Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

245 results about "Trusted Computing" patented technology

Trusted Computing (TC) is a technology developed and promoted by the Trusted Computing Group. The term is taken from the field of trusted systems and has a specialized meaning. With Trusted Computing, the computer will consistently behave in expected ways, and those behaviors will be enforced by computer hardware and software. Enforcing this behavior is achieved by loading the hardware with a unique encryption key inaccessible to the rest of the system.

Block chain technology-based review data information security tamper-proofing method

The invention discloses a block chain technology-based review data information security tamper-proofing method, and relates to the technical field of information security, the tamper-proofing method comprises the following steps: a data encryption storage step, a data evidence storage step, a trusted computing step and a data verification step, when a computing request is received, the trusted computing step is executed, and the trusted computing step is executed; whether the identity of a requester conforms to the access control strategy is verified through the smart contract, after verification is passed, the smart contract generates a calculation task event, the oracle monitors and captures the event, then a calculation task is transmitted to the trusted execution environment, ciphertext data is obtained in the trusted execution environment and decrypted, and the calculation task is sent to the target server. The method has the advantages that the balance of data privacy protection and integrity verification is realized through a hierarchical architecture combining on-chain evidence storage and off-chain encrypted storage, sensitive review data is stored in an off-chain database in an encrypted form, the security of the review data is improved, the security of the review data is improved, and the security of the review data is improved. Only data fingerprints are recorded on the block chain, data privacy is protected, and data integrity can be verified through the block chain.
Owner:HEFEI FANKE NETWORK TECH CO LTD

Sandbox type trusted data space construction method and equipment based on trusted verification architecture

PendingCN121637484ADigital data protectionPlatform integrity maintainanceTrusted ComputingDeterministic finite automaton
The invention discloses a sandbox type trusted data space construction method and equipment based on a trusted verification architecture, belongs to the technical field of data security circulation and trusted computing, and aims to overcome the defects that a traditional sandbox behavior is unknowable and untrusted and a strategy is rigid. The method comprises the following steps of: starting a sandbox in a hardware trusted execution environment and generating a task unique context identifier; intercepting system call by a monitoring agent; generating a chained operation certificate containing preorder certificate hash; compiling an advanced security policy into a deterministic finite automaton executable policy set; and the auditing unit is used for generating a decision instruction in an illegal scale, storing the chain anchor point to the non-tampering system, forcibly executing decision and generating a Merkel tree evidence. The equipment correspondingly comprises a sandbox management module, a behavior monitoring module, a strategy compiling module, a verification judgment module and an auditing execution module. The full-flow transparent tracing of the operation in the sandbox is realized, the strategy dynamic adaptation is supported, and the problem that a traditional sandbox monitoring log is easy to counterfeit and difficult to verify is solved.
Owner:姚远

Server security authentication system based on block chain trusted computing

The invention relates to the field of network and information security, and discloses a server security authentication system based on block chain trusted computing. Comprising a block chain network, an intelligent contract module, an authentication service module, a verification node and a to-be-authenticated server. The intelligent contract module records a registration index, a certification public key, a policy version number, a baseline commitment value and a revocation state. The authentication service module generates a challenge parameter and a challenge value based on the block height and the block hash digest. The trusted agent module collects a measurement abstract and forms a certification packet, and the trusted root module derives a staging certification key in a protected environment and signs the certification packet. And the verification node reads the data on the chain to complete signature verification, challenge value re-calculation, window verification and compliance proof verification, and generates an authentication bill containing an effective height range for resource access judgment after passing the verification.
Owner:EASY POINT GEEK (BEIJING) TECHNOLOGY CO LTD

PLC behavior measurement method, device and equipment based on trusted 3.0 and national cryptographic algorithms

The invention discloses a PLC behavior measurement method, device and equipment based on trusted 3.0 and national cryptographic algorithms, and relates to the field of safety control in an industrial control system.The method comprises the steps that a hardware trust root module installed on a PLC in advance is used for conducting trusted verification on the PLC during starting, and the module is constructed based on the trusted computing 3.0 standard; after verification succeeds, a behavior feature vector of the PLC operation state is obtained based on trusted computing 3.0, wherein the vector comprises at least one of an integrity verification parameter, a resource consumption parameter, an operation parameter and an associated parameter; generating behavior measurement data based on trusted computing 3.0, and measuring a vector through an Euclidean distance algorithm in combination with behavior baseline data; comparing the measurement result with a preset Euclidean distance threshold value, encrypting the measurement result by adopting a domestic key algorithm, and transmitting a comparison result to a security management platform; according to the method, trusted computing 3.0 (TC3.0) and the national cryptographic algorithm are combined, accurate behavior measurement is carried out on the operation state, and the equipment safety and the attack resistance can be enhanced.
Owner:NINGBO HOLLYSHI INFORMATION SECURITY RES INST CO LTD

Emergency rescue integrated data security protection method and system based on block chain

The invention discloses an emergency rescue integrated data security protection method based on a block chain, and belongs to the technical field of data security protection, and the method comprises the following steps: constructing an end-side cloud cooperative trusted computing architecture, and establishing a trust chain transmission mechanism from a terminal to an edge node through a physical trusted root; a dynamic multi-dimensional credibility measurement model is adopted, the static credibility, the behavior credibility and the collaborative credibility of the equipment are comprehensively evaluated, and the real-time credibility of the equipment is generated in combination with environmental factors; implementing credibility verification based on the behavior measurement index; cross-domain data sharing auditing is realized by using a block chain smart contract, and the full-life-cycle security of data is ensured through a fragmented storage strategy and a self-destruction key design. According to the method, the problems of insufficient security authentication, dynamic trust evaluation and data cross-domain sharing auditing of the multi-source heterogeneous equipment in emergency rescue are solved.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

Industrial project cross-department collaborative approval and supervision system based on trusted computing

The invention provides an industrial project cross-department collaborative approval and supervision system based on trusted computing, and relates to the technical field of cross-department processing, and the system comprises an extraction module which is used for triggering an intelligent contract deployed on an alliance chain based on an on-chain evidence storage record, generating an approval event, and sending the approval event to a server; according to the data integrity, the process time sequence and the operation behavior characteristics in the approval process event, each behavior characteristic is quantified into a risk index corresponding to each dimension through a preset risk model, and a set of the risk indexes of each dimension forms a multi-dimensional vector; through on-chain credible evidence storage, multi-dimensional risk measurement, dynamic credit evaluation and closed-loop regulation and control, precision, credibility and dynamic optimization of industrial project cross-department collaborative approval and supervision are realized, approval efficiency and supervision efficiency are improved, and scientificity and safety of collaborative management and control are guaranteed.
Owner:FUZHOU PLANNING DESIGN & RES INST

Data management method and system for trusted data delivery platform

The invention discloses a data management method and system for a data credible delivery platform. Access is realized through symmetric encryption of source data, and credible right confirmation is realized by relying on identities of owners and users of alliance chain evidence storage, source data hash and authorization rules; adding a timestamp to the encrypted data stream verified by the certificate to form a traceability mark, and encrypting or desensitizing privacy data; the trusted computing is provided with three modes: a local mode executes an algorithm in an ownership party isolation environment and records a log on a chain, a third-party mode constructs a trusted sandbox based on TEE, executes computing and links log hash after remote certification, and an algorithm privacy mode realizes cooperative computing through a Shamir secret sharing splitting algorithm in combination with MPC, a confusion circuit and zero-knowledge certification; and the result delivery adopts public key encryption, a decryption key is issued after the receipt of the user is verified, and the result hash and the receipt are linked for evidence storage, so that the problems that the existing trusted platform cannot support the execution of various algorithms and is lack of effective supervision are solved.
Owner:GUIZHOU DIGITAL INNOVATION HLDG (GRP) CO LTD

Safe starting system and method of baseboard management controller

The invention provides a safe starting system and method for a substrate management controller, and the system comprises a plurality of first storage modules which are used for storing the power-on starting firmware of the substrate management controller; the first logic switching module is provided with a plurality of first selection ends and two first connection ends, and the first storage modules are connected with different first selection ends; the credibility verification module is used for carrying out credibility verification on the firmware content input by the verification input end; the trusted computing module is used for carrying out trusted computing on firmware content input by the computing input end; the second logic switching module is provided with two second selection ends and two second connection ends; and the control module is used for selecting any first selection end of the first logic switching module to be valid, and selecting any second selection end of the second logic switching module to be valid or two second connection ends to be connected in a loopback manner. According to the application, the starting and running safety, reliability and stability of the baseboard management controller can be effectively improved.
Owner:HUNAN BOJIANG INFORMATION TECHNOLOGY CO LTD

Subscriber Identity Module (Sim) card feature-based Non-Fungible Token (NFT)

A Subscriber Identity Module (SIM) card feature-based Non-Fungible Token. SIM card features, such as communication features, software / hardware features, electrical features, SIM Card behavior features and / or the like are extracted from the SIM card of a user's mobile communication device and a SIM card feature-based NFT is generated and stored on a distributed trust computing network. The distributed trust computing network serves to verify the authenticity of the underlying SIM card features. The NFT is subsequently used as a means for authentication is resource exchange events and other events requiring user / mobile communication device verification.
Owner:BANK OF AMERICA CORP

Zero-trust architecture-based emergency rescue multi-source data fusion method and system

The invention discloses an emergency rescue multi-source data fusion method based on a zero-trust architecture, and belongs to the technical field of multi-source data fusion, and the method comprises the following steps: constructing an end-side cloud collaborative trusted computing environment; based on trusted computing environment dynamic trust evaluation, correcting a trust value through a sliding window algorithm according to response time, an abnormal index and a collaborative efficiency index which are acquired in real time; encrypting and transmitting multi-source data based on the real-time trust value; and multi-party data fusion is carried out under encryption and trust guarantee. According to the method, multi-source data security fusion of a zero-trust architecture can be realized in an emergency rescue scene, and meanwhile, the problems of trust splitting and high delay of a traditional method are avoided.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

Enabling large frames for secure virtual machines

The computer-implemented methods, computer program products, and computer systems include computer operations that include executing, in a trusted computing environment, a call from a host in an untrusted computing environment, where the call is to determine a status of a large page of memory for use by a secure guest, where the secure guest is managed by the host in the untrusted computing environment. The executing includes determining that all small pages comprising the large page and the large page meet pre-defined security requirements. The executing also includes, based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest. The executing also includes storing in a computing element, a designation identifying the large page as belonging to the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Regional building group power transaction safety guarantee system

The invention relates to the technical field of electric power security, and discloses a regional building group electric power transaction security guarantee system, which comprises the following modules: a trusted computing environment authentication module, a transaction data encryption and commitment module, an under-chain privacy computing and verification module, and a computing process certification and settlement module. According to the method, the algorithm hash value recorded in the program registry contract is combined with the remote authentication mechanism of the trusted execution environment, so that the traceability and verifiability of the under-chain computing environment are constructed. The system digitally signs a report containing an algorithm code hash value by using a hardware built-in private key, and submits the report to an on-chain contract for comparison, and the mechanism ensures that any under-chain privacy computing task is executed in a specified algorithm environment which is approved by block chain consensus and is not tampered with codes, so that the privacy computing efficiency is improved. The security risk caused by the untrusted computing environment or the non-compliance of the algorithm logic is completely eradicated from the source, and the basic guarantee is provided for the correctness of the subsequent computing result.
Owner:ZHEJIANG PROVINCE ELECTRIC POWER FUEL CORP +1

Vehicle-mounted domain controller verification protection method and system, electronic equipment and storage medium

The invention discloses a vehicle-mounted domain controller verification protection method and system, electronic equipment and a storage medium, and relates to the field of vehicle machine safety control, and the method comprises the steps: electrifying an HSM, starting an HSM Boot process, and carrying out an initialization operation; checking and pulling up an HSM APP process and sending an HSM state to a control layer; the HOST is powered on, the HOST Boot process is started, a verification request is sent to the HSM APP through the control layer, and the integrity and legality of the HOST Boot and the HOST APP are verified; the control layer performs trust evaluation on the received HOST request and forwards the request to the HSM APP after the evaluation is passed, and the HSM APP feeds back a calling result and supports the HOST Boot to complete verification and pull up the HOST APP; and the control layer continuously monitors the operation state of the HOST, and performs dynamic access control on the request of calling the HSM APP interface by the HOST APP according to the real-time trust evaluation result. According to the method, by introducing a dynamic authorization and continuous verification mechanism, normal form conversion of the trusted computing system from static defense to dynamic verification is realized, and the safety of the vehicle-mounted domain controller is further improved.
Owner:CHINA FAW CO LTD +1

Cross-border accounting compliance processing system based on federated learning and trusted computing

The invention belongs to the technical field of financial data sharing, and particularly relates to a cross-border accounting compliance processing system based on federated learning and trusted computing, and the system comprises a federated learning module which is used for synchronously updating the learning models of all financial nodes through a federated average algorithm according to the locally trained model parameters of each financial node; the dynamic account book mapping module is used for acquiring exchange rate data of a country where each financial node is located in real time, and automatically adjusting currency amount in an account book through sliding window backtracking and recalculation; the trusted execution module is used for executing the cross-chain contract in the isolation container; the tax graph reasoning module is used for calculating association strength among nodes in a locally configured knowledge graph through an attention mechanism so as to generate probability distribution of a compliance path and identify an optimal tax processing scheme; and the report generation module is used for generating a report in a standard format according to the related data about the accounting criterion alignment and the related data about the exchange rate adjustment.
Owner:SHANGHAI GREAT WISDOM SHENJIU INFORMATION TECH CO LTD

Power distribution terminal key management method and system based on trusted computing

The invention provides a power distribution terminal key management method and system based on trusted computing, and relates to the field of power system management.The method comprises the following steps that key strength is determined according to risk indexes; encrypting the real-time data of the power distribution terminal by using the encryption key; transmitting to a key management center through a preset security access gateway; performing integrity verification on the encrypted real-time data, and associatively storing a verification result, a security risk index and a transmission timestamp to a block chain evidence storage node to form a tampering-free encryption key operation context record; and dynamically optimizing an encryption key updating strategy in combination with the historical change trend of the security risk index so as to realize closed-loop security management and control of the whole life cycle of the encryption key. According to the invention, the active immunity and the overall safety management and control level of the power distribution Internet of Things in a complex environment are significantly improved.
Owner:HEFEI ZHONGNENG POWER TECH

Secret transmission security management system for secret-related electronic files

The invention relates to the technical field of secret-related electronic file transmission and management, and discloses a secret-related electronic file secret transmission safety management system which comprises a safety management system. The security management system comprises a hardware security support layer, a distributed security storage layer, a file full life cycle security management layer, a user identity authentication and behavior auditing layer, a security auditing layer and an emergency response layer. The confidential electronic file secret transmission security management system integrates a trusted computing chip, security boot firmware, a physical unclonable function (PUF) and an optical isolation technology through a hardware security support layer, is different from a traditional system which only depends on software protection, constructs a trusted execution environment from a hardware bottom layer, guarantees the operation credibility by using the trusted computing chip, and improves the security of the confidential electronic file. The secure boot firmware blocks illegal program loading, the PUF endows the hardware with a unique uncounterfeited identity, and the optical isolation realizes physical level network isolation, so that threats such as hardware tampering and physical attacks are radically defended.
Owner:BEIJING AEROSPACE NETWORK TECHNOLOGY CO LTD

Request redirection with connectivity preparation

At a security gateway residing within a trusted computer network, a service request is obtained from an external client and is authenticated. In response, one instance of a plurality of available application instances is identified. The instances are hosted on a plurality of hosts having a plurality of firewalls, and the firewalls and the hosts reside within the network. The firewalls have been initially defaulted to block external access to all instances. A corresponding one of the hosts, within the trusted computer network, and corresponding to the identified one of the plurality of available application instances, is instructed to open a corresponding one of the firewalls to a network address corresponding to the external client. The external client is advised of a destination identifier and port corresponding to the opening of the firewall, to facilitate the external client communicating with the corresponding one of the hosts.
Owner:CHARTER COMM OPERATING LLC

Transparent enablement of large frames for secure guests

Computer program products, computer-implemented method, and computer systems include a trusted element enabling host translation for a large page for a given block of memory of a secure guest. The enabling can include executing, in a trusted computing environment, a call from a host to import a page to a memory of the secure guest. The trusted element can determine that a page virtual address matches a page corresponding absolute address and based on this determination can increase a counter associated with the large page; the counter indicates small pages comprising the large page imported to guest memories. When the counter indicates that all the small pages were imported and based on this determination, the trusted element determines if that all the small pages meet pre-defined security requirements and if they do, enables host translation for the large page for the given block of memory of the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

High-concurrency trusted computing remote attestation method and system based on equipment type adaptation

PendingCN122001694AAvoid process redundancyReduce bandwidth consumptionPublic key for secure communicationUser identity/authority verificationDevice typeSoftware engineering
The invention discloses a high-concurrency trusted computing remote certification method and system based on equipment type adaptation, and relates to the technical scheme that the method comprises the following steps: receiving a registration request which is sent by a client and contains an equipment type identifier; creating a thread pool, packaging the received registration request into a registration processing task, scheduling the registration processing task, analyzing an equipment type field in the registration request, and storing a mapping relationship between a client identifier and an equipment type to a local configuration file; in the challenge certification stage, querying the equipment type of the client from the local configuration file, and selecting an adaptive remote certification protocol according to a preset mapping rule; and packaging response verification operation of the server to the client into a proof processing task, and submitting the proof processing task to a thread pool for high-concurrency scheduling. The method can adapt to multi-form client requests, and can efficiently process large-scale concurrent remote attestation requests at the same time.
Owner:TIANFU JIANGXI LAB

Safe and credible wind power plant energy management system

The invention relates to the technical field of energy management, and discloses a safe and credible wind power plant energy management system, which comprises a server, a workstation, a fan main controller and a credible management center, and is characterized in that bidirectional identity authentication is performed between the server and the fan main controller, and credible connection is established; the server, the work station and the fan main controller all adopt an active immune dual-system defense architecture with parallel calculation and safety protection, and the active immune dual-system defense architecture is used for performing static measurement and dynamic measurement on a key program and preventing unauthorized and unexpected execution program operation. The active defense of known or unknown malicious codes is realized, and the safety and credibility of the operation environment of the wind power plant energy management system are ensured. A trusted computing dual-system architecture is adopted in the server, the work station and the fan main controller, static and dynamic measurement is conducted on equipment and programs, it is ensured that the operation environment of the system is safe and trusted, and the safety weakness of a wind power plant energy management system is overcome.
Owner:GUODIAN NANJING AUTOMATION

Homomorphic encryption privacy computing system and method supporting afterward traceability and auditing

The invention provides a homomorphic encryption privacy computing system and method supporting post-tracing and auditing, belongs to the technical field of computer data processing, and is used for deeply coupling generation of an encrypted auditing trace and a homomorphic encryption computing process and carrying out distributed random storage and chained verification. According to the method, the calculation chain based on the chain pointer is constructed, and the unique decryption and verification authority of the user side is combined, so that the integrity of the data processing process is guaranteed, and a user can obtain a credible calculation result and can verify the continuity and consistency of the whole calculation chain.
Owner:郭正宏

Railway signal system based on trusted computing security computing protection technology

The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

Telemetry-initiated mitigations in a zero-trust computing environment

Information Handling Systems (IHSs) support pre-boot telemetry for use in a zero-trust environment. A pre-boot telemetry orchestrator of the IHS retrieves a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment. The pre-boot telemetry orchestrator establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the pre-boot telemetry orchestrator receives a telemetry definition specifying pre-boot telemetry to be collected by the IHS. The telemetry is collected and transmitted during the pre-boot intervals according to the telemetry definition.
Owner:DELL PROD LP

Bmc-based trusted computing method, server, storage medium and electronic device

The embodiment of the application provides a kind of based on BMC's trusted computing method, server, storage medium and electronic equipment, it is related to computer technical field, method is applied to server, the host board card of server includes: host, BMC chip, method includes: host determines to be encrypted data, to be encrypted data is packaged as target data, and the target data is transmitted to the BMC chip;Host issues operation instruction to the BMC chip, and the operation instruction is used to indicate that target data is carried out trusted computing;The BMC chip is encapsulated according to the operation instruction to the target data, and obtains the trusted service package after encapsulation;The BMC chip carries out trusted computing according to the trusted service package, and obtains first calculation result;The first calculation result is encapsulated, and trusted service result package is obtained;The BMC chip feeds back the trusted service result package to the host.Just like this, trusted computing is realized by BMC chip, and the security and trusted computing performance are improved.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

A computing power zero-trust security tunnel method and system for improving private network security

This invention discloses a method and system for improving the security of dedicated networks using zero-trust computing power tunnels. Relating to the field of network communication technology, the method includes: registering each tunnel endpoint with a unified control center and authenticating tunnel endpoint information on the control plane; selecting a routing protocol and announcing service layer routing information, computing power information, and network information; scheduling computing power networks according to actual needs through the routing protocol; when a source node receives an uplink service message from a terminal, it adds tunnel encapsulation to the message based on the overlay routing information and includes comprehensive encrypted authentication security identifier information in the encapsulation before sending it out; upon receiving the message, the destination node classifies it and verifies the security identifier information of messages that conform to preset security characteristics, thus completing authentication in both tunnel and security dimensions. This invention eliminates the need for establishing tunnels between nodes actively or passively, and is applicable to point-to-point and point-to-multipoint tunnels.
Owner:INSPUR COMM TECH CO LTD

Method of operating a memory controller, a memory controller and a memory system

The present disclosure provides a method of operating a memory controller, a memory controller, and a memory system, and relates to the technical field of memories. The memory controller includes an Advanced Encryption Standard (AES) engine, a processor, and a first interface, and the memory controller is communicatively connected with a first memory through the first interface. The method includes: in response to the memory controller being powered on, obtaining, by the processor, firmware from the first memory through the first interface, wherein the firmware includes a configuration information ciphertext of a first trusted computing group (TCG); and decrypting, by the AES engine, the configuration information ciphertext of the first TCG based on a first key and a preset decryption algorithm, to obtain a configuration information plaintext of the TCG.
Owner:YANGTZE MEMORY TECH CO LTD

A power industrial control security protection system and method based on microkernel active defense

PendingCN122179216ASecuring communicationScheduling (computing)Trusted computing base
The application discloses a power industrial control safety protection system and method based on a microkernel active defense, wherein the system takes a microkernel isolation base as a minimum trusted computing base, allocates revocable communication endpoints and controlled mapping permissions to each protection domain, and provides base support for the isolation domain boundary and permission recovery in the active defense; in the method, the system is uniformly formatted by an input module to process field data and service requests and generate a request identifier, a request distribution service distributes the same request to an odd number of online executors for parallel processing, a single decision output available externally is generated, an executor scheduling service selects a candidate executor from a candidate protection domain pool and reconstructs an online user mode service cluster according to a feedback index by adopting a periodic rotation and event triggering strategy, and if the request distribution service, the consistency arbitration service or the executor scheduling service fails, a minimum bottom-up cleaning is performed by an active defense kernel state support module and a reestablishable state is entered.
Owner:NARI INFORMATION & COMM TECH

Trusted startup control method and system of modular separation design embedded system

The invention discloses a trusted start control method for a modular separation design embedded system, the embedded system comprises a core board and a special bottom board, the core board is integrated with a processor and a first BIOS, and the special bottom board is integrated with a trusted computing module, a second BIOS, an analog switch and a chip selection controller; the method comprises the following steps that after the embedded system is powered on, the trusted computing module prevents the processor from being started through a control signal, and the analog switch is controlled to switch a data path of the second BIOS to the trusted computing module; the trusted computing module reads the boot firmware in the second BIOS for trusted measurement, if measurement succeeds, the analog switch is controlled to switch a data path of the second BIOS to the processor, and the processor is allowed to be started; if the measurement fails, the processor is continuously prevented from being started. According to the method provided by the embodiment of the invention, the trusted root is preferentially started and actively measures the boot firmware, the code executed by the processor is ensured to be trusted, and a trust chain is established from the source.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)

Trusted computing remote attestation method and device, computer device and storage medium

The application relates to a trusted computing remote attestation method and device, computer equipment and a storage medium. The method comprises the following steps: obtaining random verification information, generating a remote attestation request according to the random verification information; outputting the remote attestation request to a party to be checked, receiving signature random information and a signature digital certificate fed back by the party to be checked, the party to be checked being a trusted computing execution party, the signature digital certificate being generated by signing a trusted digital certificate by the party to be checked, and the trusted digital certificate being issued to the party to be checked by a trusted agency; obtaining trusted attestation information of the party to be checked and a root certificate of the trusted agency from a preset block chain; when the signature digital certificate is verified to be correct according to the root certificate and the trusted attestation information, the signature random information is verified according to the signature digital certificate and the random verification information; and when the signature random information is verified to be correct, it is determined that the remote attestation is passed. The method can improve verification security and realize accurate verification.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD