

[0150] The preset security label configuration for writable attributes can include the preset security label configuration for write-only attributes and the preset security label configuration for read-write attributes.

[0151] Thus, in this embodiment, security labels are loaded onto files and / or directories in the writable partition each time the operating system starts, and only the files and / or directories with different security label configurations from the preset ones are loaded. This reduces CPU load, improves operating system startup speed, and allows the restoration of modified security labels in the operating system, thereby enhancing operating system security and improving user experience.

[0152] In some examples, the objects loaded by the security label in the operating system include files and / or targets, or the objects loaded by the security label in the operating system may also include others, such as processes, etc. This application embodiment does not impose specific limitations on this.

[0153] This application's embodiments use the example of a security label in an operating system loading objects including files and / or targets.

[0154] In some examples, embodiments of this application can be applied to a first device for deploying a runtime environment. The first device may include an operating system with a mandatory access control mechanism, which includes a read-only partition, a write-only partition, and a read-write partition.

[0155] In some examples, embodiments of this application can be applied to a system where a first device deploys a runtime environment and a second device deploys a development environment. The first device may include an operating system with a mandatory access control mechanism, which includes read-only partitions, write-only partitions, and read-write partitions. The second device may include a development platform for developing the operating system of the first device. Alternatively, the second device may also include a secondary development platform for further developing the operating system of the first device.

[0156] In some examples, the first device and the second device can be the same device, and an operating system can be developed and run.

[0157] In some examples, the first device and the second device may include one or more of a smart vehicle, a terminal device, and a server. Where the second platform can be located on either the first or second device, the first or second device may provide development tools and development resources.

[0158] Intelligent vehicles can be used to indicate electric vehicles, cars, trucks, motorcycles, buses, ships, airplanes, helicopters, recreational vehicles, amusement park vehicles, construction equipment, trams, or trains, etc. The embodiments of this application do not impose any special limitations on the specific form of intelligent vehicles.

[0159] Terminal devices can be used to instruct mobile phones, personal computers (PCs), tablets, laptops, desktop computers, computers with transceiver capabilities, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, wearable devices, or in-vehicle devices, etc. This application does not impose any particular limitation on the specific form of the terminal device.

[0160] The server can be a big data server, etc., and the specific form of the server is not particularly limited in the embodiments of this application.

[0161] In some examples, the second device may include devices such as mobile phones, personal computers, laptops, desktop computers, workstations, virtual machines, or servers.

[0162] Taking an example where the first device is a smart vehicle, terminal device, or server, and the second device is a personal computer, as shown in Figure 4, researchers can perform operating system development operations on the second device, determining the pre-configured security label settings and security label loading methods. The pre-configured security label settings are then sent to the first device in the runtime environment, allowing the first device to execute the security label loading method based on these settings.

[0163] In some examples, as shown in Figure 5, developers can pre-configure mandatory access control (MACC) settings on the second device. MACC settings include: pre-configured security labels for the subject and object, as well as a subject-to-object access policy file. The pre-configured security labels for the subject and object can be represented as "pre-configured security label settings." When creating the root file system, security labels are loaded onto the root file system using MACC settings, and the MACC settings are integrated into the root file system. The root file system is then integrated into the operating system software upgrade package. Subsequently, the second device can send the operating system software upgrade package to the first device, which then loads the security labels through the upgrade package.

[0164] In some examples, as shown in Figure 6, the second device can send the operating system software upgrade package to the first device via a wireless communication network, such as through over-the-air (OTA) technology.

[0165] Alternatively, the second device can send the operating system software upgrade package to the first device via a physical connection, such as via a universal serial bus (USB) or cable.

[0166] Alternatively, when the first device and the second device are the same device, the device's development environment can send the operating system software upgrade package to the device's runtime environment via inter-process communication (IPC). This application does not impose specific limitations on this aspect.

[0167] In some examples, embodiments of this application can also be applied to a secondary development environment. As shown in Figure 7, developer A can develop a product in a development environment to obtain a security tag loading device. This security tag loading device can deploy a second device, including a secondary development platform. The secondary development platform corresponds to a secondary development package, which may include software, software user manuals, software technical manuals, etc., from the secondary development platform. Developer A can sell the security tag loading device and the corresponding secondary development package to developer B. Developer B can then perform secondary development on the operating system of the first device within the secondary development environment, i.e., the security tag loading device, based on the secondary development package. For example, developer B can modify files and / or directories in the operating system, modifying one or more of the following: files, directories, pre-set security tags corresponding to files, and pre-set security tags corresponding to directories. This includes operations such as adding, deleting, changing, and querying one or more of these. Afterward, developer B can configure the corresponding modified mandatory access control configuration. The second device can send the modified mandatory access control configuration to the first device, and the first device implements security tag loading based on the mandatory access control configuration.

[0168] In some examples, the operating system can implement MAC (Macro-Access Module) through the security-enhanced Linux (SELinux) kernel security module to enhance its security. Alternatively, the operating system can also implement MAC through AppArmor to enhance its security. Or, the operating system can implement MAC through other modules to enhance its security. This application does not impose specific limitations on these methods.

[0169] This application uses the example of an operating system implementing MAC through the SELinux (security-enhanced Linux) kernel security module to illustrate the concept. Figure 8 is a schematic diagram of the software structure of a first device provided in this application embodiment.

[0170] As shown in Figure 8, the software system of the first device can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This embodiment uses a layered Android system as an example to illustrate the software structure of the first device.

[0171] A layered architecture divides software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the software framework of a first device may include an application layer, an application framework layer, system libraries, a runtime, a hardware abstraction layer (HAL), and a kernel layer.

[0172] The application layer can include a series of application packages. For example, application packages can include applications such as settings, calling, maps, navigation, Bluetooth, and music.

[0173] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications within the application layer. The application framework layer includes predefined functions. It may also include a series of system services. System services are modular components focused on specific functionalities. The functionality provided by the application framework API allows communication with system services to access the underlying hardware. For example, the application framework layer may include window managers, content providers, view systems, resource managers, and notification managers. Window managers are used to manage window programs.

[0174] The system library may include several functional modules. For example, a surface manager, a 3D graphics processing library (e.g., OpenGL ES), and a 2D graphics engine (e.g., SGL). The specific meaning and function of these modules can be found in relevant technical documentation and will not be elaborated upon here.

[0175] The system library may also include SELinux calling and compilation modules. These modules can be used to build various tools needed to compile SELinux security policies and security labels, such as providing libselinux library functions, a checkpolicy compiler (compiling policy.conf into a .cil file), and a secilc compiler (compiling the .cil file into binary). In some embodiments of this application, the SELinux calling and compilation modules can be used to call functions related to loading pre-defined security labels.

[0176] In some embodiments of this application, after the first device obtains the operating system upgrade package, it can trigger the SELinux call and compilation module to execute the relevant process of loading security labels. During the process of the first device triggering the SELinux call and compilation module to execute the relevant process of loading security labels for files and / or directories in the operating system (i.e., files and / or directories with changed security labels), the first device can call relevant functions (e.g., the restorecon function, the recursive function, etc.) through the SELinux call and compilation module to load security labels for files and / or directories in the operating system.

[0177] The Android runtime is responsible for system scheduling and management. The runtime includes the core libraries and the virtual machine. The core libraries consist of two parts: one part contains the functionalities that Java needs to call, and the other part comprises Android's core libraries. The application layer and application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0178] The kernel layer is the layer between hardware and software. It forms the foundation of the Android operating system. The kernel layer is responsible for hardware drivers, networking, power, system security, and memory management. As an intermediary between hardware and software, the kernel layer's role is to pass application requests to the hardware.

[0179] The kernel layer may include a SELinux security module. An SELinux security module is a module obtained by loading the SELinux security model into the kernel as a module. In some embodiments of this application, after the first device triggers SELinux calls and the compilation module executes the relevant processes for tag-based loading, the SELinux security module ultimately implements the security tag loading method.

[0180] The kernel layer may also include display drivers, audio drivers, and sensor drivers, etc. The specific functions of these drivers can be found in the relevant technical documents, which will not be elaborated here.

[0181] It should be noted that the software architecture diagram of the first device shown in Figure 8 of this application is only an example and does not limit the specific module division in different layers of the Android operating system. For details, please refer to the introduction of the Android operating system software architecture in conventional technology. In addition, the operating system update method provided in this application can also be implemented based on other operating systems, which will not be listed in detail in this application.

[0182] The software structure of the first device has been described above. The security tag loading method provided in this application embodiment will now be described in detail with reference to the accompanying drawings. In some examples, as shown in Figure 9, a flowchart of a security tag loading method provided in this application embodiment is illustrated.

[0183] It should be noted that this method is not limited to the specific order shown in Figure 9 and below. It should be understood that in other embodiments, the order of some steps in this method can be interchanged according to actual needs, or some steps can be omitted or deleted. The method includes the following steps:

[0184] S901, The first device obtains the first loading manifest file.

[0185] In some examples, the operating system may include a first partition and a second partition. The default security label configuration for the current running version of the operating system may include the default security label configuration for the first attribute and the default security label configuration for the second attribute of the current running version of the operating system. The default security label configuration for the first attribute and the default security label configuration for the second attribute of the current running version of the operating system are identified separately. The first partition corresponds to the default security label configuration for the first attribute of the current running version of the operating system, and the second partition corresponds to the default security label configuration for the second attribute of the current running version of the operating system.

[0186] The first load manifest file is associated with the default security label configuration of the first attribute of the operating system's current running version and the security label configuration of the first partition where the operating system is running.

[0187] The operating system includes a first partition and a second partition. The second partition corresponds to the preset security label configuration of the second attribute, and the first partition corresponds to the preset security label configuration of the first attribute. The preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified separately.

[0188] S902, the first device loads security tags for the first configurable element of the first partition where the operating system is running, based on the first load file list.

[0189] The elements to be configured can be used to indicate files and / or directories in the operating system that require security labels.

[0190] In this way, the first device only loads security labels for the first partition in the first loading manifest file, loading only a portion of the security labels instead of all the preset security labels, which reduces CPU load, improves operating system startup speed, and enhances user experience.

[0191] In some examples, the first partition can be a read / write partition of the operating system, the first attribute can be a read / write attribute, and the default security label configuration of the first attribute is the default security label configuration of the read / write attribute.

[0192] In some examples, the first partition can be a write-only partition of the operating system, the first attribute can be a write-only attribute, and the default security label configuration of the first attribute is the default security label configuration of the write-only attribute.

[0193] In some examples, the first partition can be a write-only partition or a read-write partition of the operating system, the first attribute can be a write-only attribute or a read-write attribute, and the default security label configuration of the first attribute can be the default security label configuration of the write-only attribute or the default security label configuration of the read-write attribute.

[0194] In some examples, the second partition can be a read-only partition of the operating system, the second attribute can be a read-only attribute, and the default security label configuration of the second attribute is the default security label configuration of the read-only attribute.

[0195] This application embodiment uses the example of a first partition being both a write-only partition and a read-write partition of the operating system, with the first attribute being both write-only and read-write attributes. The second partition is described as a read-only partition of the operating system, with the second attribute being read-only.

[0196] In some examples, the security label configuration for the first partition where the operating system runs includes: the first element to be configured and the security label of the first element to be configured.

[0197] The first element to be configured may include files and / or directories in the first partition of the operating system. The files and / or directories in the first partition may be divided into main files and / or directories and object files and / or directories in the first partition. The security labels of the first element to be configured include the security labels corresponding to the files and / or directories in the first partition.

[0198] For example, the first element to be configured may include file 1, file 2, and directory 3, wherein directory 3 may include file 3 and file 5. The security label of the first element to be configured may include: the security label corresponding to file 1 may be security label 1; the security label corresponding to file 2 may be security label 2; and the security label corresponding to directory 3 may be security label 4.

[0199] In some examples, the default security label configuration of the first attribute of the currently running version of the operating system may include a first target element and the security label of the first target element.

[0200] The first target element may include files and / or directories with a first attribute of the operating system. The files and / or directories with the first attribute may be divided into the subject files and / or directories of the first attribute and the object files and / or directories of the first attribute. The security label of the first target element includes preset security labels corresponding to the files and / or directories with the first attribute.

[0201] For example, the first target element may include file 1, file 2, file 6, and directory 3, wherein directory 3 may include file 3 and file 5. The security label of the first target element may include: the security label corresponding to file 1 may be security label 1; the security label corresponding to file 2 may be security label 2; the security label corresponding to directory 3 may be security label 3; and the security label corresponding to file 6 may be security label 6.

[0202] In some examples, as shown in Figure 10, before the operating system starts, the first device can determine the first load manifest file by comparing the preset security label configuration of the first attribute of the current running version of the operating system with the security label configuration of the first partition where the operating system is running.

[0203] The first load manifest file may include: when the first element to be configured is the same as the first target element, but the security label of the first element to be configured is different from the security label of the first target element, the default security label configuration of the first attribute of the current running version of the operating system; and when the first element to be configured is different from the first target element, the default security label configuration of the first attribute of the current running version of the operating system.

[0204] For example, the first load manifest file may include: directory 3 and security label 3 corresponding to directory 3; file 6 and security label 6 corresponding to file 6.

[0205] In S102 above, the first device can load security tags for the first configurable element of the first partition on which the operating system is running, based on the first load file list.

[0206] For example, the first device can load a security label for the first configurable element directory 3 of the first partition where the operating system is running, and the security label of directory 3 is loaded as security label 3.

[0207] In this way, when the operating system starts up, it loads the elements to be configured in the first list of loaded files with security labels instead of loading all security labels, which reduces CPU load, improves the operating system startup speed, and enhances the user experience.

[0208] Furthermore, as shown in Figure 11, when the first device encounters a situation where other personnel tamper with the security tag, the first device restores the security tag when the operating system starts by loading the first loading file list.

[0209] Alternatively, the R&D personnel can perform secondary development on the operating system of the first device using the second device. When the security label in the operating system of the first device changes, the first device can restore the security label when the operating system starts by loading the first loading file list, thus ensuring the security of the operating system.

[0210] In one example, during an operating system upgrade, the first device can also obtain a second load manifest file. As shown in Figure 12, the second load manifest file is associated with the default security label configuration of the first attribute of the currently running version of the operating system and the default security label configuration of the first attribute of the target version.

[0211] The default security label configuration for the first attribute of the target version can be the default security label configuration for the first attribute of the target upgrade version of the operating system.

[0212] The pre-configured security label configuration for the target operating system version can include pre-configured security label configurations for the first attribute and the second attribute of the target operating system version. These pre-configured security label configurations for the first and second attributes of the target operating system version are identified separately. The first partition corresponds to the pre-configured security label configuration for the first attribute of the target operating system version, and the second partition corresponds to the pre-configured security label configuration for the second attribute of the target operating system version.

[0213] In some examples, the default security label configuration of the first attribute of the target version may include: a second target element and the security label of the second target element.

[0214] The second target element may include files and / or directories with second attributes from the operating system. These files and / or directories can be divided into subject files and / or directories and object files and / or directories. The security labels of the second target element include preset security labels corresponding to the files and / or directories with second attributes.

[0215] For example, the second target element may include file 1, file 2, file 6, file 7, and directory 3, wherein directory 3 may include file 3 and file 5. The security label of the second target element may include: the security label corresponding to file 1 may be security label 1; the security label corresponding to file 2 may be security label 2; the security label corresponding to directory 3 may be security label 3; the security label corresponding to file 6 may be security label 8; and the security label corresponding to file 7 may be security label 7.

[0216] In some examples, as shown in Figure 12, an upgrade identifier can be generated after the operating system upgrade is complete. The upgrade identifier is used to indicate that the operating system upgrade is complete.

[0217] In some examples, the first device can determine the second load manifest file by comparing the default security label configuration of the first attribute of the currently running version of the operating system with the default security label configuration of the first attribute of the target version.

[0218] The second load manifest file may include: a preset security label configuration for the first attribute of the target version when the first target element and the second target element are inconsistent, and a preset security label configuration for the first attribute of the target version when the first target element and the second target element are consistent, but the security label of the first target element is inconsistent with the security label of the second target element.

[0219] For example, the second load manifest file may include: the security label corresponding to file 6 may be security label 8; file 7 and the security label 7 corresponding to file 7.

[0220] In one example, when the operating system is booting for the first time after an upgrade, it can load security labels based on a first and a second list of loadable files. This simultaneously considers changes in security label configurations before and after the upgrade, as well as changes before and after boot, thus improving the security and stability of the operating system and enhancing its performance.

[0221] In some examples, as shown in Figure 13, the first load manifest file and the second load manifest file can be merged to determine the third load file manifest.

[0222] During the merging process, if the second target element in the first load manifest file is the same as the second target element in the second load manifest file, but the security label of the second target element in the first load manifest file is different from the security label of the second target element in the second load manifest file, the security label of the second target element in the second load manifest file shall prevail. The third load manifest file includes: the security label of the second target element in the second load manifest file, but does not include the security label of the second target element in the first load manifest file.

[0223] For example, the security label corresponding to file 6 in the first load manifest file is security label 6, the security label corresponding to file 6 in the first load manifest file is security label 8, and the security label corresponding to file 6 in the third load file manifest is security label 6.

[0224] Therefore, the third list of loaded files may include: directory 3 and its corresponding security label 3; file 6 and its corresponding security label 8; file 7 and its corresponding security label 7.

[0225] In some examples, the operating system can determine whether the boot process is the first boot after an upgrade based on the upgrade identifier.

[0226] For example, the upgrade identifier can be an upgrade identifier file that becomes invalid after the first boot following an operating system upgrade, or it can be deleted after the first boot following an operating system upgrade.

[0227] In some examples, the default security label configuration of the first attribute of the current running version of the operating system and the default security label configuration of the second attribute of the current running version of the operating system can be identified separately in the second device.

[0228] The second device can use the partition information file to identify the preset security label configuration of the current running version of the operating system, and determine the preset security label configuration of the first attribute and the preset security label configuration of the second attribute of the current running version of the operating system.

[0229] The partition information file may include attribute information of elements such as files and / or directories in the operating system, including second attributes and first attributes.

[0230] In some examples, as shown in Figure 14, the mandatory access control configuration includes a pre-defined security label configuration file (file contexts source file), a partition information file, and a subject-to-object access policy file (type enforcement source file). Compiling the mandatory access control configuration yields the subject-to-object access policy file, the pre-defined security label configurations for the first attribute, and the pre-defined security label configurations for the second attribute. The pre-defined security label configurations for the first and second attributes include both the subject and the object, and the subject-to-object access policy file includes the access policy between the subject and the object. This compilation result can be presented as a compilation result file, which can be stored in a policy database (PolicyDB).

[0231] In some examples, developers can also manually identify the preset security labels configured for the current version of the operating system, or they can use other methods to identify the preset security labels configured for the current version of the operating system. This application does not impose specific limitations on this.

[0232] In some examples, when the operating system is upgraded, the default security label configuration of the second attribute of the target version can be checked for consistency with the second configurable element of the second partition on which the operating system is running, so that the second configurable element is not missed and the integrity and accuracy of the second configurable element are guaranteed.

[0233] The preset security label configuration of the second attribute of the target version includes a third target element and its security label. As shown in Figure 15, the second device can perform consistency checks on the second configurable element of the second partition where the operating system is running and the third target element of the second attribute of the target version of the operating system, and obtain the consistency check result. The second configurable element of the second partition where the operating system is running is an element in the root file system.

[0234] In some examples, consistency checks are used to verify whether a third target element of the target version is consistent with a second configurable element of the operating system. If the third target element is consistent with the second configurable element, the consistency check passes; if the third target element is inconsistent with the second configurable element, the consistency check fails.

[0235] In some examples, consistency checks are used to verify whether the number and content of the third target element in the target version are consistent with the number and content of the second configurable element in the operating system. If the number and content of the third target element are consistent with the second configurable element, the consistency check passes; if the number and / or content of the third target element are inconsistent with the second configurable element, the consistency check fails.

[0236] The result of the consistency check may include a fourth target element, which includes the third target element, and the fourth element is inconsistent with the second element to be configured.

[0237] In some examples, the consistency check result may also include the security label corresponding to the fourth target element.

[0238] For example, the second element to be configured may include: file A, file B, and file C. The preset security label configuration for the second attribute may include: file A and its corresponding security label a; file B and its corresponding security label b; file C and its corresponding security label c. Therefore, the third target element may include file A, file B, and file C.

[0239] If the number and content of the second element to be configured are the same as those of the third target element, the consistency check passes.

[0240] For another example, the second element to be configured may include file A, file B, and file C. The preset security label configuration for the second attribute may include: file A and its corresponding security label a; file B and its corresponding security label b; file C and its corresponding security label c; and file D and its corresponding security label d. Then the third target element may include file A, file B, file C, and file D.

[0241] If the number and content of the second target element and the third target element are different, the consistency check will fail. Specifically, the third target element includes file D, while the second target element does not include file D. Therefore, the consistency check result can include the fourth target element file D. Alternatively, the consistency check result can include the fourth target element file D and its corresponding security label d.

[0242] For another example, the second element to be configured may include file A, file B, and file C. The preset security label configuration of the second attribute may include: file A and its corresponding security label a; file B and its corresponding security label b; file M and its corresponding security label m. Then the third target element may include file A, file B, and file M.

[0243] If the content of the second element to be configured is different from that of the third target element, the consistency check fails. Here, the third target element includes file M, while the second element to be configured does not include file M. The result of the consistency check can include: the fourth target element file M. Alternatively, the result of the consistency check can include: the fourth target element file M and the security label m corresponding to the fourth target element file M.

[0244] In some examples, the security label of the second element to be configured is associated with the default security label configuration of the second attribute of the target version of the operating system and the second element to be configured of the second partition on which the operating system is running.

[0245] The second device can load security labels for the second element to be configured in the second partition where the operating system is running, based on the preset security label configuration of the second attribute of the target version of the operating system, so as to determine the security label of the second element to be configured.

[0246] If the consistency check passes, the second device can load the security label of the corresponding third target element onto the second element to be configured, in order to determine the security label of the second element to be configured. Thus, the security label of the second element to be configured in the second partition where the operating system is running is the security label of the corresponding third target element.

[0247] For example, the second element to be configured may include file A, file B, and file C. The preset security label configuration of the second attribute may include: file A and its corresponding security label a; file B and its corresponding security label b; and file C and its corresponding security label c.

[0248] The second device can load the corresponding third target element security tags: security tag a, security tag b, and security tag c for the second elements to be configured: file A, file B, and file C, respectively. Thus, it can be determined that the security tag of the second element to be configured, file A, is the security tag a of the third target element file A; the security tag of the second element to be configured, file B, is the security tag b of the third target element file B; and the security tag of the second element to be configured, file C, is the security tag c of the third target element file C.

[0249] In some examples, if the consistency check fails, the second device can indicate the result of the consistency check to the user.

[0250] The user can be a research and development personnel or a maintenance personnel, etc., and this application embodiment does not impose specific limitations on this. This application embodiment uses a research and development personnel as an example for description.

[0251] In some examples, the second device can remind developers of the consistency verification results through interface display or voice prompts.

[0252] For example, the result of the consistency check can include: the fourth target element file D and the security label d corresponding to the fourth target element file D.

[0253] For example, as shown in Figure 16, the display interface 161 of the second device includes the result of the consistency verification: file D and the security label d corresponding to file D.

[0254] In this way, developers can correct the second element to be configured based on the results of the consistency check, so that the second element to be configured is not omitted.

[0255] In summary, when the operating system starts up, it can load security tags for the first configurable element of the first partition on which the operating system runs, based on either the first or third load manifest file.

[0256] Figure 17 illustrates the security label loading process during operating system startup. During operating system startup, the security label loading device of the first device can parse either the first or third load manifest file to load security labels for the first configurable element of the first partition where the operating system is running. The first and third load manifest files can be obtained before the operating system starts.

[0257] In some examples, after the security label has been loaded, the contents of either the first or third manifest file can be cleared so that new content can be added to the third manifest file later. Alternatively, after the security label has been loaded, the first device can delete the third manifest file so that a new third manifest file can be obtained later, and the first device can load the security label based on the new third manifest file.

[0258] In some examples, as shown in Figure 18, there is a flowchart of a second device performing a consistency check on the second element to be configured in the second partition.

[0259] In some examples, developers can pre-configure mandatory access control settings in the second device. These settings may include pre-configured security label settings and subject-to-object access policy files. The second device can identify the pre-configured security label settings for the first attribute and the second attribute through a partition information file.

[0260] The second device can create a root file system located on the second partition of the operating system. The second device can then perform a consistency check between the second configurable element and the preset security label configuration of the second attribute on the second partition where the operating system is running, and obtain the consistency check result.

[0261] If the consistency check fails, the user is shown the result of the consistency check.

[0262] If the consistency check passes, the root file system is loaded with a security label using the pre-configured security label in the second attribute, and the pre-configured security label is integrated into the root file system. Subsequently, the second device can integrate the root file system into the operating system upgrade package and send the operating system upgrade package to the first device.

[0263] In some examples, the details of the method described in Figure 18 above can be found above, and will not be repeated here in the embodiments of this application.

[0264] In this way, performing consistency checks on the second element to be configured can ensure that no second element to be configured in the operating system is omitted, thus guaranteeing the security and accuracy of the operating system.

[0265] In some examples, as shown in Figure 19A, there is a flowchart of a first device receiving an operating system upgrade package from a second device and performing an operating system upgrade.

[0266] In some examples, after receiving an operating system upgrade package from a second device, the first device can perform an operating system upgrade. The default security label configuration of the first attribute of the currently running operating system version is compared with the default security label configuration of the first attribute of the target version to determine the second load manifest file. The second load manifest file can be temporarily stored in a cache.

[0267] The first device can update the original root file system in the operating system according to the root file system manager in the operating system upgrade package, so that the second partition security label of the operating system is loaded. After the operating system upgrade is completed, the first device can create an upgrade identifier and a second load manifest file.

[0268] In some examples, the details of the method described in Figure 19A above can be found above, and will not be repeated here in the embodiments of this application.

[0269] In this way, when the operating system of the first device is upgraded, a second loading manifest file can be generated so that a security label can be loaded on the first partition when the operating system starts.

[0270] In some examples, as shown in Figure 19B, there is a flowchart of the first device booting up its operating system.

[0271] Before the first device boots, it can generate a first load manifest file based on the preset security label configuration of the first attribute of the current running version of the operating system and the security label configuration of the first partition where the operating system is running. Afterwards, the first device can use the upgrade identifier to determine whether this boot is the first boot after an upgrade.

[0272] If the upgrade identifier indicates that this is the first boot after an upgrade, the first and second load manifest files can be merged to obtain a third load manifest file, and the upgrade identifier becomes invalid. The operating system boots, loads the root file system into the kernel security module, and mounts the first and second partitions of the operating system. Then, the first device can parse the third load manifest file and load security labels based on it. Specifically, based on the third load manifest file, security labels are loaded for the first configurable element of the first partition where the operating system is running. The upgrade identifier can be an upgrade identifier file that becomes invalid after the first boot after an operating system upgrade, or it can be deleted after the first boot after an operating system upgrade, thus rendering the upgrade identifier invalid.

[0273] After the security label is loaded, the first device can clear the contents of the third loading manifest file so that new content can be added to it later. Alternatively, after the security label is loaded, the first device can delete the third loading manifest file so that a new third loading manifest file can be obtained later, and the first device will load the security label based on the new third loading manifest file.

[0274] If the upgrade flag indicates that this boot is not the first boot after an upgrade, the operating system starts, loads the root file system to the kernel security module, and mounts the first and second partitions of the operating system. Then, the first device can parse the first load manifest file and load security labels according to it. Specifically, based on the first load manifest file, security labels are loaded for the first configurable element of the first partition where the operating system is running. If the upgrade flag is invalid, the upgrade flag indicates that this boot is not the first boot after an upgrade.

[0275] In this way, the operating system loads different manifest files in different scenarios and loads security tags according to the elements in the operating system based on the manifest file. Even with fewer security tags loaded, the requirement for security tag reset during operating system startup is met, which improves the performance of the operating system in loading security tags and enhances the security and stability of the operating system.

[0276] After the security label is loaded, the first device can clear the contents of the first loading manifest file so that new content can be added to it later. Alternatively, after the security label is loaded, the first device can delete the first loading manifest file so that a new first loading manifest file can be obtained later, and the first device will load the security label based on the new first loading manifest file.

[0277] Finally, the first device can start the business process and complete the operating system startup.

[0278] In some examples, the details of the method described in Figure 19B above can be found above, and will not be repeated here in the embodiments of this application.

[0279] In this way, the operating system only needs to load security tags for some files and / or directories to restore the security tags in the operating system, reducing CPU load, improving operating system startup speed, and enhancing user experience.

[0280] It should be understood that some operations in the processes of the above method embodiments may be optionally combined, and / or the order of some operations may be optionally changed. Furthermore, the execution order between the steps of each process is merely exemplary and does not constitute a limitation on the execution order between steps; other execution orders are also possible. It is not intended to indicate that the execution order is the only possible order in which these operations can be performed. Those skilled in the art will conceive of various ways to reorder the operations described herein. Additionally, it should be noted that process details relating to one embodiment herein are similarly applicable to other embodiments, or different embodiments may be combined.

[0281] Furthermore, some steps in the method embodiments can be equivalently replaced with other possible steps. Alternatively, some steps in the method embodiments may be optional and can be deleted in certain use cases. Or, other possible steps may be added to the method embodiments.

[0282] Furthermore, the above-described method embodiments can be implemented individually or in combination.

[0283] Figure 20 shows a schematic diagram of another security tag loading device provided in an embodiment of this application. The security tag loading device 2000 can be located in the first device and includes a transceiver module 2001 and a processing module 2002. The security tag loading device 2000 is used to execute the aforementioned security tag loading method, for example, to execute the security tag loading method in the first device shown in Figures 9, 18, and 19. Of course, the security tag loading device 2000 may also include other modules, or it may include even fewer modules. This application does not specifically limit the specific form and implementation of the security tag loading device.

[0284] The transceiver module 2001 is used to retrieve the first load manifest file; the first load manifest file is associated with the preset security label configuration of the first attribute of the current running version of the operating system and the security label configuration of the first partition on which the operating system is running; the operating system includes a first partition and a second partition, the second partition corresponds to the preset security label configuration of the second attribute, the first partition corresponds to the preset security label configuration of the first attribute, and the preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified separately.

[0285] Processing module 2002 is used to load security labels for the first configurable element of the first partition on which the operating system is running, based on the first list of loaded files.

[0286] The operation and / or function of each module in the security tag loading device 2000 are respectively to implement the corresponding process of the security tag loading method described in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional unit. For the sake of brevity, it will not be repeated here.

[0287] Optionally, the security tag loading device 2000 shown in FIG20 may further include a storage module (not shown in FIG20) storing programs or instructions. When the transceiver module 2001 and the processing module 2002 execute the program or instructions, the security tag loading device 2000 shown in FIG20 can perform the security tag loading method described in the above method embodiments. Optionally, the storage module may store a preset security tag configuration for a first attribute and a preset security tag configuration for a second attribute.

[0288] The technical effects of the security tag loading device 2000 shown in Figure 20 can be referred to the technical effects of the security tag loading method described in the above method embodiments, and will not be repeated here.

[0289] Figure 21 shows a schematic diagram of another security tag loading device provided in this application embodiment. The security tag loading device 2100 can be located in a second device and includes a processing module 2101. The security tag loading device 2100 may also include a transceiver module 2102 and a storage module 2103. The security tag loading device 2100 is used to execute the aforementioned security tag loading method, for example, to execute the security tag loading method in the first device shown in Figure 17. Of course, the security tag loading device 2100 may also include other modules, or it may include fewer modules. This application embodiment does not specifically limit the specific form and implementation of the security tag loading device.

[0290] Processing module 2101 is used to determine the security label of the second configurable element of the second partition of the operating system based on the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition of the operating system. The operating system includes a first partition and a second partition. The second partition corresponds to the preset security label configuration of the second attribute, and the first partition corresponds to the preset security label configuration of the first attribute. The preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately.

[0291] The transceiver module 2102 is used to send the second configurable element of the second partition on which the operating system is running and the security tag of the second configurable element to the first device.

[0292] Storage module 2103 is used to store the preset security label configuration of the second attribute of the target version of the operating system.

[0293] The operation and / or function of each module in the security tag loading device 2100 are respectively to implement the corresponding process of the security tag loading method described in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional unit. For the sake of brevity, it will not be repeated here.

[0294] The technical effects of the security tag loading device 2100 shown in Figure 21 can be referred to the technical effects of the security tag loading method described in the above method embodiments, and will not be repeated here.

[0295] This application also provides a chip system, as shown in FIG22, which includes at least one processor 221 and at least one interface circuit 222. The processor 221 and the interface circuit 222 are interconnected via lines. For example, the interface circuit 222 can be used to receive signals from other devices (e.g., the memory of the first device). As another example, the interface circuit 222 can be used to send signals to other devices (e.g., the processor 221). Exemplarily, the interface circuit 222 can read instructions stored in the memory and send the instructions to the processor 221. When the instructions are executed by the processor 221, the first device can perform the steps in the above embodiments. Of course, the chip system may also include other discrete devices, which are not specifically limited in this application.

[0296] This application also provides a computer storage medium that includes computer instructions. When the computer instructions are executed on the aforementioned device, the first device performs various functions or steps performed by the mobile phone in the above method embodiment.

[0297] This application also provides a computer program product that, when run on a computer, causes the computer to perform the various functions or steps performed by the mobile phone in the above method embodiments.

[0298] This application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, it implements the methods described above. The methods described in the above embodiments can be implemented wholly or partially by software, hardware, firmware, or any combination thereof. If implemented in software, the functionality can be stored as one or more instructions or code on or transmitted over the computer-readable medium. The computer-readable medium can include computer storage media and communication media, and can also include any medium that can transfer a computer program from one place to another. The storage medium can be any target medium accessible by a computer.

[0299] In one possible implementation, a computer-readable medium may include random access memory (RAM), read-only memory (ROM), compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage or other magnetic storage devices, or any other medium intended to carry or store required program code in the form of instructions or data structures, and accessible by a computer. Furthermore, any connection is appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disks and optical discs include optical discs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs optically reproduce data using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0300] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, the division of the above functional modules is only used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and module described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0301] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0302] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0303] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0304] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially or in other words, the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0305] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for loading security tags, characterized in that, Applied to the first device, including: Obtain the first load manifest file; the first load manifest file is associated with the preset security label configuration of the first attribute of the current running version of the operating system and the security label configuration of the first partition where the operating system is running; The operating system includes a first partition and a second partition. The second partition corresponds to the preset security label configuration of the second attribute, and the first partition corresponds to the preset security label configuration of the first attribute. The preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified separately. Based on the first list of loaded files, security tags are loaded for the first configurable element of the first partition where the operating system is running.

2. The method according to claim 1, characterized in that, The second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

3. The method according to claim 1 or 2, characterized in that, The first attribute is a read / write attribute, and the first partition is a read / write partition of the operating system.

4. The method according to claim 1 or 2, characterized in that, The first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

5. The method according to any one of claims 1-4, characterized in that, The preset security label configuration of the first attribute of the current running version of the operating system includes: a first target element and a security label of the first target element; The security label configuration of the first partition where the operating system runs includes: a first element to be configured and the security label of the first element to be configured.

6. The method according to claim 5, characterized in that, The first loading manifest file is determined by comparing the preset security label configuration of the first attribute of the currently running version of the operating system with the security label configuration of the first partition where the operating system is running; The first loading manifest file includes: a preset security label configuration for the first attribute of the current running version of the operating system when the first element to be configured is the same as the first target element and the security label of the first element to be configured is different from the security label of the first target element; and a preset security label configuration for the first attribute of the current running version of the operating system when the first element to be configured is different from the first target element.

7. The method according to any one of claims 1-6, characterized in that, The preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified by a partition information file respectively; the partition information file includes the attribute information of the target element, and the attribute information includes the second attribute and the first attribute.

8. The method according to any one of claims 1-7, characterized in that, The method further includes: If the upgrade identifier indicates that the operating system is being booted for the first time after an upgrade, a second load file list is obtained; the second load file is associated with the preset security label configuration of the first attribute of the current running version of the operating system and the preset security label configuration of the first attribute of the target version; the upgrade identifier is generated after the operating system upgrade is completed; According to the third load manifest, a security label is loaded onto the first partition where the operating system runs; the third load manifest file is determined by merging the first load manifest file and the second load manifest file.

9. The method according to claim 8, characterized in that, The preset security label configuration of the first attribute of the current running version of the operating system includes: a first target element and a security label of the first target element; the preset security label configuration of the first attribute of the target version includes a second target element and a security label of the second target element.

10. The method according to claim 9, characterized in that, The second loading manifest file is determined by comparing the preset security label configuration of the first attribute of the currently running version of the operating system with the preset security label configuration of the first attribute of the target version; The second loading manifest file includes: a preset security label configuration for the first attribute of the target version when the first target element and the second target element are inconsistent, and a preset security label configuration for the first attribute of the target version when the first target element and the second target element are consistent, and the security label of the first target element is inconsistent with the security label of the second target element.

11. The method according to claim 10, characterized in that, If the second target element in the first load manifest file is the same as the second target element in the second load manifest file, and the security label of the second target element in the first load manifest file is different from the security label of the second target element in the second load manifest file, then the third load manifest file includes the security label of the second target element in the second load manifest file, but does not include the security label of the second target element in the first load manifest file.

12. The method according to any one of claims 8-11, characterized in that, The upgrade identifier becomes invalid after the first boot of the upgraded operating system.

13. The method according to any one of claims 8-12, characterized in that, After loading security labels onto the first partition where the operating system runs based on the third load file list, the method further includes: Clear the contents of the third load manifest file.

14. The method according to any one of claims 1-13, characterized in that, include: Obtain the second configurable element and the security label of the second configurable element from the second device, which is the second partition on which the operating system is running.

15. The method according to claim 14, characterized in that, The security label of the second element to be configured is associated with the preset security label configuration of the second attribute of the target version of the operating system and the second element to be configured of the second partition where the operating system is running.

16. The method according to claim 14 or 15, characterized in that, The security label of the second element to be configured in the second partition of the operating system is the security label of the corresponding third target element; the second element to be configured corresponds to the third target element; the third target element and the security label of the third target element belong to the preset security label configuration of the second attribute of the target version.

17. The method according to claim 15 or 16, characterized in that, The pre-configured security label of the second attribute of the target version passes the consistency check with the second configurable element of the second partition of the operating system.

18. The method according to claim 17, characterized in that, If the consistency check between the preset security label configuration of the second attribute of the target version and the second configurable element of the second partition on which the operating system is running fails, the result of the consistency check includes a fourth target element, the fourth target element includes the third target element, and the fourth element is inconsistent with the second configurable element.

19. The method according to claim 17 or 18, characterized in that, The consistency check is used to verify whether the third target element is consistent with the second element to be configured.

20. A method for loading security tags, characterized in that, Applied to a second device, including: Based on the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition in which the operating system is running, determine the security label of the second configurable element of the second partition in which the operating system is running; The operating system includes a first partition and a second partition. The second partition corresponds to the preset security label configuration of the second attribute, and the first partition corresponds to the preset security label configuration of the first attribute. The preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately.

21. The method according to claim 20, characterized in that, The second attribute is a read-only attribute, and the second partition is a read-only partition of the operating system.

22. The method according to claim 20 or 21, characterized in that, The first attribute is a read / write attribute, and the first partition is a read / write partition of the operating system.

23. The method according to claim 20 or 21, characterized in that, The first attribute is a write-only attribute, and the first partition is a write-only partition of the operating system.

24. The method according to any one of claims 20-23, characterized in that, The step of determining the security label of the second configurable element of the second partition running the operating system, based on the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition running the operating system, includes: The preset security label configuration of the second attribute of the target version of the operating system is used to perform a consistency check with the second configurable element of the second partition on which the operating system is running; if the consistency check passes, the security label is loaded onto the second configurable element of the second partition on which the operating system is running according to the preset security label configuration of the second attribute of the target version, so as to determine the security label of the second configurable element of the second partition on which the operating system is running.

25. The method according to any one of claims 20-24, characterized in that, include: Send the second configurable element of the second partition on which the operating system is running, along with the security tag of the second configurable element, to the first device.

26. The method according to any one of claims 20-25, characterized in that, The preset security label configuration of the second attribute of the target version includes a third target element and the security label of the third target element.

27. The method according to claim 26, characterized in that, The step of loading security labels for the second configurable element of the second partition running the operating system based on the preset security label configuration of the second attribute of the target version, to determine the second configurable element of the second partition running the operating system and the security label of the second configurable element, includes: Load the security label of the corresponding third target element for the second element to be configured, and determine the second element to be configured and the security label of the second element to be configured for the second partition where the operating system is running.

28. The method according to claim 26 or 27, characterized in that, The consistency check is used to verify whether the third target element is consistent with the second element to be configured.

29. The method according to claim 28, characterized in that, include: If the consistency check fails, the user is informed of the result of the consistency check. The result of the consistency check includes a fourth target element, which includes the third target element, and the fourth element is inconsistent with the second element to be configured.

30. The method according to any one of claims 20-29, characterized in that, The preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified by a partition information file respectively; the partition information file includes the attribute information of the target element, and the attribute information includes the second attribute and the first attribute.

31. A security tag loading device, characterized in that, Applied to the first device, including: The transceiver module is used to obtain a first load manifest file; the first load manifest file is associated with the preset security label configuration of the first attribute of the current running version of the operating system and the security label configuration of the first partition in which the operating system runs; the operating system includes a first partition and a second partition, the second partition corresponds to the preset security label configuration of the second attribute, the first partition corresponds to the preset security label configuration of the first attribute, and the preset security label configuration of the first attribute and the preset security label configuration of the second attribute are identified separately; The processing module is used to load security tags for the first configurable element of the first partition on which the operating system runs, based on the first list of loaded files.

32. A security tag loading device, characterized in that, Applied to a second device, including: The processing module is configured to determine the security label of the second configurable element of the second partition on which the operating system is running, based on the preset security label configuration of the second attribute of the target version of the operating system and the second configurable element of the second partition on which the operating system is running; the operating system includes a first partition and a second partition, the second partition corresponds to the preset security label configuration of the second attribute, the first partition corresponds to the preset security label configuration of the first attribute, and the preset security label configuration of the second attribute and the preset security label configuration of the first attribute are identified separately.

33. A vehicle, characterized in that, It includes the security tag loading device as claimed in claim 31, or includes a first device that performs the method as claimed in any one of claims 1-19.

34. A security tag loading device, characterized in that, It includes at least one processor and a memory for storing computer-readable instructions, wherein when at least one processor reads the computer-readable instructions from the memory, it causes the security tag loading device to perform the method of any one of claims 1-19, or causes the security tag loading device to perform the method of any one of claims 20-30.

35. A computer-readable storage medium storing instructions, characterized in that, When the instructions are executed on a computer, they cause the computer to perform the method as claimed in any one of claims 1-19, or cause the computer to perform the method as claimed in any one of claims 20-30.

36. A computer program product, characterized in that, The computer program product includes: a computer program or instructions that, when executed on a computer, cause the computer to perform the method as claimed in any one of claims 1-19, or cause the computer to perform the method as claimed in any one of claims 20-30.