Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

40 results about "Integrity measurement" patented technology

Integrity is a concept of consistency of actions, values, methods, measures, principles, expectations, and outcomes. In ethics, integrity is regarded as the honesty and truthfulness or accuracy of one’s actions.

Mobile solid state disk data encryption storage method based on trusted computing module

The invention relates to the technical field of data security, in particular to a mobile solid state disk data encryption storage method based on a trusted computing module. According to the method, integrity measurement is carried out on an operating environment through a trusted computing module, and a trusted measurement value is generated; generating a session-level encryption key based on the trusted magnitude; encrypting data using the key and storing key metadata; during data reading, correlation verification is carried out to determine whether decryption is authorized or not; and baseline adjustment can be triggered according to the measurement deviation. According to the invention, the data security of the mobile storage device is improved, and an environment-aware dynamic key management mechanism is realized.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Method and device for constructing network security operating system, electronic equipment and storage medium

ActiveCN121887549AArtificial lifeSecuring communicationOperational systemTrusted computing base
The invention belongs to the field of network security, and relates to a method and a device for constructing a network security operating system, electronic equipment and a storage medium, and the method comprises the following steps: constructing an autonomously controllable improved microkernel infrastructure; based on the microkernel infrastructure, constructing a full-stack layered security control computing architecture base; constructing intelligent agent components, and deploying a multi-intelligent agent collaborative protection component system; integrating trusted computing and an integrity measurement verification system; performing dynamic adaptation and execution of multiple security policies; and a standardized safety evaluation and adaptive optimization closed loop is established. A trusted computing base is cut from a design source, so that the probability of occurrence of high-risk vulnerabilities is reduced; the real-time defense that the threat is changed and the strategy is changed is realized, and the blind area of the static strategy in resisting the unknown threat is made up; the malicious codes can be blocked before running, and the post passive situation that traditional security software only depends on a feature library for searching and killing is broken; and the contradiction between security capability solidification and threat dynamic evolution is fundamentally solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

A method for integrity measurement of a satellite-borne embedded system based on link symbol topology

This invention discloses a method for measuring the integrity of a spaceborne embedded system based on link symbol topology. In the static injection phase, a linker script is configured to inject symbols at critical memory segment boundaries, generating hierarchical hybrid fingerprints and redundantly persisting them to non-volatile storage. In the dynamic verification phase, a lightweight program is started before the operating system takes over, performing hierarchical dual-dimensional and SEU-resistant temporal redundancy verification, supporting multi-container dedicated isolation verification. In the linkage blocking phase, anomalies are forcibly blocked and primary / backup linkage is triggered, collecting eight types of fault contexts and supporting on-orbit updates. This invention solves the problems of traditional hash methods failing to detect layout anomalies and high time consumption, reducing complexity to O(K), achieving sub-millisecond-level measurement decoupled from image volume, adapting to spaceborne radiation-resistant, cloud-native, and redundancy scenarios, and meeting the high reliability requirements of aerospace.
Owner:北京星云越动科技有限公司

A large language model privacy inference method and system capable of verifying log-free behavior and output integrity

The application relates to the technical field of artificial intelligence and password security, and discloses a large language model privacy reasoning method and system capable of verifying no-log behavior and output integrity; the method first sends an encrypted question to the server by the client; the server loads a pre-compiled no-log reasoning program in a trusted execution environment, decrypts and reasons; the reasoning is completed, and zero is cleared; a joint hash value is obtained, a custom data field of a remote proof report is embedded, and a program integrity measurement value is obtained; finally, the response and the proof report are returned to the user. The user client compares the local joint hash value with the custom data in the proof, and verifies the program measurement value, so that it can be confirmed that the log function is not enabled in this reasoning, and the received model response is generated by the specified model for the question, and is not tampered with. The application first realizes double-verified guarantee of privacy and output credibility in large model services, and significantly improves the trust degree of the user for the AI system.
Owner:KOAL SOFTWARE CO LTD

Remote attestation method, apparatus, medium, electronic device, and program product

A remote attestation method, device, medium, electronic device and program product. The method comprises: loading a virtual machine image file of a first application, the virtual machine image file being used to deploy the first application in a first trusted execution environment, the virtual machine image file comprising a root file system, a joint file system and a kernel; starting the kernel and measuring the root file system to deploy the first application in the first trusted execution environment; measuring the kernel and a lower component of the kernel to obtain a first measurement value, and after the kernel is started, measuring the joint file system using an integrity measurement architecture in the kernel to obtain a second measurement value, so as to remotely attest the first application based on the first measurement value and the second measurement value. When remotely attesting the first application, the first measurement value and the second measurement value are generated based on the measurement results of the kernel and the lower component thereof and the joint file system above the kernel, so as to realize the measurement of the code and data at the application level.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD +1

An industrial mainboard security booting method based on hardware root of trust

PendingCN122640112APathPingRandom seed
The application relates to the technical field of mainboards, in particular to an industrial mainboard security starting method based on a hardware root of trust, which comprises the following steps: after the industrial mainboard is powered on and reset, a security control domain runs prior to a business processing domain, and a main processor is kept waiting for starting; the security control domain reads hardware root anchor credentials and an initial boot program, and sequentially performs integrity measurement and signature verification on the initial boot program and a later-stage boot program; after the verification passes, running key materials are derived based on a random seed, device private credentials and a later-stage boot program digest, a running private key is written into a restricted key area, and a running public key is written into a public storage area; when a boot update package exists, a firmware public key certificate, a boot image signature and a replacement identifier are verified, a boot image is loaded after the certificate is valid and the signature passes, starting proof information is generated, an access path is closed and the main processor is released; any verification failure enters a fault processing flow.
Owner:深圳市兴研科技有限公司

Firmware integrity measurement and remote certification method based on DSP chip and SM3 algorithm

The invention discloses a firmware integrity measurement and remote certification method based on a DSP chip and an SM3 algorithm, and the method comprises the following steps: a presetting stage: in a protected secure storage area of the DSP chip, presetting a reference measurement value Hbenchmark generated based on a trusted firmware mirror image, and a cryptographic key material for signature; in the dynamic measurement and proof generation stage, when verification is needed, the DSP chip executes the following operations: (a) obtaining a dynamically generated random number Non; (b) performing integrity measurement on the current firmware code to be verified, and generating a dynamic measurement value Hcurrent; the integrity measurement comprises the following steps of: performing SM3 hash calculation on measurement data related to the current firmware state by adopting a parallel hash calculation strategy; the measurement data at least comprises the random number Non and one or more pieces of measurement metadata obtained based on the current firmware code data. The firmware verification is safe and efficient, the adaptation of the Internet of Things is tamper-proof and anti-replay, and the Internet of Things is efficient, anti-attack and credible.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Container trusted measurement and verification method in confidential environment

The invention discloses a container trusted measurement and verification method in a confidential environment, and belongs to the technical field of information security. According to the method, a dual-system architecture in which calculation and protection components run in parallel is designed, TCMTPCM and vTPCM management modules and a trusted software base TSB are constructed and deployed in the protection components, protection and hardware trusted roots are provided for running containers in a confidential virtual machine in a confidential environment, and integrity measurement judgment of key content is carried out in the starting and running processes of the containers. Confidentiality, integrity and credibility of a user service container provided in the cloud service are realized. And finally, a dual verification mechanism for providing a service container is introduced, and a remote verification platform not only needs to verify the identity and integrity of a confidential virtual machine where the container is located, but also needs to verify the integrity of the container and the integrity of the container during operation based on the vTPCM in the virtual machine. The method can get rid of absolute dependence of a user on single hardware trust of a hardware trust provider, and integrity measurement and verification are carried out during container operation in a confidential environment.
Owner:BEIJING UNIV OF TECH

A file integrity detection method and device, electronic equipment and storage medium

ActiveCN121881416BDetect if it has been tampered with in a timely mannerFind out if it has been tampered withDigital data protectionFile systemObject file
Embodiments of the present application provide a file integrity detection method and device, electronic equipment and storage medium, and relate to the technical field of computer, the method comprises: the kernel state responds to the file information of the to-be-detected file transmitted from the target file node to the kernel state, calling the target process bound by the target file node to process the file information, obtaining the detection result of the integrity of the to-be-detected file; wherein, the target file node is mounted in the security file system in the kernel, and the target process is the process in the integrity measurement architecture (IMA) in the kernel for file integrity detection; the kernel state returns the detection result to the user state. Through the embodiments of the present application, the problem of IMA integrity detection not being timely can be solved.
Owner:NEW H3C TECH CO LTD

Heterogeneous fusion platform-oriented trusted computing method and system

The invention relates to a trusted computing method and system for a heterogeneous fusion platform, and the method comprises the steps: defining trusted middleware through software, firstly carrying out the unified abstraction of all computing units in the platform, constructing a platform identity summary, decomposing a computing task into trusted task objects containing expected behavior portraits, and carrying out the unified abstraction of all computing units in the platform; and the behavior indexes during operation of each unit are collected in real time through the virtual trusted agent, the behavior indexes are compared with the expected portrait to generate a consistency judgment result, and the behavior integrity measurement register is dynamically updated. When verification is needed, the system collects multiple layers of evidences such as platform identity, behavior measurement, hardware certification and accelerator declaration to form a structured certification set, and a hierarchical unified certification report is generated after platform key signature. And after analyzing the report, the remote verification party issues a fine-grained credible token to the verified platform by comparing the credible reference value with the evaluation behavior compliance.
Owner:BEIJING SECURITY UNION IT CO LTD +1

Self-verifying integrated circuit

The invention relates to a self-verifying integrated circuit. A technique includes making, by a self-verification engine of an integrated circuit, measurements on the integrated circuit to provide hardware integrity measurements. The technique includes generating, by a self-verification engine, an observed fingerprint of the integrated circuit based on hardware integrity measurements and firmware integrity measurements. The technique includes validating, by a self-validation engine, the integrated circuit based on the observed fingerprint.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

A container security execution method, device and storage medium

The application provides a container security execution method, device and storage medium, wherein the method comprises the following steps: establishing a main monitoring and a plurality of sub-monitorings based on an SGX, and managing a container through the main monitoring and the plurality of sub-monitorings; in response to the first start of a container system, performing integrity measurement on a structural file of the container system, calculating an integrity measurement value of the structural file of the container system, and saving the integrity measurement value as an integrity measurement base value of the container system to the main monitoring. The application solves the problem that containers in a same Network Namespace can access each other, solves the isolation problem between containers, limits the access ability of other containers to a runtime container by setting a container network whitelist, and prevents malicious attack behaviors of untrusted containers. The application solves the integrity and legality verification of a container runtime code segment and a stack function return address, and prevents problems such as tampering of the container runtime code segment and overflow of the stack function return address.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Apparatus, a method and a non-transitory machine-readable storage medium

It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to record an entry into a virtual integrity register. The entry is based on a measurement of a module. The module is a part of a confidential computing environment. The machine-readable instructions further include instructions to load the module into a memory. The memory is accessible by the confidential computing environment. The machine-readable instructions further include instructions to record an entry of a log. The log comprises a load history. The entry comprises information about the loading of the module. The machine-readable instructions further include instructions to record an entry into an integrity measurement register. The entry being based on the recorded virtual integrity register entry.
Owner:XING BIN +2

Security encryption and privacy protection method for online learning data in credential environment

The invention belongs to the technical field of information security, and discloses an online learning data security encryption and privacy protection method in a credential environment. Comprising the steps of detecting underlying hardware features of an equipment end through a micro-architecture probe, and loading a target national cryptographic algorithm library adaptive to a current hardware architecture based on a detection result; generating an integrity measurement value of the equipment based on the feature information of the target national cryptographic algorithm library, taking the integrity measurement value as a key generation factor, generating an equipment private key, and negotiating with a platform server by using the equipment private key to generate a session key; calling the target national secret algorithm library by taking the session key as a parameter, performing encryption protection on video data in the online learning data, and uploading the encrypted video data to a platform server; and efficient and safe online learning data encryption and privacy protection in a credential environment are realized.
Owner:SHANGHAI INFORMATION IND COMM SERVICE CO LTD TRAINING CENT

A method and apparatus for integrity measurement

The application relates to the field of network security, in particular to an integrity measurement method and an integrity measurement device. The method comprises the following steps: a first measurement module performs integrity measurement on a second measurement module to obtain a first measurement result. Herein, the credibility of the first measurement module is higher than that of the second measurement module. The first measurement module receives a second measurement result sent by the second measurement module. The second measurement result is obtained by the second measurement module performing integrity measurement on an object to be measured. The first measurement module sends measurement result information to a proof module. The measurement result information is determined by the first measurement result and the second measurement result. The proof module determines whether the object to be measured passes the integrity verification according to the measurement result information. The method can improve the accuracy and reliability of the integrity measurement.
Owner:HUAWEI TECH CO LTD

RAID card and TPM chip collaborative system trusted startup method

The invention relates to the technical field of computer system security, and particularly discloses an RAID (redundant array of independent disks) card and TPM (trusted platform module) chip collaborative system trusted startup method, which comprises the following steps: S1, after a system is powered on, starting by using a TPM chip as a trusted root, and executing integrity measurement to establish a trusted startup chain; s2, after BIOS verification is passed and before a bootLoader is loaded, the BIOS initiates integrity measurement and verification of the RAID card, and the measurement and verification of the RAID card at least comprise verification of firmware of the RAID card and feature values of a system hard disk connected with the firmware; s3, only after verification of the RAID card is passed, the system loads and executes subsequent BootLoader and an operating system kernel from a system disk on the RAID card, and starting is completed; s4, during normal operation of the system, the TPM chip performs periodic or triggered dynamic measurement on the RAID card and the system disk thereof through the system management bus, and executes a security processing strategy when the measurement is abnormal; and the trust chain is expanded to the storage subsystem, so that comprehensive security protection is realized.
Owner:CHENGDU HUARUI SHUXIN TECHNOLOGY CO LTD

Trusted execution environment running state integrity measurement method facing TrustZone block chain node

The invention discloses a TrustZone block chain node-oriented trusted execution environment running state integrity measurement method, which relates to the field of computer technology and information security, and is composed of a strategy management module, an integrity measurement module, an evaluation module and a security log construction module. According to the method, the kernel, the static component, the trusted application and the system call in the trusted execution environment of the block chain node equipment can be measured, evaluated and recorded, and a complete log of the component and the event which influence the integrity during operation in the trusted execution environment is formed. The method is used for solving the problem that the integrity of the existing ARM TrustZone block chain node equipment is difficult to ensure when the equipment runs in the trusted execution environment, so that the node is trusted in the whole life cycle, and the integrity measurement of the running state of the TrustZone block chain node in the trusted execution environment is safely and efficiently realized.
Owner:BEIJING JIAOTONG UNIV

Data protection method and apparatus, and device

A data protection method and apparatus, and a device. A data storage apparatus provides a confidential storage service, wherein the service is a storage service having better security, and the service is designed to authenticate data access and enforce isolation to prevent data from unauthorized operations such as reading, tampering, or deletion. The service is further responsible for persistently storing confidential data, maintaining data integrity, and performing identity mapping for confidential computing tasks on a data access apparatus. The data storage apparatus obtains a first integrity measurement report, wherein the first integrity measurement report indicates a hardware environment and / or a software environment of the data access apparatus. Upon successfully verifying the data access apparatus on the basis of the first integrity measurement report, the data storage apparatus receives and processes a data access request sent by the data access apparatus. Achieving verification by means of the first integrity measurement report can ensure that data is processed in a relatively secure environment upon transmission to the data access apparatus, thereby effectively ensuring data security.
Owner:HUAWEI TECH CO LTD

DEVICE, METHOD AND NON-TRANSITORIAL MACHINE-READY STORAGE MEDIUM

A system is provided that includes interface switching logic, machine-readable instructions, and processing switching logic for executing the machine-readable instructions. The machine-readable instructions include instructions for recording an entry in a virtual integrity register. The entry is based on a measurement of a module. The module is part of a confidential computing environment. The machine-readable instructions also include instructions for loading the module into memory. The confidential computing environment can access this memory. Furthermore, the machine-readable instructions include instructions for recording an entry in a log. The log contains a load history. The entry includes information about the module's loading. Finally, the machine-readable instructions include instructions for recording an entry in an integrity measurement register.The entry is based on the recorded entry in the virtual integrity register.
Owner:INTEL CORP

Reporting integrity measurement error distribution groups

Reporting integrity measurement error distribution groups is provided. An apparatus may include at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to communicate, with a network device, information that may include one or more integrity distribution groups (IDGs) and corresponding distribution parameters. The apparatus may further perform positioning measurements for positioning integrity and determine one of the one or more IDGs based on at least one of the positioning measurements. A report is transmitted to the network device that may include at least one of the positioning measurements or an identifier of the determined IDG.
Owner:NOKIA TECHNOLOGIES OY

Photovoltaic data security assurance method, system and device fusing trusted computing and block chain, and medium

The invention discloses a photovoltaic data security guarantee method and system fusing trusted computing and a block chain, equipment and a medium. The method comprises the following steps: performing integrity measurement on photovoltaic acquisition equipment through a trusted measurement mechanism to generate an equipment measurement log; when the equipment credibility verification result is passed, encrypting photovoltaic data acquired by the photovoltaic acquisition equipment in the credible execution environment and generating a data abstract, and signing the data abstract through the credible platform module to form an encrypted data packet; extracting voucher information from the encrypted data packet, writing the voucher information into the block chain after the voucher information passes the verification of the smart contract to obtain an evidence storage receipt, and establishing an encrypted transmission channel after the identity authentication is passed; and transmitting the encrypted data packet through the encrypted transmission channel. The problems that in an existing data security guarantee method, integrity verification of collection equipment is not comprehensive, data processing lacks credible protection, identity authentication reliability is insufficient, transmission log traceability is poor, and stored data is prone to being tampered and difficult to recover are solved.
Owner:GUIZHOU POWER GRID CO LTD

File integrity detection method and device, electronic equipment and storage medium

The embodiment of the invention provides a file integrity detection method and device, electronic equipment and a storage medium, and relates to the technical field of computers.The method comprises the steps that a kernel mode responds to file information, obtained from a target file node, of a to-be-detected file transmitted from a user mode to the kernel mode; calling a target process bound with the target file node to process the file information to obtain a detection result of the integrity of the to-be-detected file; wherein the target file node is mounted in a security file system in a kernel, and the target process is a process of an integrity measurement architecture IMA in the kernel for carrying out file integrity detection; and the kernel mode returns a detection result to the user mode. According to the embodiment of the invention, the problem that IMA integrity detection is not timely can be solved.
Owner:NEW H3C TECH CO LTD

A network security protection architecture, a communication method and device, and a communication equipment

The embodiment of the application discloses a network security protection architecture, a communication method and device, and a communication equipment. The network security protection architecture comprises a first processing layer containing physical equipment, a second processing layer containing various virtualized network functions and a third processing layer; the first processing layer further comprises a security component for integrity measurement of the physical equipment, and the integrity measurement result is sent to the third processing layer; each virtualized network function in the second processing layer is used for anomaly detection, and the anomaly detection result is sent to the third processing layer; the third processing layer comprises a security management center for analyzing the integrity measurement result sent by the first processing layer and / or the anomaly detection result sent by the second processing layer, and determining a processing strategy according to the analysis result.
Owner:CHINA MOBILE COMM LTD RES INST +1

Trusted computing method and system for heterogeneous fusion platform

The application relates to a trusted computing method and system for a heterogeneous fusion platform, which comprises the following steps: firstly, all computing units in the platform are uniformly abstracted and a platform identity profile is constructed through software-defined trusted middleware; meanwhile, a computing task is decomposed into a trusted task object containing an expected behavior portrait; runtime behavior indexes of each unit are collected in real time through a virtual trusted agent; a consistency judgment result is generated by comparing the indexes with the expected portrait; and a behavior integrity measurement register is dynamically updated. When verification is needed, the system collects multi-layered evidences such as platform identity, behavior measurement, hardware proof and accelerator declaration, forms a structured proof set, generates a layered unified proof report after signing by using a platform key, and issues a fine-grained trusted token to the platform that passes the verification after a remote verifier analyzes the report, compares trusted reference values and evaluates behavior compliance.
Owner:BEIJING SECURITY UNION IT CO LTD +1

Dcs controller security startup and whole-process authentication method based on trusted computing

This invention provides a method for secure startup and end-to-end authentication of DCS controllers based on trusted computing, relating to the field of industrial control system security. The method includes performing layer-by-layer integrity measurements on the controller's startup firmware and software components to generate a set of hierarchical measurement values, and periodically performing memory checks during operation to generate runtime measurement values. Deviation measurements are then calculated and encapsulated as bi-state credentials. Simultaneously, relevant measurement values ​​are linked by a timestamp-based chained hash to generate an evidence chain. During inter-controller communication, credentials and evidence chains are exchanged. By calculating negotiated measurements and adaptive thresholds, resource allocation ratios are dynamically determined, and processor time slices and memory space are allocated to and executed for peer control commands. This invention achieves dynamic trusted authentication and resource isolation throughout the entire lifecycle of the controller from startup to operation, improving the overall security of the DCS system.
Owner:GUANGDONG DATANG INT CHAOZHOU POWER GENERATION CO LTD

Data protection method, device and equipment

A data protection method, device and equipment, in the present application, a data storage device provides a confidential storage service, the service is a storage service with better security, and the service authenticates and isolates data access to prevent data from unexpected operations such as reading, tampering, deleting and the like. The service is also responsible for persistently storing confidential data, maintaining data integrity and carrying out identity mapping on confidential computing tasks on the data access device. The data storage device obtains a first integrity metric report indicating a hardware environment and / or a software environment of the data access device. And the data storage device receives and processes the data access request sent by the data access device after the data access device passes verification based on the first integrity measurement report. Verification is realized through the first integrity measurement report, so that the data can be ensured to be processed in a relatively safe environment after being transmitted to the data access device, and the data security is effectively ensured.
Owner:HUAWEI TECH CO LTD

System and method for secure remote computing with enhanced isolation and access control

A system and method for providing a remote user with verifiable proofs of a secure computing environment. The system comprises a secure execution environment, an attestation manager, and an attestation reporting interface. The attestation manager generates verifiable proofs regarding the integrity of the execution environment, the software running within the environment, and the effectiveness of access 5 control measures. These proofs are provided to the remote user via the attestation reporting interface, enabling them to independently verify the security of the environment. The method involves establishing a secure execution environment, monitoring system integrity, implementing access controls, and generating attestation reports. By combining trusted execution environments, integrity measurement architectures, and access control mechanisms, the invention provides a robust solution for securing remote computing, enabling 10 users to confidently entrust sensitive data and applications to remote infrastructure.
Owner:MODELYO TECHNOLOGIES LTD

Mobile solid state disk data encryption storage method based on trusted computing module

The application relates to the technical field of data security, in particular to a mobile solid state disk data encryption storage method based on a trusted computing module. The method carries out integrity measurement on a running environment through the trusted computing module to generate a trusted measurement value; generates a session-level encryption key based on the trusted measurement value; encrypts data by using the key and stores key metadata; carries out association verification when data is read to decide whether to authorize decryption; and can trigger baseline adjustment according to measurement deviation. The application improves the data security of a mobile storage device and realizes an environment-aware dynamic key management mechanism.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Java program integrity measurement and start control method and device based on JavaAgent

The invention discloses a Java program integrity measurement and start control method and device based on JavaAgent, and the method comprises the steps: setting an administrator password, an initialization path of a white list and an environment variable by using a configuration management module, scanning a Java program in the initialization path by using an initialization module after the setting is completed, obtaining an absolute path of a Java program file, and starting the Java program file according to the absolute path; calling an algorithm interface to calculate a hash value of a byte code corresponding to the Java program, and recording the hash value as an expected value and an absolute path into a white list file one by one; and starting the measurement module, loading data in the white list file into a memory, generating a white list cache table, starting an integrity measurement function and starting a control function. According to the method and the device, integrity measurement and start control of the Java program can be realized, and the protection effects of security enhancement, practicability and easiness in use are achieved.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

TEE-based video monitoring fire reasoning model tamper-proofing method

The invention discloses a TEE-based video monitoring fire reasoning model tamper-proofing method, and aims to solve the core problem that a fire reasoning model deployed by an edge camera is easily tampered to cause function failure, a three-layer protection system of'hardware-level trusted foundation + full life cycle model protection + output data security guarantee 'is constructed, and the tamper-proofing effect of a video monitoring fire reasoning model is improved. According to the method, the tampering risk of the fire inference model is accurately resisted, the credibility of model operation is remarkably improved, and the method is specifically embodied in the following three aspects: (1) depending on a static and dynamic combination integrity measurement mechanism, a model tampering path is blocked from the source, and the functional integrity of the fire inference model is guaranteed; and (2) through hierarchical data stream protection, the credibility of a fire reasoning result is guaranteed, and the decision value of the model is prevented from being damaged by tampering output data. And (3) safety and performance collaboration are optimized, the fire reasoning model is ensured to adapt to edge equipment, and credibility and real-time performance are both considered.
Owner:XINJIANG UNIVERSITY