IP Library Granted Patent US 12699767
Granted Patent B2
US 12699767 · App. 18/843,446 · Granted Aug 4, 2026

Virtualization-based trusted computing measurement method and apparatus, device, and storage medium

Inventors: Yufei Mai (Shanghai, CN); Fang Lu (Shanghai, CN); Su Wang (Shanghai, CN)
Assignee: Cloud Intelligence Assets Holding (Singapore) Private Limited
G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12699767
App. No.
18/843,446
Granted
Aug 4, 2026
Kind
B2
Abstract

A virtualization-based trusted computing measurement method and apparatus, a device, and a storage medium. The method comprises: determining an application program to be measured; separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment; determining the credibility of a target virtual image file loaded to the trusted execution environment; and according to the credibility of the target virtual image file, allowing or forbidding an application program corresponding to the target virtual image file to operate in the trusted execution environment. In the embodiments of the present application, fine-grained trusted computing measurement may be performed on the application program, thereby better providing a service on the basis of the fine-grained measurement result.

Claims (41)

1 . A virtualization-based trusted computing measurement method, comprising:

determining an application program to be measured;

separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;

computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;

writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and

allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.

2 . The method according to claim 1 , wherein the target measurement data comprises a code, a configuration file, and an environment variable of the application program.

3 . The method according to claim 1 , wherein allowing or forbidding, according to the credibility of the target virtual image file, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:

reading the measurement value of the target virtual image file from the specified storage area during the process of operating in the trusted execution environment; and

comparing the measurement value of the target virtual image file with a preset measurement value, to allow or forbid, according to a comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment.

4 . The method according to claim 3 , wherein comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:

forbidding the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a black list; and

allowing the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a white list.

5 . The method according to claim 3 , wherein prior to comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment, the method further comprises:

determining a service level, and obtaining, from the configuration file, a preset measurement value corresponding to the service level.

6 . The method according to claim 1 , further comprising:

destroying the measurement value in the specified storage area in a case where operating in the trusted execution environment ends.

7 . An electronic device, comprising: a processor; and

a memory having executable codes stored thereon, which cause, when executed, the processor to execute operations of:

determining an application program to be measured;

separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;

computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;

writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and

allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.

8 . One or more non-transitory machine-readable media having executable codes stored thereon, which cause, when executed, a processor to execute operations of:

determining an application program to be measured;

separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;

computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;

writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and

allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.

9 . The electronic device according to claim 7 , wherein the target measurement data comprises a code, a configuration file, and an environment variable of the application program.

10 . The electronic device according to claim 7 , wherein the operation of allowing or forbidding, according to the credibility of the target virtual image file, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:

reading the measurement value of the target virtual image file from the specified storage area during the process of operating in the trusted execution environment; and

comparing the measurement value of the target virtual image file with a preset measurement value, to allow or forbid, according to a comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment.

11 . The electronic device according to claim 10 , wherein the operation of comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:

forbidding the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a black list; and

allowing the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a white list.

12 . The electronic device according to claim 10 , wherein prior to the operation of comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment, the executable codes further cause, when executed, the processor to execute operations of:

determining a service level, and obtaining, from the configuration file, a preset measurement value corresponding to the service level.

13 . The electronic device according to claim 7 , wherein the executable codes further cause, when executed, the processor to execute operations of:

destroying the measurement value in the specified storage area in a case where operating in the trusted execution environment ends.