WO2022170966A1 - 在目标平台上启动应用程序的方法及装置 - Google Patents

在目标平台上启动应用程序的方法及装置 Download PDF

Info

Publication number
WO2022170966A1
WO2022170966A1 PCT/CN2022/073725 CN2022073725W WO2022170966A1 WO 2022170966 A1 WO2022170966 A1 WO 2022170966A1 CN 2022073725 W CN2022073725 W CN 2022073725W WO 2022170966 A1 WO2022170966 A1 WO 2022170966A1
Authority
WO
WIPO (PCT)
Prior art keywords
verification
startup
execution environment
trusted
chip
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/073725
Other languages
English (en)
French (fr)
Inventor
张煜龙
韦韬
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alipay Hangzhou Information Technology Co Ltd
Original Assignee
Alipay Hangzhou Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alipay Hangzhou Information Technology Co Ltd filed Critical Alipay Hangzhou Information Technology Co Ltd
Priority to US18/276,542 priority Critical patent/US12524547B2/en
Priority to EP22752127.5A priority patent/EP4293507B1/en
Publication of WO2022170966A1 publication Critical patent/WO2022170966A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/575—Secure boot
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00—Arrangements for program control, e.g. control units
    • G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44—Arrangements for executing specific programs
    • G06F9/445—Program loading or initiating
    • G06F9/44505—Configuring for program initiating, e.g. using registry, configuration files
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/51—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00—Arrangements for program control, e.g. control units
    • G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44—Arrangements for executing specific programs
    • G06F9/4401—Bootstrapping

Definitions

  • One or more embodiments of this specification relate to the field of data security, and in particular, to a method and apparatus for launching an application on a target platform.
  • the embodiments in this specification aim to provide a method for more effectively guaranteeing the code/data of the program on the computing platform, and solve the deficiencies in the prior art.
  • a method for starting an application program on a target platform comprising: sequentially starting multiple systems according to a preset starting sequence Item, wherein the startup of the first startup item included in the multiple system startup items includes measuring the next startup item and recording the measurement result in the verifiable startup chip; starting the verification agent based on the trusted execution environment A program; starting a first user application program based on a trusted execution environment, and determining the first verification information corresponding to the first user application program by the verification agent program based on local verification in the trusted execution environment.
  • the method further includes recording the first verification information into the verifiable boot chip.
  • the method further includes, in response to an access request by a remote user of the target platform to the verifiable boot chip, providing the remote user with a verifiable boot chip generated according to the first verification information the first record; enabling the remote user to determine the security of the first user application and/or the security of the target platform according to the first record.
  • the first verification information is maintained by the verification agent; the method further comprises, in response to a remote user requesting access to the verifiable boot chip, providing a second record to the remote user , the second record is generated by the verifiable bootable chip according to the first measurement result recorded when the tail boot item in the plurality of system boot items is booted; the verification agent program responds to the remote user based on the first measurement result.
  • the connection request of the measurement result establishes a trust channel with the remote user, and provides the first verification information to the remote user through the trust channel.
  • the second record is used by the remote user to determine the security of the target platform according to the second record.
  • the first verification information is used by the remote user to determine the security of the first user application program according to the first verification information.
  • determining the security of the target platform according to the second record includes, according to the second record, verifying whether the version of the operating system OS and/or the virtual machine monitor VMM started by the target platform is a predetermined version, The security of the target platform is determined according to the verification result.
  • the verifiable boot chip includes one of a trusted platform module TPM chip, a trusted password module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
  • the method further includes, after starting the first user application: starting the second user application based on the trusted execution environment, and the authentication agent program based on local authentication in the trusted execution environment, Second verification information corresponding to the second user application is determined.
  • the first activation item among the plurality of system activation items is a trusted metric root core CRTM.
  • the plurality of system startup items further include several items of a boot loader BootLoader, an operating system OS, and a virtual machine monitor VMM.
  • the verification agent program includes at least a trusted part; the startup of the verification agent program includes at least executing the trusted part in a trusted execution environment; The startup includes measuring the trusted part and recording the measurement result in the verifiable startup chip.
  • the first user application program includes at least a trusted part; starting the first user application program based on the trusted execution environment includes at least executing the trusted part in the trusted execution environment; the verification agent program Determining the first verification information of the first user application based on the local verification in the trusted execution environment includes, the verification agent determining the first user according to the trusted part based on the local verification in the trusted execution environment The first verification information corresponding to the application.
  • the verification agent program determines the first verification information corresponding to the first user application based on the local verification in the trusted execution environment, including: the verification agent program invokes the local verification instruction of the software protection extension SGX to obtain The first verification information corresponding to the first user application.
  • an apparatus for starting an application program on a target platform wherein the target platform at least includes a verifiable boot chip and a trusted execution environment, and the apparatus includes: a system boot unit configured to, according to a preset The startup sequence starts multiple system startup items in turn, wherein the startup of the first startup item included in the multiple system startup items includes measuring the next startup item, and recording the measurement result in the verifiable startup chip
  • a verification agent startup unit configured to start a verification agent program based on a trusted execution environment
  • a user application startup unit configured to start a first user application program based on a trusted execution environment, and the verification agent program based on the trusted execution environment.
  • the local verification in the environment determines the first verification information corresponding to the first user application.
  • a computer-readable storage medium on which a computer program is stored, and when the computer program is executed in a computer, the computer is caused to perform the method of the first aspect.
  • a computing device comprising a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, the first described method.
  • FIG. 1 shows a schematic diagram of the principle of a method for starting an application program on a target platform according to an embodiment of the present specification
  • FIG. 2 shows a flowchart of a method for starting an application on a target platform according to an embodiment of the present specification
  • FIG. 3 shows a flowchart of an implementation manner of a method for launching an application program on a target platform according to an embodiment of the present specification
  • FIG. 4 shows a flowchart of still another implementation manner of a method for launching an application program on a target platform according to an embodiment of the present specification
  • FIG. 5 shows a structural diagram of an apparatus for starting an application program on a target platform according to an embodiment of the present specification
  • the commonly used security methods for the code/data of the program on the computing platform mainly include the verifiable startup-based scheme and the trusted execution environment-based scheme.
  • the verifiable startup refers to a system startup process with step-by-step integrity verification.
  • the principle based on the verifiable boot scheme is that the system starts from the root of trust and starts to the user program step by step, and each boot step measures and checks the next boot item, and writes the trusted record in the verifiable boot chip. .
  • TPM Trusted Platform Module
  • the hash value of the next startup item is written into the platform configuration register PCR in the TPM chip.
  • the user can remotely retrieve the boot trusted record (the record will be signed to ensure integrity and authenticity) to determine whether the system maintains the expected boot items and boot sequence.
  • the disadvantage of verifiable startup is that it can only guarantee the security at startup. If it is a dynamic attack completed after startup, this scheme is difficult to detect and resist.
  • a trusted execution environment refers to an encrypted or isolated execution environment that is considered secure and trusted, so that code and data in an encrypted or isolated environment are not vulnerable to attacks from outside the environment.
  • the principle of the scheme based on the Trusted Execution Environment (TEE) is to exclude the high-privileged operating system OS or Virtual Machine Monitor (VMM) from the Trusted Computing Base (TCB for short) ), allowing users to safely run the code and data that needs to be protected on an untrusted operating system or VMM, and provide the ability for remote verification.
  • TEE-based scheme is that it only defends against direct attacks from malicious operating systems or VMMs, but cannot defend against side-channel attacks.
  • the solutions based on the trusted execution environment rely more or less on the remote verification services provided by third-party manufacturers, resulting in external availability (Availability) dependencies, and it is also necessary to assume that these third-party manufacturers will not do evil (for example, assuming that no collusion occurs. Attack a Collusion Attack or an Insider Attack).
  • Availability external availability
  • the inventor proposes a method and an apparatus for starting an application program on a target platform in the embodiments of this specification.
  • the trusted logic of the user application is placed in a trusted execution environment for isolated execution, thereby preventing direct (non-side-channel) attacks by malicious VMM/OS; on the other hand, the user is verifying the program
  • the verification information of the boot chain and the platform can be obtained at the same time, so as to verify that the booted VMM/operating system is in the expected state (for example, a credible version with a small TCB and with side-channel attack monitoring), which improves the Defense against side-channel attacks.
  • program verification is based on the combination of verifiable startup and local verification, and does not need to rely on external trusted execution environment verification services such as IAS, which greatly improves the reliability and security of program verification.
  • FIG. 1 shows a schematic diagram of the principle of a method for starting an application program on a target platform according to an embodiment of the present specification.
  • the target platform at least includes a verifiable boot chip, a trusted execution environment, and multiple boot items
  • the multiple boot items include multiple system boot items in the boot order (as shown in Figure 1, CRTM, Bootloader/ OS, the first system startup item is Trusted Metrics Root Core (CRTM), authentication agent, several user applications (User Application 1, User Application 2).
  • CRTM Trusted Metrics Root Core
  • authentication agent or its trusted part
  • the verification agent program obtains the verification information corresponding to the user application program at least by invoking the local verification in the trusted execution environment.
  • the verification agent program can maintain the verification information corresponding to the user application program, and can also record it. into the verifiable boot chip.
  • Using this method to start the application on the target platform and execute the user application in the trusted execution environment can prevent attacks from malicious VMM/operating systems, and, in the authentication of the application in the trusted execution environment, through the authentication agent
  • the program calls local verification, and no longer relies on the external trusted execution environment verification service.
  • FIG. 2 shows a flowchart of a method for launching an application program on a target platform according to an embodiment of the present specification.
  • the target platform at least includes a verifiable boot chip and a trusted execution environment, and the method at least includes the following steps.
  • step 21 start a plurality of system startup items in sequence according to a preset startup order, wherein, the startup of the first startup item included in the plurality of system startup items includes measuring the next startup item thereof, and measuring the result of the measurement. Recorded to the Verifiable Boot Chip.
  • verifiable startup refers to the system startup process with step-by-step integrity verification. Relying on an independent verifiable boot chip implementation.
  • the verifiable boot chip may use different types of verifiable boot chips, and this specification does not limit the specific use of the verifiable boot chip.
  • the verifiable boot chip may include one of a trusted platform module TPM chip, a trusted cryptographic module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
  • the measurement of the launch item may include a summary, characterization or identification of the content of the launch item.
  • the next startup item may be hashed to obtain its metrics.
  • the hash calculation result of the next startup item can also be performed after hash expansion to obtain the measurement result for recording.
  • hash expansion refers to the process of performing more than one nested hash operation based on the hash calculation result obtained first and the added calculation item to obtain the calculation result.
  • the system startup sequence is shown in FIG. 1 .
  • the Trusted Measurement Root Core (CRTM, Core Root of Trust Measurement) is the initial startup component of the target platform and is also the trusted source of the entire system. foundation. After CRTM starts, it will start the next startup item (eg, basic input output system BIOS), and then BIOS will start further startup items (eg, bootloader Bootloader, VMM, operating system, etc.), and so on, until the user mode program is started. .
  • BIOS basic input output system BIOS
  • CRTM will measure the next boot item (such as BIOS) after booting, and then BIOS will measure further boot items (such as Bootloader) , until the measurement reaches the user-mode program.
  • BIOS the next boot item
  • BIOS the next boot item
  • BIOS the next boot item
  • BIOS the next boot item
  • BIOS the next boot item
  • BIOS the further boot items
  • Each measurement result is written to the corresponding trusted record (in the verifiable chip), which can be later shown to the remote user.
  • the first activation item among the plurality of system activation items is the Root of Trust Metrics Core CRTM.
  • the plurality of system startup items may further include several items of a boot loader BootLoader, an operating system OS, and a virtual machine monitor VMM.
  • a dynamic CRTM (D-CRTM, Dynamic CRTM) scheme may also be adopted.
  • D-CRTM Dynamic CRTM
  • the BIOS starts up before the D-CRTM, and the dynamic startup event DL is triggered during the BIOS startup.
  • Event dynamic launch event
  • the verification agent program in the startup of the last system startup item, is measured, and the measurement result is recorded in the verifiable startup chip. Details of this embodiment will be set forth later in this specification.
  • the authentication agent is started based on the trusted execution environment.
  • a Trusted Execution Environment a secure enclave in the main processor (CPU), acts as an isolated execution environment that ensures that the code and data loaded inside are protected in terms of confidentiality and integrity.
  • TEEs provide the integrity of applications executed through TEE isolation and the confidentiality of their resources.
  • a TEE provides an execution space that provides a higher level of security than the operating system (OS) for trusted applications running on the device.
  • OS operating system
  • TEEs may be implemented on different host processors, and implementing TEEs on different host processors has different specific implementations. For example, implement the SGX scheme of TEE on a certain CPU, implement the TrustZone scheme of TEE on another CPU, and so on. This specification does not limit the specific implementation of the TEE.
  • an authentication agent is started before the user program Apps.
  • the authentication agent runs by means of the trusted execution environment technology like the user program Apps to be started in the future.
  • the trusted portion of the authentication agent (Trusted Logic) can be loaded into the trusted execution environment to isolate cryptographic execution.
  • the difference from the conventional verifiable startup mode is that the conventional verifiable startup mode is measured by directly entering the user program Apps during the startup process of the system startup item.
  • the verification agent program is measured and the measurement result is recorded in the verifiable bootable chip. That is to say, the last measurement of the system item and the object that records the result are different.
  • the authentication agent may include at least a trusted portion.
  • the specific implementation may be to measure the trusted part, and record the measurement result in the verifiable activation chip.
  • step 23 the first user application is started based on the trusted execution environment, and the verification agent program determines the first verification information corresponding to the first user application based on the local verification in the trusted execution environment.
  • the user application program started after the verification agent program obtains its verification information by at least invoking the local verification in the trusted execution environment by the verification agent program.
  • the SGX Local Attestation can be called on the SGX platform to obtain the authentication information of the application.
  • the verification agent program can also perform extended calculation after superimposing other data items on the basis of the information obtained by invoking the local verification in the trusted execution environment to verify the user program, for example, after hash extended calculation, obtain Authentication information for the application.
  • the authentication agent and the user application run in the TEE on the same target platform, the authentication agent can authenticate the user application by calling the local authentication (Local Attestation) in the TEE without avoiding the With the help of third-party remote verification.
  • the first user application may include at least a trusted part; the trusted part is executed in a trusted execution environment; the authentication agent is based on local authentication in the trusted execution environment, according to the first user
  • the trusted part of the application program determines the corresponding first verification information.
  • the verification agent program can invoke the local verification instruction of the software protection extension SGX to obtain the first verification information corresponding to the first user application.
  • a second user application may be started based on a trusted execution environment, and the verification agent program determines the second user application based on local verification in the trusted execution environment.
  • Second verification information corresponding to the user application. That is to say, for each user application program started after the authentication agent program is started, the authentication agent program determines its authentication information based on the local authentication in the TEE. This is again different from verifiable boot, where the next boot program is verified in sequence in a chain.
  • the verification information corresponding to the user application program may be written into the verifiable boot chip, or may not be written into the chip, but only maintained by the verification agent program, so that the above boot program can be remotely verified users provide different remote verification methods.
  • the first verification information may be recorded in the verifiable boot chip.
  • the user can send an access request to the verifiable boot chip in the target platform.
  • the target platform may provide the remote user with a first record generated by the verifiable boot chip according to the first verification information. In this way, the remote user can determine the security of the first user application and/or the security of the target platform according to the first record.
  • the remote user can build the same operating environment as the target platform on his own platform according to the program version number of the startup item on the target platform, and obtain the corresponding value of the first record accordingly , according to the corresponding value of the first record and the first record, determine the security of each startup item (including the system startup item and the user application program startup item) on the target platform startup chain.
  • the corresponding value of the first record matches the first record, it means that each startup item on the startup chain of the target platform is complete and correct, that is to say, the target platform and the applications started on it are both complete and correct. It is safe; if the corresponding value of the first record does not match the first record, it means that at least one of the startup items on the target platform startup chain is incomplete or incorrect, that is, the target platform and the startup on it One or more of the applications are unsafe.
  • the remote user can also obtain the corresponding value of the first record from, for example, a trusted third party, and the rest of the execution process is the same as the corresponding part of the execution process in the previous example, and details are not repeated here. .
  • the first verification information may be maintained by the verification agent.
  • the user when a remote user of the target platform wishes to remotely verify the security of the target platform, the user can still issue an access request to the verifiable boot chip in the target platform.
  • the target platform provides the remote user with a second record, where the second record is the first measurement result recorded when the verifiable boot chip is booted according to the tail boot item of the plurality of system boot items generate.
  • the tail startup item is the last system startup item, and the program started after it is the verification agent program. Therefore, the first measurement result recorded when the tail startup item is started corresponds to the measurement result of the verification agent program.
  • the remote user can issue a connection request to the authentication agent based on the first measurement result.
  • the authentication agent may establish a trusted channel with the remote user, and provide it with the first authentication information through the trusted channel.
  • the first authentication information may be used by the remote user to determine the security of the first user application program according to the first authentication information.
  • the second record may be used by the first remote user to determine the security of the target platform according to the second record.
  • the second record can be used by the first remote user to verify whether the version of the operating system OS and/or virtual machine monitor VMM started by the target platform is a predetermined version according to the second record, and determine the Describe the security of the target platform.
  • the remote user can build the same operating environment as the target platform on his own platform according to the program version numbers of each startup item on the target platform, so as to obtain the correspondence between the second record and the first verification information on his own platform value, according to the corresponding value of the second record and the second record, determine the security of the on-chain system startup item and the verification agent program on the target platform.
  • the corresponding value of the second record matches the second record, it can be determined that each system startup item and the verification agent program on the startup chain on the target platform are complete and correct, that is to say, the target platform can be determined The system on which the platform runs is secure.
  • the integrity and correctness of the first user application can also be determined according to the corresponding value of the first verification information and the first verification information. If the corresponding value of the first verification information and the first verification information If they match, it can be determined that the first user application is safe.
  • the remote user can also obtain the corresponding values of the second record and the first verification information from, for example, a trusted third party, and the rest of the execution process is the same as the corresponding part of the execution process in the previous example, which will not be repeated here. .
  • FIG. 5 shows a structural diagram of an apparatus for launching an application program on a target platform according to an embodiment of the present specification.
  • the target platform at least includes a verifiable boot chip and a trusted execution environment.
  • the apparatus 500 includes: a system boot unit 51, configured to sequentially boot multiple system boot items according to a preset boot sequence, wherein, for The startup of the first startup item included in the plurality of system startup items includes measuring its next startup item, and recording the measurement result in the verifiable startup chip; the verification agent startup unit 52 is configured to perform a trusted execution based on The environment starts the verification agent program; the user application startup unit 53 is configured to start the first user application program based on the trusted execution environment, and the verification agent program determines the first user based on the local verification in the trusted execution environment The first verification information corresponding to the application.
  • the apparatus 500 may further include a recording unit configured to record the first verification information into the verifiable boot chip.
  • the apparatus 500 may further include a first response unit configured to, in response to a request for accessing the verifiable boot chip by a remote user of the target platform, provide a verifiable boot chip to the remote user A first record generated according to the first verification information; enabling the remote user to determine the security of the first user's application program and/or the security of the target platform according to the first record.
  • a first response unit configured to, in response to a request for accessing the verifiable boot chip by a remote user of the target platform, provide a verifiable boot chip to the remote user A first record generated according to the first verification information; enabling the remote user to determine the security of the first user's application program and/or the security of the target platform according to the first record.
  • the user application launching unit 53 may be further configured to maintain the first authentication information by the authentication agent; the apparatus 500 may further include a second response unit configured to respond to the remote user For the access request to the verifiable boot chip, a second record is provided to the remote user, and the second record is the first record recorded when the verifiable boot chip is activated according to the tail boot item in the plurality of system boot items.
  • a measurement result is generated; the third response unit is configured to, in response to the connection request of the remote user based on the first measurement result, the verification agent program establishes a trust channel with the remote user, and sends a message to the remote user through the trust channel. It provides the first verification information.
  • the second record is used by the remote user to determine the security of the target platform according to the second record.
  • the first verification information may be used by the remote user to determine the security of the first user application program according to the first verification information.
  • the second response unit may be further configured to, according to the second record, determine the security of the target platform, including, according to the second record, verifying whether the version of the operating system OS and/or the virtual machine monitor VMM started by the target platform is For a predetermined version, the security of the target platform is determined according to the verification result.
  • the verifiable boot chip may include one of a trusted platform module TPM chip, a trusted cryptographic module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
  • the user application starting unit may be further configured to, after starting the first user application: start the second user application based on the trusted execution environment, and the user application starting unit may be further configured to:
  • the verification agent program determines the second verification information corresponding to the second user application based on the local verification in the trusted execution environment.
  • the first activation item among the plurality of system activation items may be the Root of Trust Metrics Core CRTM.
  • the plurality of system startup items may further include several items of the boot loader BootLoader, the operating system OS, and the virtual machine monitor VMM.
  • the verification agent program may include at least a trusted part; the verification agent startup unit may be further configured to execute the trusted part in a trusted execution environment; the system startup unit may be further configured to, for all The trusted part is measured, and the measurement result is recorded in the verifiable boot chip.
  • the first user application program includes at least a trusted part; the user application startup unit may be further configured to execute the trusted part in a trusted execution environment; the verification agent program is based on the trusted execution environment In the local verification, the first verification information corresponding to the first user application is determined according to the trusted part.
  • the user application startup unit may be further configured to: the authentication agent program invokes the local authentication instruction of the software protection extension SGX to obtain the first authentication information corresponding to the first user application program.
  • Another aspect of the present specification provides a computer-readable storage medium on which a computer program is stored, when the computer program is executed in a computer, the computer is made to execute any one of the above methods.
  • Another aspect of the present specification provides a computing device, including a memory and a processor, where executable code is stored in the memory, and when the processor executes the executable code, any one of the foregoing methods is implemented.
  • the functions described in the present invention may be implemented in hardware, software, firmware, or any combination thereof.
  • the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Stored Programmes (AREA)
  • Storage Device Security (AREA)

Abstract

说明书实施例提供了一种在目标平台上启动应用程序的方法及装置,目标平台至少包含可验证启动芯片和可信执行环境,该方法包括:按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;基于可信执行环境启动验证代理程序;基于可信执行环境启动第一用户应用程序,并由验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序对应的第一验证信息。

Description

在目标平台上启动应用程序的方法及装置 技术领域
本说明书一个或多个实施例涉及数据安全领域,尤其涉及用于在目标平台上启动应用程序的方法及装置。
背景技术
当前,在多方计算、数据外包、敏感数据处理等场景下,在计算平台上保障程序的代码/数据不被攻击者窃取或破坏,成为技术上的刚需。现有技术中,虽然有一些方案用于保障程序的代码/数据的安全,但是仍旧存在保障有漏洞、依赖远程验证服务等缺点。
因此,对于计算平台上的程序的代码/数据进行保护是亟需解决的问题。
发明内容
本说明书中的实施例旨在提供更有效地保障计算平台上的程序的代码/数据的方法,解决现有技术中的不足。
根据第一方面,一种在目标平台上启动应用程序的方法,所述目标平台至少包含可验证启动芯片和可信执行环境,所述方法包括:按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;基于可信执行环境启动验证代理程序;基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
在一个实施例中,所述方法还包括,将第一验证信息记录到可验证启动芯片中。
在一个实施例中,所述方法还包括,响应于所述目标平台的远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供可验证启动芯片根据所述第一验证信息生成的第一记录;使得所述远程用户根据第一记录,确定第一用户应用程序的安全性,和/或,所述目标平台的安全性。
在一个实施例中,所述第一验证信息由所述验证代理程序维护;所述方法还包括,响应于远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供第二记录,所述第二记录为可验证启动芯片根据所述多个系统启动项中的尾启动项启动时所记录的 第一度量结果生成;所述验证代理程序响应于所述远程用户基于第一度量结果的连接请求,建立与该远程用户的信任通道,通过所述信任通道向其提供所述第一验证信息。
在一个实施例中,所述第二记录用于远程用户根据第二记录,确定所述目标平台的安全性。
在一个实施例中,所述第一验证信息用于远程用户根据第一验证信息,确定第一用户应用程序的安全性。
在一个实施例中,根据第二记录,确定所述目标平台的安全性,包括,根据第二记录,验证目标平台启动的操作系统OS和/或虚拟机监视器VMM的版本是否为预定版本,根据验证结果确定所述目标平台的安全性。
在一个实施例中,所述可验证启动芯片包括可信平台模块TPM芯片、可信密码模块TCM芯片、可信平台控制模块TPCM芯片、Titan芯片中的一种。
在一个实施例中,所述方法,还包括,在启动第一用户应用程序之后:基于可信执行环境启动第二用户应用程序,由所述验证代理程序基于可信执行环境中的本地验证,确定所述第二用户应用程序对应的第二验证信息。
在一个实施例中,所述多个系统启动项中的首个启动项为可信度量根核心CRTM。
在一个实施例中,所述多个系统启动项还包括,引导加载程序BootLoader、操作系统OS、虚拟机监视器VMM中的若干项。
在一个实施例中,验证代理程序至少包括可信部分;所述启动验证代理程序,至少包括,在可信执行环境中执行所述可信部分;所述多个系统启动项中最后一项的启动,包括,对于所述可信部分进行度量,并将度量结果记录到可验证启动芯片中。
在一个实施例中,第一用户应用程序至少包括可信部分;基于可信执行环境启动第一用户应用程序,至少包括,在可信执行环境中执行所述可信部分;所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序的第一验证信息,包括,所述验证代理程序基于可信执行环境中的本地验证,根据所述可信部分,确定第一用户应用程序对应的第一验证信息。
在一个实施例中,所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序对应的第一验证信息,包括,验证代理程序调用软件保护扩展SGX的本地验证指令,得到第一用户应用程序对应的第一验证信息。
根据第二方面,提供了一种在目标平台上启动应用程序的装置,所述目标平台至少包含可验证启动芯片和可信执行环境,所述装置包括:系统启动单元,配置为,按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;验证代理启动单元,配置为,基于可信执行环境启动验证代理程序;用户应用启动单元,配置为,基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
根据第三方面,提供了一种计算机可读存储介质,其上存储有计算机程序,当所述计算机程序在计算机中执行时,令计算机执行第一方面所述的方法。
根据第四方面,提供了一种计算设备,包括存储器和处理器,其特征在于,所述存储器中存储有可执行代码,所述处理器执行所述可执行代码时,实现第一所述的方法。
利用以上各个方面中的方法、装置、计算设备、存储介质中的一个或多个,可以更为有效地解决保障计算平台上的程序的代码/数据的问题。
附图说明
为了更清楚说明本发明实施例的技术方案,下面将对实施例描述中所需使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的原理示意图;
图2示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的流程图;
图3示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的一种实施方式的流程图;
图4示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的又一种实施方式的流程图;
图5示出根据本说明书实施例的一种在目标平台上启动应用程序的装置的结构图;
具体实施方式
下面将结合附图,对本发明书提供的方案进行描述。
如前所述,目前的保障程序的代码/数据的安全的方法,仍旧存在保障有漏洞、依赖远程验证服务等缺点。发明人对于启动程序的代码/数据的现有的保障方法进行了研究,并得到以下结论。
目前,常用的计算平台上程序的代码/数据的保障方法,主要有基于可验证启动的方案和基于可信执行环境的方案。其中,可验证启动是指,具备逐级完整性校验的系统启动过程。基于可验证启动方案的原理为,系统从可信根出发,一步一步启动到用户程序,每启动一步都对下一步启动项进行度量、校验,并写入可验证启动芯片中的可信记录。以采用TPM(Trusted Platform Module)技术为例,即是将下一步启动项的哈希值写入TPM芯片中的平台配置寄存器PCR中。用户可以远程调取启动可信记录(该记录会被签名来保证完整性和真实性)来判定系统是否维持了预期的启动项及启动顺序。然而,可验证启动的缺点在于,只能保证启动时的安全,如果是启动之后完成的动态攻击,该方案很难检测和抵御。
可信执行环境是指加密或隔离的、因而被认为安全可信的执行环境,因此,代码和数据在加密或隔离的环境里不易受来自环境外的攻击。基于可信执行环境(Trusted Execution Environment,简称TEE)的方案的原理为,将高权限的操作系统OS或虚拟机管理器(Virtual Machine Monitor,简称VMM)排除在信任基(Trusted Computing Base,简称TCB)之外,让用户放心地在不可信的操作系统或VMM之上运行需要保护的代码和数据,并提供远程校验的能力。然而,基于可信执行环境的方案的首要缺点是只防御来自恶意操作系统或VMM的直接攻击,却无法抵御侧信道攻击(Side-channel Attack)。此外,基于可信执行环境的方案多少都依赖第三方厂商提供的远程校验服务,产生了外部可用性(Availability)依赖,同时也需要假设这些第三方厂商不会作恶(例如,假设不发生共谋攻击Collusion Attack或内部攻击Insider Attack)。
发明人为了解决上述技术方案存在的问题,在本说明书中的实施例中,提出一种在目标平台上启动应用程序的方法及装置。在该方案中,一方面,将用户应用程序的可信逻辑放在可信执行环境里隔离执行,从而防止恶意VMM/操作系统的(非侧信道)直接攻击;另一方面,用户在验证程序时可以同时获取启动链和平台的校验信息,从而能验证所启动的VMM/操作系统是预期状态(例如是一个可信的、TCB很小的、具备侧信道攻 击监控的版本),既而提高对侧信道攻击的防御能力。再一方面,程序验证建立在可验证启动和本地验证相结合的机制上,不需要依赖诸如IAS之类的外部可信执行环境校验服务,大大提升了程序验证的可靠性和安全性。
下面进一步说明该方法的基本思想。
图1示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的原理示意图。如图1所示,目标平台至少包含可验证启动芯片、可信执行环境、以及多个启动项,多个启动项按启动次序包括多个系统启动项(如图中1所示CRTM、Bootloader/OS,第一个系统启动项为可信度量根核心CRTM)、验证代理程序、若干用户应用程序(用户应用1、用户应用2)。首先,依次启动多个系统启动项,在任意一个系统启动项的启动中,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中。然后,在TEE中启动验证代理程序(或其可信部分)。最后,启动用户应用程序,验证代理程序至少通过调用可信执行环境中的本地验证,得到该用户应用程序对应的验证信息,验证代理程序可以维护用户应用程序对应的验证信息,也可以将其纪录到可验证启动芯片中。
使用该方法在目标平台上启动应用程序,在可信执行环境里执行用户应用程序,可以防止来自恶意VMM/操作系统的攻击,并且,在可信执行环境对应用程序的验证中,通过验证代理程序调用本地验证进行,不再依赖外部可信执行环境校验服务。还可以利用可验证启动芯片根据纪录到其中的度量/验证信息生成的可信纪录,验证所启动的程序和VMM/操作系统是否为预期状态,进而根据验证结果对侧信道攻击进行防御。
下面进一步阐述该方法的具体过程。
图2示出根据本说明书实施例的一种在目标平台上启动应用程序的方法的流程图。目标平台至少包含可验证启动芯片和可信执行环境,该方法至少包括如下步骤。
在步骤21,按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中。
如前所述,可验证启动是指具备逐级完整性校验的系统启动过程,其原理是对启动项进行可以据以施行逐级完整性校验的可信纪录,该可信纪录通常是依赖于独立的可验证启动芯片实现。在不同的实施例中,可验证启动芯片可以采用不同种类的可验证启动芯片,本说明书对于具体采用何种可验证启动芯片不做限定。在一个实施例中,可验证启动芯片可以包括可信平台模块TPM芯片、可信密码模块TCM芯片、可信平台控制模 块TPCM芯片、Titan芯片中的一种。
对启动项的度量(measurement)可以包括,对启动项内容的汇总、表征或是标识。根据一种实施方式,可以对下一个启动项进行哈希(hash)计算,从而获得其度量结果。在另一个例子中,也可以对下一个启动项的hash计算的结果,进行hash扩展后获取度量结果进行纪录。所谓的hash扩展是指根据先获得hash计算结果,和添加的计算项,进行一次以上嵌套的hash运算,以获得计算结果的过程。
在一个实施例中,在该步骤中,系统启动顺序如图1所示,可信度量根核心(CRTM,Core Root of Trust Measurement),是目标平台最开始的启动组件,也是整个系统的可信根基。CRTM启动后会启动下一个启动项(例如,基本输入输出系统BIOS),然后BIOS会启动进一步的启动项(例如引导加载程序Bootloader、VMM、操作系统等等),如此迭代,直到启动用户态程序。在此过程中,为了建立启动关系的信任链,像常规可验证启动一样,CRTM启动后会对下一个启动项(例如BIOS)予以度量,然后BIOS会对进一步的启动项(例如Bootloader)予以度量,直到度量到用户态程序。每一个度量结果都会写入相应的可信记录(可验证芯片中)里,事后可以出示给远程用户。
在一个实施例中,多个系统启动项中的首个启动项为可信度量根核心CRTM。在另一个实施例中,多个系统启动项还可以包括,引导加载程序BootLoader、操作系统OS、虚拟机监视器VMM中的若干项。在又一个实施例中,也可以采用动态CRTM(D-CRTM,Dynamic CRTM)方案,在D-CRTM(Dynamic CRTM)方案中,BIOS先于D-CRTM启动,在BIOS启动中激发动态启动事件DL Event(dynamic launch event),从而启动D-CRTM,但是BIOS启动中,并不会对于下一个启动项的度量,并记录到可启动验证芯片。也就是说,无论是采用常规CRTM(或称静态CRTM,S-CRTM,Static CRTM)、或是D-CRTM,对于下一个启动项的度量,并记录到可启动验证芯片,均由CRTM(S-CRTM或D-CRTM)启动开始。
在一个实施例中,在最后一个系统启动项的启动中,对于验证代理程序进行度量,并将度量结果记录到可验证启动芯片中。该实施例的详情将在本说明书后文中阐述。
在步骤22,基于可信执行环境启动验证代理程序。
可信执行环境(TEE),是主处理器(CPU)中的一个安全区域,作为一种隔离执行环境,它可以确保在内部加载的代码和数据在机密性和完整性方面得到保护。例如,TEE提供了通过TEE隔离执行的应用程序的完整性以及其资源的机密性。或者说,TEE 提供了一个执行空间,该执行空间为设备上运行的受信任应用程序提供了比操作系统(OS)高的安全性。
在不同的实施例中,TEE可以在不同的主处理器上实现,而在不同的主处理器上实现TEE具有不同的具体实施方式。例如在某种CPU上实现TEE的SGX方案,在另一种CPU实现TEE的TrustZone方案,等等。本说明书对TEE的具体实施方式不做限制。
该步骤中,与常规可验证启动不同的是,在用户程序Apps之前启动一个验证代理程序。验证代理程序和未来要启动的用户程序Apps一样借助可信执行环境技术运行。在一个例子中,可以将验证代理程序的可信部分(Trusted Logic)加载到可信执行环境里隔离加密执行。
与常规可验证方式启动不同之处还在于,常规可验证启动方式由在系统启动项的启动过程中直接进入对用户程序Apps进行度量。而本说明书实施例中,如上文所述的,在多个系统启动项中最后一项的启动中,对于验证代理程序进行度量并将度量结果记录到可验证启动芯片中。也就是说系统项的最后度量和纪录结果的对象不同。在一个实施例中,验证代理程序可以至少包括可信部分。该实施例中,在步骤21中对于多个系统启动项中最后一项的启动,其具体实施方式可以是,对于所述可信部分进行度量,并将度量结果记录到可验证启动芯片中。
在步骤23,基于可信执行环境启动第一用户应用程序,并由验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序对应的第一验证信息。
该步骤中,在验证代理程序之后启动的用户应用程序,由验证代理程序至少通过调用可信执行环境中的本地验证,获取其验证信息。例如,在一个例子中,可以在SGX平台上调用SGX的本地验证(Local Attestation),获取应用程序的验证信息。在另一个例子中,验证代理程序也可以在调用可信执行环境中的本地验证对该用户程序进行验证获得的信息的基础上,叠加其他数据项后进行扩展计算,如hash扩展计算后,获得该应用程序的验证信息。本质上,由于验证代理程序和用户应用程序运行在同一目标平台上的TEE中,因此,验证代理程序可以通过调用TEE中的本地验证(Local Attestation)来实现对用户应用程序的身份验证,而避免借助于第三方的远程验证。
在一个实施例中,第一用户应用程序可以至少包括可信部分;在可信执行环境中执行所述可信部分;验证代理程序基于可信执行环境中的本地验证,根据所述第一用户应用程序的可信部分,确定对应的第一验证信息。在一个具体的实施例中,验证代理程序 可以调用软件保护扩展SGX的本地验证指令,得到第一用户应用程序对应的第一验证信息。
在一个实施例中,还可以在启动第一用户应用程序之后,基于可信执行环境启动第二用户应用程序,由所述验证代理程序基于可信执行环境中的本地验证,确定所述第二用户应用程序对应的第二验证信息。也就是说,在验证代理程序启动之后启动的各个用户应用程序,均由验证代理程序基于TEE中的本地验证,确定其验证信息。这与可验证启动中,链式地依次验证下一启动程序的方式,再次形成不同。
在不同的实施方式中,用户应用程序对应的验证信息,可以被写入可验证启动芯片,也可以不被写入该芯片、而仅由验证代理程序维护,从而可以对上述启动程序进行远程验证的用户提供不同的远程校验方式。
因此,根据一种实施方式,如图3所示,可以将第一验证信息记录到可验证启动芯片中。在一个实施例中,当目标平台的远程用户希望对目标平台的安全性进行远程校验时,该用户可以对目标平台中的可验证启动芯片发出访问请求。响应于该访问请求,目标平台可以向所述远程用户提供可验证启动芯片根据所述第一验证信息生成的第一记录。如此,该远程用户可以根据该第一记录,确定第一用户应用程序的安全性,和/或,所述目标平台的安全性。
在该实施方式中的一个例子中,远程用户可以在其自己的平台上根据目标平台上的启动项的程序版本号,搭建与目标平台相同的运行环境,并据以获得第一记录的对应值,根据第一记录的对应值和第一记录,确定目标平台启动链上各启动项(包括系统启动项和用户应用程序启动项)的安全性。在一个例子中,如果第一记录的对应值和第一记录相匹配,则说明目标平台的启动链上各启动项均是完整和正确的,也就是说目标平台和其上启动的应用程序均是安全的;如果第一记录的对应值和第一记录不匹配,则说明目标平台启动链上各启动项中至少有一项是不完整或不正确的,也就是说目标平台和其上启动的应用程序中有一项或多项是不安全的。
在该实施方式中的另一个例子中,远程用户也可以从例如信任的第三方获得第一记录的对应值,其余的执行过程同于上一个例子中执行过程中相应的部分,这里不再赘述。
根据另一种实施方式,如图4所示,第一验证信息可以由验证代理程序维护。在一个实施例中,在目标平台的远程用户希望对目标平台的安全性进行远程校验时,该用户仍然可以对目标平台中的可验证启动芯片发出访问请求。响应于该访问请求,目标平台 向该远程用户提供第二记录,所述第二记录为可验证启动芯片根据所述多个系统启动项中的尾启动项启动时所记录的第一度量结果生成。需要理解,尾启动项是最后一个系统启动项,在其之后启动的程序为验证代理程序,因此,尾启动项启动时所记录的第一度量结果,即对应于验证代理程序的度量结果。于是,远程用户可以基于该第一度量结果,向该验证代理程序发出连接请求。响应于该连接请求,验证代理程序可以建立与该远程用户的信任通道,通过所述信任通道向其提供所述第一验证信息。
在一个例子中,第一验证信息可以用于远程用户根据第一验证信息,确定第一用户应用程序的安全性。另一个例子中,第二记录可以用于第一远程用户根据第二记录,确定所述目标平台的安全性。在一个具体的例子中,第二记录可以用于第一远程用户根据第二记录,验证目标平台启动的操作系统OS和/或虚拟机监视器VMM的版本是否为预定版本,根据验证结果确定所述目标平台的安全性。
具体的,远程用户可以在其自己的平台上根据目标平台上的各启动项的程序版本号,搭建与目标平台相同的运行环境,从而获得其自己平台上第二记录和第一验证信息的对应值,根据第二记录的对应值和第二记录,确定目标平台上启动链上系统启动项和验证代理程序的安全的。在一个例子中,如果第二记录的对应值和第二记录相匹配,则可确定目标平台上启动链上各系统启动项和验证代理程序均是完整的、正确的,也就是说可以确定目标平台运行的系统是安全的。然后,在另一个例子中,还可以根据第一验证信息的对应值和第一验证信息,确定第一用户应用程序的完整性和正确性,如果第一验证信息的对应值和第一验证信息相匹配,则可确定第一用户应用程序安全的。
在另一个例子中,远程用户也可以从例如信任的第三方获得第二记录和第一验证信息的对应值,其余的执行过程同于上一个例子中执行过程中相应的部分,这里不再赘述。
图5示出根据本说明书实施例的一种在目标平台上启动应用程序的装置的结构图。目标平台至少包含可验证启动芯片和可信执行环境,如图5所示,该装置500包括:系统启动单元51,配置为,按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;验证代理启动单元52,配置为,基于可信执行环境启动验证代理程序;用户应用启动单元53,配置为,基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
在一个实施例中,该装置500还可以包括,记录单元,配置为,将第一验证信息记 录到可验证启动芯片中。
在一个例子中,该装置500还可以包括,第一响应单元,配置为,响应于所述目标平台的远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供可验证启动芯片根据所述第一验证信息生成的第一记录;使得所述远程用户根据第一记录,确定第一用户应用程序的安全性,和/或,所述目标平台的安全性。
在一个实施例中,用户应用启动单元53,可以进一步配置为,所述第一验证信息由所述验证代理程序维护;该装置500还可以包括,第二响应单元,配置为,响应于远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供第二记录,所述第二记录为可验证启动芯片根据所述多个系统启动项中的尾启动项启动时所记录的第一度量结果生成;第三响应单元,配置为,所述验证代理程序响应于所述远程用户基于第一度量结果的连接请求,建立与该远程用户的信任通道,通过所述信任通道向其提供所述第一验证信息。
在一个例子中,所述第二记录用于远程用户根据第二记录,确定所述目标平台的安全性。
在一个例子中,所述第一验证信息可以用于远程用户根据第一验证信息,确定第一用户应用程序的安全性。
第二响应单元,可以进一步配置为,根据第二记录,确定所述目标平台的安全性,包括,根据第二记录,验证目标平台启动的操作系统OS和/或虚拟机监视器VMM的版本是否为预定版本,根据验证结果确定所述目标平台的安全性。
在一个实施例中,所述可验证启动芯片可以包括可信平台模块TPM芯片、可信密码模块TCM芯片、可信平台控制模块TPCM芯片、Titan芯片中的一种。
在一个实施例中,用户应用启动单元,可以进一步配置为,在启动第一用户应用程序之后:基于可信执行环境启动第二用户应用程序,用户应用启动单元,可以进一步配置为,由所述验证代理程序基于可信执行环境中的本地验证,确定所述第二用户应用程序对应的第二验证信息。
在一个实施例中,多个系统启动项中的首个启动项可以为可信度量根核心CRTM。在一个例子中,多个系统启动项还可以包括,引导加载程序BootLoader、操作系统OS、虚拟机监视器VMM中的若干项。
在一个实施例中,验证代理程序可以至少包括可信部分;验证代理启动单元,可以 进一步配置为,在可信执行环境中执行所述可信部分;系统启动单元,可以进一步配置为,对于所述可信部分进行度量,并将度量结果记录到可验证启动芯片中。
在一个实施例中,第一用户应用程序至少包括可信部分;用户应用启动单元,可以进一步配置为,在可信执行环境中执行所述可信部分;所述验证代理程序基于可信执行环境中的本地验证,根据所述可信部分,确定第一用户应用程序对应的第一验证信息。
在一个实施例中,用户应用启动单元,可以进一步配置为,验证代理程序调用软件保护扩展SGX的本地验证指令,得到第一用户应用程序对应的第一验证信息。
本说明书另一方面提供一种计算机可读存储介质,其上存储有计算机程序,当所述计算机程序在计算机中执行时,令计算机执行上述任一项方法。
本说明书另一方面提供一种计算设备,包括存储器和处理器,所述存储器中存储有可执行代码,所述处理器执行所述可执行代码时,实现上述任一项方法。
需要理解,本文中的“第一”,“第二”等描述,仅仅为了描述的简单而对相似概念进行区分,并不具有其他限定作用。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本发明所描述的功能可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些功能存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。
以上所述的具体实施方式,对本发明的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上所述仅为本发明的具体实施方式而已,并不用于限定本发明的保护范围,凡在本发明的技术方案的基础之上,所做的任何修改、等同替换、改进等,均应包括在本发明的保护范围之内。

Claims (17)

  1. 一种在目标平台上启动应用程序的方法,所述目标平台至少包含可验证启动芯片和可信执行环境,所述方法包括:
    按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;
    基于可信执行环境启动验证代理程序;
    基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
  2. 根据权利要求1所述的方法,还包括,将第一验证信息记录到可验证启动芯片中。
  3. 根据权利要求2所述的方法,还包括,
    响应于所述目标平台的远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供可验证启动芯片根据所述第一验证信息生成的第一记录;使得所述远程用户根据第一记录,确定第一用户应用程序的安全性,和/或,所述目标平台的安全性。
  4. 根据权利要求1所述的方法,其中,所述第一验证信息由所述验证代理程序维护;所述方法还包括,
    响应于远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供第二记录,所述第二记录为可验证启动芯片根据所述多个系统启动项中的尾启动项启动时所记录的第一度量结果生成;
    所述验证代理程序响应于所述远程用户基于第一度量结果的连接请求,建立与该远程用户的信任通道,通过所述信任通道向其提供所述第一验证信息。
  5. 根据权利要求4所述的方法,其中,所述第二记录用于远程用户根据第二记录,确定所述目标平台的安全性。
  6. 根据权利要求4所述的方法,其中,所述第一验证信息用于远程用户根据第一验证信息,确定第一用户应用程序的安全性。
  7. 根据权利要求5所述的方法,其中,根据第二记录,确定所述目标平台的安全性,包括,根据第二记录,验证目标平台启动的操作系统OS和/或虚拟机监视器VMM的版本是否为预定版本,根据验证结果确定所述目标平台的安全性。
  8. 根据权利要求1所述的方法,其中,所述可验证启动芯片包括可信平台模块TPM芯片、可信密码模块TCM芯片、可信平台控制模块TPCM芯片、Titan芯片中的一种。
  9. 根据权利要求1所述的方法,还包括,在启动第一用户应用程序之后:
    基于可信执行环境启动第二用户应用程序,
    由所述验证代理程序基于可信执行环境中的本地验证,确定所述第二用户应用程序对应的第二验证信息。
  10. 根据权利要求1所述的方法,其中,所述多个系统启动项中的首个启动项为可信度量根核心CRTM。
  11. 根据权利要求10所述的方法,其中,所述多个系统启动项还包括,引导加载程序BootLoader、操作系统OS、虚拟机监视器VMM中的若干项。
  12. 根据权利要求1所述的方法,其中,验证代理程序至少包括可信部分;
    所述启动验证代理程序,至少包括,在可信执行环境中执行所述可信部分;
    所述多个系统启动项中最后一项的启动,包括,对于所述可信部分进行度量,并将度量结果记录到可验证启动芯片中。
  13. 根据权利要求1所述的方法,其中,第一用户应用程序至少包括可信部分;
    基于可信执行环境启动第一用户应用程序,至少包括,在可信执行环境中执行所述可信部分;
    所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序的第一验证信息,包括,
    所述验证代理程序基于可信执行环境中的本地验证,根据所述可信部分,确定第一用户应用程序对应的第一验证信息。
  14. 根据权利要求1所述的方法,所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序对应的第一验证信息,包括,验证代理程序调用软件保护扩展SGX的本地验证指令,得到第一用户应用程序对应的第一验证信息。
  15. 一种在目标平台上启动应用程序的装置,所述目标平台至少包含可验证启动芯片和可信执行环境,所述装置包括:
    系统启动单元,配置为,按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;
    验证代理启动单元,配置为,基于可信执行环境启动验证代理程序;
    用户应用启动单元,配置为,基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
  16. 一种计算机可读存储介质,其上存储有计算机程序,当所述计算机程序在计算机 中执行时,令计算机执行权利要求1-14中任一项的所述的方法。
  17. 一种计算设备,包括存储器和处理器,其特征在于,所述存储器中存储有可执行代码,所述处理器执行所述可执行代码时,实现权利要求1-14中任一项所述的方法。
PCT/CN2022/073725 2021-02-09 2022-01-25 在目标平台上启动应用程序的方法及装置 Ceased WO2022170966A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US18/276,542 US12524547B2 (en) 2021-02-09 2022-01-25 Methods and apparatuses for starting application on target platform
EP22752127.5A EP4293507B1 (en) 2021-02-09 2022-01-25 Methods and apparatuses for starting application on target platform

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110176522.7 2021-02-09
CN202110176522.7A CN112988262B (zh) 2021-02-09 2021-02-09 一种在目标平台上启动应用程序的方法及装置

Publications (1)

Publication Number Publication Date
WO2022170966A1 true WO2022170966A1 (zh) 2022-08-18

Family

ID=76392508

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/073725 Ceased WO2022170966A1 (zh) 2021-02-09 2022-01-25 在目标平台上启动应用程序的方法及装置

Country Status (4)

Country Link
US (1) US12524547B2 (zh)
EP (1) EP4293507B1 (zh)
CN (2) CN115237495B (zh)
WO (1) WO2022170966A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4571550A4 (en) * 2022-10-27 2025-12-17 Huawei Tech Co Ltd SECURE PRIMING METHOD AND APPARATUS, AND DEVICE

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115237495B (zh) 2021-02-09 2025-09-16 支付宝(杭州)信息技术有限公司 一种在目标平台上启动应用程序的方法及装置
GB2615137B (en) * 2022-02-01 2024-06-05 Trustonic Ltd Trusted execution environment side-channel protection method
CN120277680B (zh) * 2025-06-06 2025-09-05 南湖实验室 一种基于可信执行环境的隐私测控方法和系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102332070A (zh) * 2011-09-30 2012-01-25 中国人民解放军海军计算技术研究所 一种可信计算平台的信任链传递方法
US20150188944A1 (en) * 2013-12-27 2015-07-02 Trapezoid, Inc. System and method for hardware-based trust control management
CN107533609A (zh) * 2015-05-29 2018-01-02 英特尔公司 用于对系统中的多个可信执行环境进行控制的系统、设备和方法
CN112329005A (zh) * 2020-11-06 2021-02-05 中国电子信息产业集团有限公司 操作系统启动的引导度量方法、装置、电子设备和介质
CN112988262A (zh) * 2021-02-09 2021-06-18 支付宝(杭州)信息技术有限公司 一种在目标平台上启动应用程序的方法及装置

Family Cites Families (27)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5038396B2 (ja) * 2006-04-21 2012-10-03 インターデイジタル テクノロジー コーポレーション トラステッドコンピューティングの完全性測定の通知を実行する装置および方法
US8151262B2 (en) * 2007-03-30 2012-04-03 Lenovo (Singapore) Pte. Ltd. System and method for reporting the trusted state of a virtual machine
WO2009154526A1 (en) * 2008-06-19 2009-12-23 Telefonaktiebolaget Lm Ericsson (Publ) A method and a device for protecting private content
GB2466071B (en) * 2008-12-15 2013-11-13 Hewlett Packard Development Co Associating a signing key with a software component of a computing platform
US8176336B1 (en) * 2008-12-19 2012-05-08 Emc Corporation Software trusted computing base
CN102986163B (zh) * 2010-03-05 2015-11-25 交互数字专利控股公司 给设备提供安全性的方法和装置
US9372984B2 (en) * 2011-09-30 2016-06-21 Intel Corporation Authenticated launch of virtual machines and nested virtual machine managers
US9367688B2 (en) * 2012-06-22 2016-06-14 Intel Corporation Providing geographic protection to a system
US10305893B2 (en) * 2013-12-27 2019-05-28 Trapezoid, Inc. System and method for hardware-based trust control management
US9536094B2 (en) * 2014-01-13 2017-01-03 Raytheon Company Mediated secure boot for single or multicore processors
CN104936030B (zh) * 2014-03-20 2019-06-14 海信集团有限公司 一种开机画面显示方法、设备以及组合终端系统
FR3024915B1 (fr) * 2014-08-18 2016-09-09 Proton World Int Nv Dispositif et procede pour assurer des services de module de plateforme securisee
US20170364685A1 (en) * 2014-11-20 2017-12-21 Interdigital Patent Holdings. Inc. Providing security to computing systems
US10248791B2 (en) * 2015-07-20 2019-04-02 Intel Corporation Technologies for secure hardware and software attestation for trusted I/O
US10402566B2 (en) * 2016-08-01 2019-09-03 The Aerospace Corporation High assurance configuration security processor (HACSP) for computing devices
CN107870788B (zh) * 2016-09-26 2020-10-02 展讯通信(上海)有限公司 多可信执行环境下终端设备的启动方法和终端设备
US10341321B2 (en) * 2016-10-17 2019-07-02 Mocana Corporation System and method for policy based adaptive application capability management and device attestation
US11126699B2 (en) * 2018-02-07 2021-09-21 Nec Corporation Replica trusted execution environment: enabling seamless replication of trusted execution environment (TEE)-based enclaves in the cloud
CN108399339B (zh) * 2018-02-12 2021-09-14 广东为辰信息科技有限公司 一种基于安全芯片的可信启动方法
US10185595B1 (en) * 2018-06-04 2019-01-22 Confia Systems, Inc. Program verification using hash chains
US10742421B1 (en) * 2019-03-08 2020-08-11 Ares Technologies, Inc. Methods and systems for anonymous hardware attestation
SG11201908946PA (en) 2019-03-26 2019-10-30 Alibaba Group Holding Ltd Program execution and data proof scheme using multiple key pair signatures
WO2021028971A1 (ja) * 2019-08-09 2021-02-18 日本電気株式会社 バックドア検査装置、システム、方法、及び非一時的なコンピュータ可読媒体
US11741439B2 (en) * 2020-01-21 2023-08-29 National Currency Technologies, Inc. Blockchain-based transaction mechanisms
CN111651740B (zh) * 2020-05-26 2023-04-07 西安电子科技大学 一种面向分布式智能嵌入式系统的可信平台共享系统
CN111950014A (zh) * 2020-08-27 2020-11-17 英业达科技有限公司 服务器系统启动的安全度量方法、安全度量装置及服务器
CN111770201B (zh) * 2020-08-31 2020-12-04 支付宝(杭州)信息技术有限公司 一种数据验证方法、装置及设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102332070A (zh) * 2011-09-30 2012-01-25 中国人民解放军海军计算技术研究所 一种可信计算平台的信任链传递方法
US20150188944A1 (en) * 2013-12-27 2015-07-02 Trapezoid, Inc. System and method for hardware-based trust control management
CN107533609A (zh) * 2015-05-29 2018-01-02 英特尔公司 用于对系统中的多个可信执行环境进行控制的系统、设备和方法
CN112329005A (zh) * 2020-11-06 2021-02-05 中国电子信息产业集团有限公司 操作系统启动的引导度量方法、装置、电子设备和介质
CN112988262A (zh) * 2021-02-09 2021-06-18 支付宝(杭州)信息技术有限公司 一种在目标平台上启动应用程序的方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4293507A4 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4571550A4 (en) * 2022-10-27 2025-12-17 Huawei Tech Co Ltd SECURE PRIMING METHOD AND APPARATUS, AND DEVICE

Also Published As

Publication number Publication date
CN115237495B (zh) 2025-09-16
CN115237495A (zh) 2022-10-25
US12524547B2 (en) 2026-01-13
US20240095362A1 (en) 2024-03-21
CN112988262B (zh) 2022-06-07
EP4293507A4 (en) 2024-11-06
EP4293507B1 (en) 2026-03-11
CN112988262A (zh) 2021-06-18
EP4293507A1 (en) 2023-12-20

Similar Documents

Publication Publication Date Title
US11645390B2 (en) Cloud-based method to increase integrity of a next generation antivirus (NGAV) security solution in a virtualized computing environment
CN109669734B (zh) 用于启动设备的方法和装置
US8583908B2 (en) Enhanced network and local boot of Unified Extensible Firmware Interface images
US10740468B2 (en) Multiple roots of trust to verify integrity
CN105468978B (zh) 一种适用于电力系统通用计算平台的可信计算密码平台
US9690498B2 (en) Protected mode for securing computing devices
US7739517B2 (en) Hardware-based authentication of a software program
CN103718165B (zh) Bios闪存攻击保护和通知
US9288155B2 (en) Computer system and virtual computer management method
CN112988262B (zh) 一种在目标平台上启动应用程序的方法及装置
CN110334515B (zh) 一种基于可信计算平台生成度量报告的方法及装置
TWI745629B (zh) 電腦系統以及初始化電腦系統的方法
JP2005535005A (ja) 安全な環境を初期化する命令を実行するシステムおよび方法
KR20140016280A (ko) 운영 체제 구성 값 보호
CN113906424B (zh) 用于磁盘认证的装置和方法
US20080163212A1 (en) Paralleled management mode integrity checks
CN112818327A (zh) 基于TrustZone的用户级代码和数据安全可信保护方法及装置
WO2020114342A1 (zh) 内核安全检测方法、装置、设备及存储介质
JP2010182196A (ja) 情報処理装置およびファイル検証システム
CN113641463A (zh) 虚拟化系统可信认证方法、系统及计算机可读存储介质
CN107924440A (zh) 安全计算环境
CN105308610A (zh) 用于设备上的平台和用户应用安全性的方法和系统
Dimitrov Hardware rooted security in industry 4.0 systems
US11416604B2 (en) Enclave handling on an execution platform
WO2026036803A1 (zh) 文件访问方法与电子设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22752127

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 18276542

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2022752127

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2022752127

Country of ref document: EP

Effective date: 20230911

WWE Wipo information: entry into national phase

Ref document number: 11202305964X

Country of ref document: SG

WWG Wipo information: grant in national office

Ref document number: 18276542

Country of ref document: US

WWG Wipo information: grant in national office

Ref document number: 2022752127

Country of ref document: EP