Virtualization-Based Trusted Computing Measurement for Application Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies for trusted computing measurement are limited to overall measurements of application programs, failing to provide fine-grained measurements that could better support service provision based on application program integrity.
Innovation Solution
A virtualization-based trusted computing measurement method that separates target measurement data from an application program, stores it in a virtual image file within a virtual machine with a trusted execution environment, and determines the credibility of the virtual image file to allow or forbid the application program from operating within the trusted environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If overall measurement of application programs is performed, then measurement coverage is achieved, but measurement precision is insufficient for fine-grained credibility assessment
Solution Approach 1:
The patent segments the application program into multiple components (executable files, dynamic link libraries, configuration files, etc.) and performs measurement on each component separately. This segmentation enables fine-grained credibility assessment of individual components while maintaining overall program measurement coverage, directly resolving the contradiction between measurement precision and device complexity by organizing the measurement process into manageable segments
Solution Approach 2:
The patent extracts specific measurement data from each application program component and stores it in a centralized database. By taking out the essential measurement information (hash values, component identifiers, credibility ratings) from the complex application structure, the system achieves precise measurement without requiring complex real-time analysis of the entire application, thus improving measurement precision while controlling device complexity
2Measurement precision
If fine-grained measurement data is stored in virtual image files, then measurement precision is improved, but data management complexity increases
Solution Approach 1:
The patent merges the storage of fine-grained measurement data into virtual image files that are integrated with the trusted execution environment. By combining measurement data storage with the existing virtualization infrastructure, the system improves measurement precision while avoiding the need for separate complex data management systems, thus maintaining ease of operation through unified management
Solution Approach 2:
The patent introduces a measurement management module as an intermediary between the application components and the storage system. This intermediary automatically handles the extraction, processing, and storage of measurement data, improving precision through systematic data collection while simplifying operations by automating the data management process and shielding users from complexity
3Reliability
If credibility determination is performed on virtual image files, then reliability of trusted execution is improved, but processing time increases
Solution Approach 1:
The patent performs credibility determination on virtual image files in advance, before the trusted execution environment is activated. By conducting measurements and credibility assessments preliminarily, the system ensures reliability of the execution environment while minimizing processing time during actual execution, as the verification work is completed beforehand
Solution Approach 2:
The patent creates and measures virtual image files that contain measurement data, using these copied representations for credibility determination without requiring repeated analysis of the original application programs. This copying approach improves reliability through consistent measurement references while reducing processing time by avoiding redundant analysis of large application binaries
Data Source
AI summary
A virtualization-based trusted computing measurement method and apparatus, a device, and a storage medium. The method comprises: determining an application program to be measured; separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment; determining the credibility of a target virtual image file loaded to the trusted execution environment; and according to the credibility of the target virtual image file, allowing or forbidding an application program corresponding to the target virtual image file to operate in the trusted execution environment. In the embodiments of the present application, fine-grained trusted computing measurement may be performed on the application program, thereby better providing a service on the basis of the fine-grained measurement result.


