WO2022170966A1 - 在目标平台上启动应用程序的方法及装置 - Google Patents
在目标平台上启动应用程序的方法及装置 Download PDFInfo
- Publication number
- WO2022170966A1 WO2022170966A1 PCT/CN2022/073725 CN2022073725W WO2022170966A1 WO 2022170966 A1 WO2022170966 A1 WO 2022170966A1 CN 2022073725 W CN2022073725 W CN 2022073725W WO 2022170966 A1 WO2022170966 A1 WO 2022170966A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- verification
- startup
- execution environment
- trusted
- chip
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/575—Secure boot
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/445—Program loading or initiating
- G06F9/44505—Configuring for program initiating, e.g. using registry, configuration files
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/51—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/4401—Bootstrapping
Definitions
- One or more embodiments of this specification relate to the field of data security, and in particular, to a method and apparatus for launching an application on a target platform.
- the embodiments in this specification aim to provide a method for more effectively guaranteeing the code/data of the program on the computing platform, and solve the deficiencies in the prior art.
- a method for starting an application program on a target platform comprising: sequentially starting multiple systems according to a preset starting sequence Item, wherein the startup of the first startup item included in the multiple system startup items includes measuring the next startup item and recording the measurement result in the verifiable startup chip; starting the verification agent based on the trusted execution environment A program; starting a first user application program based on a trusted execution environment, and determining the first verification information corresponding to the first user application program by the verification agent program based on local verification in the trusted execution environment.
- the method further includes recording the first verification information into the verifiable boot chip.
- the method further includes, in response to an access request by a remote user of the target platform to the verifiable boot chip, providing the remote user with a verifiable boot chip generated according to the first verification information the first record; enabling the remote user to determine the security of the first user application and/or the security of the target platform according to the first record.
- the first verification information is maintained by the verification agent; the method further comprises, in response to a remote user requesting access to the verifiable boot chip, providing a second record to the remote user , the second record is generated by the verifiable bootable chip according to the first measurement result recorded when the tail boot item in the plurality of system boot items is booted; the verification agent program responds to the remote user based on the first measurement result.
- the connection request of the measurement result establishes a trust channel with the remote user, and provides the first verification information to the remote user through the trust channel.
- the second record is used by the remote user to determine the security of the target platform according to the second record.
- the first verification information is used by the remote user to determine the security of the first user application program according to the first verification information.
- determining the security of the target platform according to the second record includes, according to the second record, verifying whether the version of the operating system OS and/or the virtual machine monitor VMM started by the target platform is a predetermined version, The security of the target platform is determined according to the verification result.
- the verifiable boot chip includes one of a trusted platform module TPM chip, a trusted password module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
- the method further includes, after starting the first user application: starting the second user application based on the trusted execution environment, and the authentication agent program based on local authentication in the trusted execution environment, Second verification information corresponding to the second user application is determined.
- the first activation item among the plurality of system activation items is a trusted metric root core CRTM.
- the plurality of system startup items further include several items of a boot loader BootLoader, an operating system OS, and a virtual machine monitor VMM.
- the verification agent program includes at least a trusted part; the startup of the verification agent program includes at least executing the trusted part in a trusted execution environment; The startup includes measuring the trusted part and recording the measurement result in the verifiable startup chip.
- the first user application program includes at least a trusted part; starting the first user application program based on the trusted execution environment includes at least executing the trusted part in the trusted execution environment; the verification agent program Determining the first verification information of the first user application based on the local verification in the trusted execution environment includes, the verification agent determining the first user according to the trusted part based on the local verification in the trusted execution environment The first verification information corresponding to the application.
- the verification agent program determines the first verification information corresponding to the first user application based on the local verification in the trusted execution environment, including: the verification agent program invokes the local verification instruction of the software protection extension SGX to obtain The first verification information corresponding to the first user application.
- an apparatus for starting an application program on a target platform wherein the target platform at least includes a verifiable boot chip and a trusted execution environment, and the apparatus includes: a system boot unit configured to, according to a preset The startup sequence starts multiple system startup items in turn, wherein the startup of the first startup item included in the multiple system startup items includes measuring the next startup item, and recording the measurement result in the verifiable startup chip
- a verification agent startup unit configured to start a verification agent program based on a trusted execution environment
- a user application startup unit configured to start a first user application program based on a trusted execution environment, and the verification agent program based on the trusted execution environment.
- the local verification in the environment determines the first verification information corresponding to the first user application.
- a computer-readable storage medium on which a computer program is stored, and when the computer program is executed in a computer, the computer is caused to perform the method of the first aspect.
- a computing device comprising a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, the first described method.
- FIG. 1 shows a schematic diagram of the principle of a method for starting an application program on a target platform according to an embodiment of the present specification
- FIG. 2 shows a flowchart of a method for starting an application on a target platform according to an embodiment of the present specification
- FIG. 3 shows a flowchart of an implementation manner of a method for launching an application program on a target platform according to an embodiment of the present specification
- FIG. 4 shows a flowchart of still another implementation manner of a method for launching an application program on a target platform according to an embodiment of the present specification
- FIG. 5 shows a structural diagram of an apparatus for starting an application program on a target platform according to an embodiment of the present specification
- the commonly used security methods for the code/data of the program on the computing platform mainly include the verifiable startup-based scheme and the trusted execution environment-based scheme.
- the verifiable startup refers to a system startup process with step-by-step integrity verification.
- the principle based on the verifiable boot scheme is that the system starts from the root of trust and starts to the user program step by step, and each boot step measures and checks the next boot item, and writes the trusted record in the verifiable boot chip. .
- TPM Trusted Platform Module
- the hash value of the next startup item is written into the platform configuration register PCR in the TPM chip.
- the user can remotely retrieve the boot trusted record (the record will be signed to ensure integrity and authenticity) to determine whether the system maintains the expected boot items and boot sequence.
- the disadvantage of verifiable startup is that it can only guarantee the security at startup. If it is a dynamic attack completed after startup, this scheme is difficult to detect and resist.
- a trusted execution environment refers to an encrypted or isolated execution environment that is considered secure and trusted, so that code and data in an encrypted or isolated environment are not vulnerable to attacks from outside the environment.
- the principle of the scheme based on the Trusted Execution Environment (TEE) is to exclude the high-privileged operating system OS or Virtual Machine Monitor (VMM) from the Trusted Computing Base (TCB for short) ), allowing users to safely run the code and data that needs to be protected on an untrusted operating system or VMM, and provide the ability for remote verification.
- TEE-based scheme is that it only defends against direct attacks from malicious operating systems or VMMs, but cannot defend against side-channel attacks.
- the solutions based on the trusted execution environment rely more or less on the remote verification services provided by third-party manufacturers, resulting in external availability (Availability) dependencies, and it is also necessary to assume that these third-party manufacturers will not do evil (for example, assuming that no collusion occurs. Attack a Collusion Attack or an Insider Attack).
- Availability external availability
- the inventor proposes a method and an apparatus for starting an application program on a target platform in the embodiments of this specification.
- the trusted logic of the user application is placed in a trusted execution environment for isolated execution, thereby preventing direct (non-side-channel) attacks by malicious VMM/OS; on the other hand, the user is verifying the program
- the verification information of the boot chain and the platform can be obtained at the same time, so as to verify that the booted VMM/operating system is in the expected state (for example, a credible version with a small TCB and with side-channel attack monitoring), which improves the Defense against side-channel attacks.
- program verification is based on the combination of verifiable startup and local verification, and does not need to rely on external trusted execution environment verification services such as IAS, which greatly improves the reliability and security of program verification.
- FIG. 1 shows a schematic diagram of the principle of a method for starting an application program on a target platform according to an embodiment of the present specification.
- the target platform at least includes a verifiable boot chip, a trusted execution environment, and multiple boot items
- the multiple boot items include multiple system boot items in the boot order (as shown in Figure 1, CRTM, Bootloader/ OS, the first system startup item is Trusted Metrics Root Core (CRTM), authentication agent, several user applications (User Application 1, User Application 2).
- CRTM Trusted Metrics Root Core
- authentication agent or its trusted part
- the verification agent program obtains the verification information corresponding to the user application program at least by invoking the local verification in the trusted execution environment.
- the verification agent program can maintain the verification information corresponding to the user application program, and can also record it. into the verifiable boot chip.
- Using this method to start the application on the target platform and execute the user application in the trusted execution environment can prevent attacks from malicious VMM/operating systems, and, in the authentication of the application in the trusted execution environment, through the authentication agent
- the program calls local verification, and no longer relies on the external trusted execution environment verification service.
- FIG. 2 shows a flowchart of a method for launching an application program on a target platform according to an embodiment of the present specification.
- the target platform at least includes a verifiable boot chip and a trusted execution environment, and the method at least includes the following steps.
- step 21 start a plurality of system startup items in sequence according to a preset startup order, wherein, the startup of the first startup item included in the plurality of system startup items includes measuring the next startup item thereof, and measuring the result of the measurement. Recorded to the Verifiable Boot Chip.
- verifiable startup refers to the system startup process with step-by-step integrity verification. Relying on an independent verifiable boot chip implementation.
- the verifiable boot chip may use different types of verifiable boot chips, and this specification does not limit the specific use of the verifiable boot chip.
- the verifiable boot chip may include one of a trusted platform module TPM chip, a trusted cryptographic module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
- the measurement of the launch item may include a summary, characterization or identification of the content of the launch item.
- the next startup item may be hashed to obtain its metrics.
- the hash calculation result of the next startup item can also be performed after hash expansion to obtain the measurement result for recording.
- hash expansion refers to the process of performing more than one nested hash operation based on the hash calculation result obtained first and the added calculation item to obtain the calculation result.
- the system startup sequence is shown in FIG. 1 .
- the Trusted Measurement Root Core (CRTM, Core Root of Trust Measurement) is the initial startup component of the target platform and is also the trusted source of the entire system. foundation. After CRTM starts, it will start the next startup item (eg, basic input output system BIOS), and then BIOS will start further startup items (eg, bootloader Bootloader, VMM, operating system, etc.), and so on, until the user mode program is started. .
- BIOS basic input output system BIOS
- CRTM will measure the next boot item (such as BIOS) after booting, and then BIOS will measure further boot items (such as Bootloader) , until the measurement reaches the user-mode program.
- BIOS the next boot item
- BIOS the next boot item
- BIOS the next boot item
- BIOS the next boot item
- BIOS the next boot item
- BIOS the further boot items
- Each measurement result is written to the corresponding trusted record (in the verifiable chip), which can be later shown to the remote user.
- the first activation item among the plurality of system activation items is the Root of Trust Metrics Core CRTM.
- the plurality of system startup items may further include several items of a boot loader BootLoader, an operating system OS, and a virtual machine monitor VMM.
- a dynamic CRTM (D-CRTM, Dynamic CRTM) scheme may also be adopted.
- D-CRTM Dynamic CRTM
- the BIOS starts up before the D-CRTM, and the dynamic startup event DL is triggered during the BIOS startup.
- Event dynamic launch event
- the verification agent program in the startup of the last system startup item, is measured, and the measurement result is recorded in the verifiable startup chip. Details of this embodiment will be set forth later in this specification.
- the authentication agent is started based on the trusted execution environment.
- a Trusted Execution Environment a secure enclave in the main processor (CPU), acts as an isolated execution environment that ensures that the code and data loaded inside are protected in terms of confidentiality and integrity.
- TEEs provide the integrity of applications executed through TEE isolation and the confidentiality of their resources.
- a TEE provides an execution space that provides a higher level of security than the operating system (OS) for trusted applications running on the device.
- OS operating system
- TEEs may be implemented on different host processors, and implementing TEEs on different host processors has different specific implementations. For example, implement the SGX scheme of TEE on a certain CPU, implement the TrustZone scheme of TEE on another CPU, and so on. This specification does not limit the specific implementation of the TEE.
- an authentication agent is started before the user program Apps.
- the authentication agent runs by means of the trusted execution environment technology like the user program Apps to be started in the future.
- the trusted portion of the authentication agent (Trusted Logic) can be loaded into the trusted execution environment to isolate cryptographic execution.
- the difference from the conventional verifiable startup mode is that the conventional verifiable startup mode is measured by directly entering the user program Apps during the startup process of the system startup item.
- the verification agent program is measured and the measurement result is recorded in the verifiable bootable chip. That is to say, the last measurement of the system item and the object that records the result are different.
- the authentication agent may include at least a trusted portion.
- the specific implementation may be to measure the trusted part, and record the measurement result in the verifiable activation chip.
- step 23 the first user application is started based on the trusted execution environment, and the verification agent program determines the first verification information corresponding to the first user application based on the local verification in the trusted execution environment.
- the user application program started after the verification agent program obtains its verification information by at least invoking the local verification in the trusted execution environment by the verification agent program.
- the SGX Local Attestation can be called on the SGX platform to obtain the authentication information of the application.
- the verification agent program can also perform extended calculation after superimposing other data items on the basis of the information obtained by invoking the local verification in the trusted execution environment to verify the user program, for example, after hash extended calculation, obtain Authentication information for the application.
- the authentication agent and the user application run in the TEE on the same target platform, the authentication agent can authenticate the user application by calling the local authentication (Local Attestation) in the TEE without avoiding the With the help of third-party remote verification.
- the first user application may include at least a trusted part; the trusted part is executed in a trusted execution environment; the authentication agent is based on local authentication in the trusted execution environment, according to the first user
- the trusted part of the application program determines the corresponding first verification information.
- the verification agent program can invoke the local verification instruction of the software protection extension SGX to obtain the first verification information corresponding to the first user application.
- a second user application may be started based on a trusted execution environment, and the verification agent program determines the second user application based on local verification in the trusted execution environment.
- Second verification information corresponding to the user application. That is to say, for each user application program started after the authentication agent program is started, the authentication agent program determines its authentication information based on the local authentication in the TEE. This is again different from verifiable boot, where the next boot program is verified in sequence in a chain.
- the verification information corresponding to the user application program may be written into the verifiable boot chip, or may not be written into the chip, but only maintained by the verification agent program, so that the above boot program can be remotely verified users provide different remote verification methods.
- the first verification information may be recorded in the verifiable boot chip.
- the user can send an access request to the verifiable boot chip in the target platform.
- the target platform may provide the remote user with a first record generated by the verifiable boot chip according to the first verification information. In this way, the remote user can determine the security of the first user application and/or the security of the target platform according to the first record.
- the remote user can build the same operating environment as the target platform on his own platform according to the program version number of the startup item on the target platform, and obtain the corresponding value of the first record accordingly , according to the corresponding value of the first record and the first record, determine the security of each startup item (including the system startup item and the user application program startup item) on the target platform startup chain.
- the corresponding value of the first record matches the first record, it means that each startup item on the startup chain of the target platform is complete and correct, that is to say, the target platform and the applications started on it are both complete and correct. It is safe; if the corresponding value of the first record does not match the first record, it means that at least one of the startup items on the target platform startup chain is incomplete or incorrect, that is, the target platform and the startup on it One or more of the applications are unsafe.
- the remote user can also obtain the corresponding value of the first record from, for example, a trusted third party, and the rest of the execution process is the same as the corresponding part of the execution process in the previous example, and details are not repeated here. .
- the first verification information may be maintained by the verification agent.
- the user when a remote user of the target platform wishes to remotely verify the security of the target platform, the user can still issue an access request to the verifiable boot chip in the target platform.
- the target platform provides the remote user with a second record, where the second record is the first measurement result recorded when the verifiable boot chip is booted according to the tail boot item of the plurality of system boot items generate.
- the tail startup item is the last system startup item, and the program started after it is the verification agent program. Therefore, the first measurement result recorded when the tail startup item is started corresponds to the measurement result of the verification agent program.
- the remote user can issue a connection request to the authentication agent based on the first measurement result.
- the authentication agent may establish a trusted channel with the remote user, and provide it with the first authentication information through the trusted channel.
- the first authentication information may be used by the remote user to determine the security of the first user application program according to the first authentication information.
- the second record may be used by the first remote user to determine the security of the target platform according to the second record.
- the second record can be used by the first remote user to verify whether the version of the operating system OS and/or virtual machine monitor VMM started by the target platform is a predetermined version according to the second record, and determine the Describe the security of the target platform.
- the remote user can build the same operating environment as the target platform on his own platform according to the program version numbers of each startup item on the target platform, so as to obtain the correspondence between the second record and the first verification information on his own platform value, according to the corresponding value of the second record and the second record, determine the security of the on-chain system startup item and the verification agent program on the target platform.
- the corresponding value of the second record matches the second record, it can be determined that each system startup item and the verification agent program on the startup chain on the target platform are complete and correct, that is to say, the target platform can be determined The system on which the platform runs is secure.
- the integrity and correctness of the first user application can also be determined according to the corresponding value of the first verification information and the first verification information. If the corresponding value of the first verification information and the first verification information If they match, it can be determined that the first user application is safe.
- the remote user can also obtain the corresponding values of the second record and the first verification information from, for example, a trusted third party, and the rest of the execution process is the same as the corresponding part of the execution process in the previous example, which will not be repeated here. .
- FIG. 5 shows a structural diagram of an apparatus for launching an application program on a target platform according to an embodiment of the present specification.
- the target platform at least includes a verifiable boot chip and a trusted execution environment.
- the apparatus 500 includes: a system boot unit 51, configured to sequentially boot multiple system boot items according to a preset boot sequence, wherein, for The startup of the first startup item included in the plurality of system startup items includes measuring its next startup item, and recording the measurement result in the verifiable startup chip; the verification agent startup unit 52 is configured to perform a trusted execution based on The environment starts the verification agent program; the user application startup unit 53 is configured to start the first user application program based on the trusted execution environment, and the verification agent program determines the first user based on the local verification in the trusted execution environment The first verification information corresponding to the application.
- the apparatus 500 may further include a recording unit configured to record the first verification information into the verifiable boot chip.
- the apparatus 500 may further include a first response unit configured to, in response to a request for accessing the verifiable boot chip by a remote user of the target platform, provide a verifiable boot chip to the remote user A first record generated according to the first verification information; enabling the remote user to determine the security of the first user's application program and/or the security of the target platform according to the first record.
- a first response unit configured to, in response to a request for accessing the verifiable boot chip by a remote user of the target platform, provide a verifiable boot chip to the remote user A first record generated according to the first verification information; enabling the remote user to determine the security of the first user's application program and/or the security of the target platform according to the first record.
- the user application launching unit 53 may be further configured to maintain the first authentication information by the authentication agent; the apparatus 500 may further include a second response unit configured to respond to the remote user For the access request to the verifiable boot chip, a second record is provided to the remote user, and the second record is the first record recorded when the verifiable boot chip is activated according to the tail boot item in the plurality of system boot items.
- a measurement result is generated; the third response unit is configured to, in response to the connection request of the remote user based on the first measurement result, the verification agent program establishes a trust channel with the remote user, and sends a message to the remote user through the trust channel. It provides the first verification information.
- the second record is used by the remote user to determine the security of the target platform according to the second record.
- the first verification information may be used by the remote user to determine the security of the first user application program according to the first verification information.
- the second response unit may be further configured to, according to the second record, determine the security of the target platform, including, according to the second record, verifying whether the version of the operating system OS and/or the virtual machine monitor VMM started by the target platform is For a predetermined version, the security of the target platform is determined according to the verification result.
- the verifiable boot chip may include one of a trusted platform module TPM chip, a trusted cryptographic module TCM chip, a trusted platform control module TPCM chip, and a Titan chip.
- the user application starting unit may be further configured to, after starting the first user application: start the second user application based on the trusted execution environment, and the user application starting unit may be further configured to:
- the verification agent program determines the second verification information corresponding to the second user application based on the local verification in the trusted execution environment.
- the first activation item among the plurality of system activation items may be the Root of Trust Metrics Core CRTM.
- the plurality of system startup items may further include several items of the boot loader BootLoader, the operating system OS, and the virtual machine monitor VMM.
- the verification agent program may include at least a trusted part; the verification agent startup unit may be further configured to execute the trusted part in a trusted execution environment; the system startup unit may be further configured to, for all The trusted part is measured, and the measurement result is recorded in the verifiable boot chip.
- the first user application program includes at least a trusted part; the user application startup unit may be further configured to execute the trusted part in a trusted execution environment; the verification agent program is based on the trusted execution environment In the local verification, the first verification information corresponding to the first user application is determined according to the trusted part.
- the user application startup unit may be further configured to: the authentication agent program invokes the local authentication instruction of the software protection extension SGX to obtain the first authentication information corresponding to the first user application program.
- Another aspect of the present specification provides a computer-readable storage medium on which a computer program is stored, when the computer program is executed in a computer, the computer is made to execute any one of the above methods.
- Another aspect of the present specification provides a computing device, including a memory and a processor, where executable code is stored in the memory, and when the processor executes the executable code, any one of the foregoing methods is implemented.
- the functions described in the present invention may be implemented in hardware, software, firmware, or any combination thereof.
- the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium.
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (17)
- 一种在目标平台上启动应用程序的方法,所述目标平台至少包含可验证启动芯片和可信执行环境,所述方法包括:按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;基于可信执行环境启动验证代理程序;基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
- 根据权利要求1所述的方法,还包括,将第一验证信息记录到可验证启动芯片中。
- 根据权利要求2所述的方法,还包括,响应于所述目标平台的远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供可验证启动芯片根据所述第一验证信息生成的第一记录;使得所述远程用户根据第一记录,确定第一用户应用程序的安全性,和/或,所述目标平台的安全性。
- 根据权利要求1所述的方法,其中,所述第一验证信息由所述验证代理程序维护;所述方法还包括,响应于远程用户对所述可验证启动芯片的访问请求,向所述远程用户提供第二记录,所述第二记录为可验证启动芯片根据所述多个系统启动项中的尾启动项启动时所记录的第一度量结果生成;所述验证代理程序响应于所述远程用户基于第一度量结果的连接请求,建立与该远程用户的信任通道,通过所述信任通道向其提供所述第一验证信息。
- 根据权利要求4所述的方法,其中,所述第二记录用于远程用户根据第二记录,确定所述目标平台的安全性。
- 根据权利要求4所述的方法,其中,所述第一验证信息用于远程用户根据第一验证信息,确定第一用户应用程序的安全性。
- 根据权利要求5所述的方法,其中,根据第二记录,确定所述目标平台的安全性,包括,根据第二记录,验证目标平台启动的操作系统OS和/或虚拟机监视器VMM的版本是否为预定版本,根据验证结果确定所述目标平台的安全性。
- 根据权利要求1所述的方法,其中,所述可验证启动芯片包括可信平台模块TPM芯片、可信密码模块TCM芯片、可信平台控制模块TPCM芯片、Titan芯片中的一种。
- 根据权利要求1所述的方法,还包括,在启动第一用户应用程序之后:基于可信执行环境启动第二用户应用程序,由所述验证代理程序基于可信执行环境中的本地验证,确定所述第二用户应用程序对应的第二验证信息。
- 根据权利要求1所述的方法,其中,所述多个系统启动项中的首个启动项为可信度量根核心CRTM。
- 根据权利要求10所述的方法,其中,所述多个系统启动项还包括,引导加载程序BootLoader、操作系统OS、虚拟机监视器VMM中的若干项。
- 根据权利要求1所述的方法,其中,验证代理程序至少包括可信部分;所述启动验证代理程序,至少包括,在可信执行环境中执行所述可信部分;所述多个系统启动项中最后一项的启动,包括,对于所述可信部分进行度量,并将度量结果记录到可验证启动芯片中。
- 根据权利要求1所述的方法,其中,第一用户应用程序至少包括可信部分;基于可信执行环境启动第一用户应用程序,至少包括,在可信执行环境中执行所述可信部分;所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序的第一验证信息,包括,所述验证代理程序基于可信执行环境中的本地验证,根据所述可信部分,确定第一用户应用程序对应的第一验证信息。
- 根据权利要求1所述的方法,所述验证代理程序基于可信执行环境中的本地验证,确定第一用户应用程序对应的第一验证信息,包括,验证代理程序调用软件保护扩展SGX的本地验证指令,得到第一用户应用程序对应的第一验证信息。
- 一种在目标平台上启动应用程序的装置,所述目标平台至少包含可验证启动芯片和可信执行环境,所述装置包括:系统启动单元,配置为,按预设的启动次序依次启动多个系统启动项,其中,对于多个系统启动项中包含的第一启动项的启动包括,对于其下一个启动项进行度量,并将度量结果记录到可验证启动芯片中;验证代理启动单元,配置为,基于可信执行环境启动验证代理程序;用户应用启动单元,配置为,基于可信执行环境启动第一用户应用程序,并由所述验证代理程序基于可信执行环境中的本地验证,确定所述第一用户应用程序对应的第一验证信息。
- 一种计算机可读存储介质,其上存储有计算机程序,当所述计算机程序在计算机 中执行时,令计算机执行权利要求1-14中任一项的所述的方法。
- 一种计算设备,包括存储器和处理器,其特征在于,所述存储器中存储有可执行代码,所述处理器执行所述可执行代码时,实现权利要求1-14中任一项所述的方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/276,542 US12524547B2 (en) | 2021-02-09 | 2022-01-25 | Methods and apparatuses for starting application on target platform |
| EP22752127.5A EP4293507B1 (en) | 2021-02-09 | 2022-01-25 | Methods and apparatuses for starting application on target platform |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110176522.7 | 2021-02-09 | ||
| CN202110176522.7A CN112988262B (zh) | 2021-02-09 | 2021-02-09 | 一种在目标平台上启动应用程序的方法及装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022170966A1 true WO2022170966A1 (zh) | 2022-08-18 |
Family
ID=76392508
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/073725 Ceased WO2022170966A1 (zh) | 2021-02-09 | 2022-01-25 | 在目标平台上启动应用程序的方法及装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12524547B2 (zh) |
| EP (1) | EP4293507B1 (zh) |
| CN (2) | CN115237495B (zh) |
| WO (1) | WO2022170966A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP4571550A4 (en) * | 2022-10-27 | 2025-12-17 | Huawei Tech Co Ltd | SECURE PRIMING METHOD AND APPARATUS, AND DEVICE |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115237495B (zh) | 2021-02-09 | 2025-09-16 | 支付宝(杭州)信息技术有限公司 | 一种在目标平台上启动应用程序的方法及装置 |
| GB2615137B (en) * | 2022-02-01 | 2024-06-05 | Trustonic Ltd | Trusted execution environment side-channel protection method |
| CN120277680B (zh) * | 2025-06-06 | 2025-09-05 | 南湖实验室 | 一种基于可信执行环境的隐私测控方法和系统 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102332070A (zh) * | 2011-09-30 | 2012-01-25 | 中国人民解放军海军计算技术研究所 | 一种可信计算平台的信任链传递方法 |
| US20150188944A1 (en) * | 2013-12-27 | 2015-07-02 | Trapezoid, Inc. | System and method for hardware-based trust control management |
| CN107533609A (zh) * | 2015-05-29 | 2018-01-02 | 英特尔公司 | 用于对系统中的多个可信执行环境进行控制的系统、设备和方法 |
| CN112329005A (zh) * | 2020-11-06 | 2021-02-05 | 中国电子信息产业集团有限公司 | 操作系统启动的引导度量方法、装置、电子设备和介质 |
| CN112988262A (zh) * | 2021-02-09 | 2021-06-18 | 支付宝(杭州)信息技术有限公司 | 一种在目标平台上启动应用程序的方法及装置 |
Family Cites Families (27)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP5038396B2 (ja) * | 2006-04-21 | 2012-10-03 | インターデイジタル テクノロジー コーポレーション | トラステッドコンピューティングの完全性測定の通知を実行する装置および方法 |
| US8151262B2 (en) * | 2007-03-30 | 2012-04-03 | Lenovo (Singapore) Pte. Ltd. | System and method for reporting the trusted state of a virtual machine |
| WO2009154526A1 (en) * | 2008-06-19 | 2009-12-23 | Telefonaktiebolaget Lm Ericsson (Publ) | A method and a device for protecting private content |
| GB2466071B (en) * | 2008-12-15 | 2013-11-13 | Hewlett Packard Development Co | Associating a signing key with a software component of a computing platform |
| US8176336B1 (en) * | 2008-12-19 | 2012-05-08 | Emc Corporation | Software trusted computing base |
| CN102986163B (zh) * | 2010-03-05 | 2015-11-25 | 交互数字专利控股公司 | 给设备提供安全性的方法和装置 |
| US9372984B2 (en) * | 2011-09-30 | 2016-06-21 | Intel Corporation | Authenticated launch of virtual machines and nested virtual machine managers |
| US9367688B2 (en) * | 2012-06-22 | 2016-06-14 | Intel Corporation | Providing geographic protection to a system |
| US10305893B2 (en) * | 2013-12-27 | 2019-05-28 | Trapezoid, Inc. | System and method for hardware-based trust control management |
| US9536094B2 (en) * | 2014-01-13 | 2017-01-03 | Raytheon Company | Mediated secure boot for single or multicore processors |
| CN104936030B (zh) * | 2014-03-20 | 2019-06-14 | 海信集团有限公司 | 一种开机画面显示方法、设备以及组合终端系统 |
| FR3024915B1 (fr) * | 2014-08-18 | 2016-09-09 | Proton World Int Nv | Dispositif et procede pour assurer des services de module de plateforme securisee |
| US20170364685A1 (en) * | 2014-11-20 | 2017-12-21 | Interdigital Patent Holdings. Inc. | Providing security to computing systems |
| US10248791B2 (en) * | 2015-07-20 | 2019-04-02 | Intel Corporation | Technologies for secure hardware and software attestation for trusted I/O |
| US10402566B2 (en) * | 2016-08-01 | 2019-09-03 | The Aerospace Corporation | High assurance configuration security processor (HACSP) for computing devices |
| CN107870788B (zh) * | 2016-09-26 | 2020-10-02 | 展讯通信(上海)有限公司 | 多可信执行环境下终端设备的启动方法和终端设备 |
| US10341321B2 (en) * | 2016-10-17 | 2019-07-02 | Mocana Corporation | System and method for policy based adaptive application capability management and device attestation |
| US11126699B2 (en) * | 2018-02-07 | 2021-09-21 | Nec Corporation | Replica trusted execution environment: enabling seamless replication of trusted execution environment (TEE)-based enclaves in the cloud |
| CN108399339B (zh) * | 2018-02-12 | 2021-09-14 | 广东为辰信息科技有限公司 | 一种基于安全芯片的可信启动方法 |
| US10185595B1 (en) * | 2018-06-04 | 2019-01-22 | Confia Systems, Inc. | Program verification using hash chains |
| US10742421B1 (en) * | 2019-03-08 | 2020-08-11 | Ares Technologies, Inc. | Methods and systems for anonymous hardware attestation |
| SG11201908946PA (en) | 2019-03-26 | 2019-10-30 | Alibaba Group Holding Ltd | Program execution and data proof scheme using multiple key pair signatures |
| WO2021028971A1 (ja) * | 2019-08-09 | 2021-02-18 | 日本電気株式会社 | バックドア検査装置、システム、方法、及び非一時的なコンピュータ可読媒体 |
| US11741439B2 (en) * | 2020-01-21 | 2023-08-29 | National Currency Technologies, Inc. | Blockchain-based transaction mechanisms |
| CN111651740B (zh) * | 2020-05-26 | 2023-04-07 | 西安电子科技大学 | 一种面向分布式智能嵌入式系统的可信平台共享系统 |
| CN111950014A (zh) * | 2020-08-27 | 2020-11-17 | 英业达科技有限公司 | 服务器系统启动的安全度量方法、安全度量装置及服务器 |
| CN111770201B (zh) * | 2020-08-31 | 2020-12-04 | 支付宝(杭州)信息技术有限公司 | 一种数据验证方法、装置及设备 |
-
2021
- 2021-02-09 CN CN202210821939.9A patent/CN115237495B/zh active Active
- 2021-02-09 CN CN202110176522.7A patent/CN112988262B/zh active Active
-
2022
- 2022-01-25 US US18/276,542 patent/US12524547B2/en active Active
- 2022-01-25 EP EP22752127.5A patent/EP4293507B1/en active Active
- 2022-01-25 WO PCT/CN2022/073725 patent/WO2022170966A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102332070A (zh) * | 2011-09-30 | 2012-01-25 | 中国人民解放军海军计算技术研究所 | 一种可信计算平台的信任链传递方法 |
| US20150188944A1 (en) * | 2013-12-27 | 2015-07-02 | Trapezoid, Inc. | System and method for hardware-based trust control management |
| CN107533609A (zh) * | 2015-05-29 | 2018-01-02 | 英特尔公司 | 用于对系统中的多个可信执行环境进行控制的系统、设备和方法 |
| CN112329005A (zh) * | 2020-11-06 | 2021-02-05 | 中国电子信息产业集团有限公司 | 操作系统启动的引导度量方法、装置、电子设备和介质 |
| CN112988262A (zh) * | 2021-02-09 | 2021-06-18 | 支付宝(杭州)信息技术有限公司 | 一种在目标平台上启动应用程序的方法及装置 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4293507A4 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP4571550A4 (en) * | 2022-10-27 | 2025-12-17 | Huawei Tech Co Ltd | SECURE PRIMING METHOD AND APPARATUS, AND DEVICE |
Also Published As
| Publication number | Publication date |
|---|---|
| CN115237495B (zh) | 2025-09-16 |
| CN115237495A (zh) | 2022-10-25 |
| US12524547B2 (en) | 2026-01-13 |
| US20240095362A1 (en) | 2024-03-21 |
| CN112988262B (zh) | 2022-06-07 |
| EP4293507A4 (en) | 2024-11-06 |
| EP4293507B1 (en) | 2026-03-11 |
| CN112988262A (zh) | 2021-06-18 |
| EP4293507A1 (en) | 2023-12-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11645390B2 (en) | Cloud-based method to increase integrity of a next generation antivirus (NGAV) security solution in a virtualized computing environment | |
| CN109669734B (zh) | 用于启动设备的方法和装置 | |
| US8583908B2 (en) | Enhanced network and local boot of Unified Extensible Firmware Interface images | |
| US10740468B2 (en) | Multiple roots of trust to verify integrity | |
| CN105468978B (zh) | 一种适用于电力系统通用计算平台的可信计算密码平台 | |
| US9690498B2 (en) | Protected mode for securing computing devices | |
| US7739517B2 (en) | Hardware-based authentication of a software program | |
| CN103718165B (zh) | Bios闪存攻击保护和通知 | |
| US9288155B2 (en) | Computer system and virtual computer management method | |
| CN112988262B (zh) | 一种在目标平台上启动应用程序的方法及装置 | |
| CN110334515B (zh) | 一种基于可信计算平台生成度量报告的方法及装置 | |
| TWI745629B (zh) | 電腦系統以及初始化電腦系統的方法 | |
| JP2005535005A (ja) | 安全な環境を初期化する命令を実行するシステムおよび方法 | |
| KR20140016280A (ko) | 운영 체제 구성 값 보호 | |
| CN113906424B (zh) | 用于磁盘认证的装置和方法 | |
| US20080163212A1 (en) | Paralleled management mode integrity checks | |
| CN112818327A (zh) | 基于TrustZone的用户级代码和数据安全可信保护方法及装置 | |
| WO2020114342A1 (zh) | 内核安全检测方法、装置、设备及存储介质 | |
| JP2010182196A (ja) | 情報処理装置およびファイル検証システム | |
| CN113641463A (zh) | 虚拟化系统可信认证方法、系统及计算机可读存储介质 | |
| CN107924440A (zh) | 安全计算环境 | |
| CN105308610A (zh) | 用于设备上的平台和用户应用安全性的方法和系统 | |
| Dimitrov | Hardware rooted security in industry 4.0 systems | |
| US11416604B2 (en) | Enclave handling on an execution platform | |
| WO2026036803A1 (zh) | 文件访问方法与电子设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22752127 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18276542 Country of ref document: US |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022752127 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2022752127 Country of ref document: EP Effective date: 20230911 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 11202305964X Country of ref document: SG |
|
| WWG | Wipo information: grant in national office |
Ref document number: 18276542 Country of ref document: US |
|
| WWG | Wipo information: grant in national office |
Ref document number: 2022752127 Country of ref document: EP |