Virtualization-based trusted computing measurement method and apparatus, device, and storage medium
View Patent ↗A virtualization-based trusted computing measurement method and apparatus, a device, and a storage medium. The method comprises: determining an application program to be measured; separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment; determining the credibility of a target virtual image file loaded to the trusted execution environment; and according to the credibility of the target virtual image file, allowing or forbidding an application program corresponding to the target virtual image file to operate in the trusted execution environment. In the embodiments of the present application, fine-grained trusted computing measurement may be performed on the application program, thereby better providing a service on the basis of the fine-grained measurement result.
1 . A virtualization-based trusted computing measurement method, comprising:
determining an application program to be measured;
separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;
computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;
writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and
allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.
2 . The method according to claim 1 , wherein the target measurement data comprises a code, a configuration file, and an environment variable of the application program.
3 . The method according to claim 1 , wherein allowing or forbidding, according to the credibility of the target virtual image file, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:
reading the measurement value of the target virtual image file from the specified storage area during the process of operating in the trusted execution environment; and
comparing the measurement value of the target virtual image file with a preset measurement value, to allow or forbid, according to a comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment.
4 . The method according to claim 3 , wherein comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:
forbidding the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a black list; and
allowing the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a white list.
5 . The method according to claim 3 , wherein prior to comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment, the method further comprises:
determining a service level, and obtaining, from the configuration file, a preset measurement value corresponding to the service level.
6 . The method according to claim 1 , further comprising:
destroying the measurement value in the specified storage area in a case where operating in the trusted execution environment ends.
7 . An electronic device, comprising: a processor; and
a memory having executable codes stored thereon, which cause, when executed, the processor to execute operations of:
determining an application program to be measured;
separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;
computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;
writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and
allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.
8 . One or more non-transitory machine-readable media having executable codes stored thereon, which cause, when executed, a processor to execute operations of:
determining an application program to be measured;
separating target measurement data from the application program, and storing the target measurement data into a virtual image file of a virtual machine, the virtual machine comprising a trusted execution environment;
computing, by adopting a specified digest algorithm, a measurement value of a target virtual image file loaded to the trusted execution environment, the measurement value being used for characterizing a credibility of the virtual image file;
writing the measurement value of the target virtual image file in a specified storage area of the virtual machine, wherein the specified storage area is forbidden from being written in during a process of operating in the trusted execution environment; and
allowing or forbidding, according to the credibility of the target virtual image file, an application program corresponding to the target virtual image file to operate in the trusted execution environment.
9 . The electronic device according to claim 7 , wherein the target measurement data comprises a code, a configuration file, and an environment variable of the application program.
10 . The electronic device according to claim 7 , wherein the operation of allowing or forbidding, according to the credibility of the target virtual image file, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:
reading the measurement value of the target virtual image file from the specified storage area during the process of operating in the trusted execution environment; and
comparing the measurement value of the target virtual image file with a preset measurement value, to allow or forbid, according to a comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment.
11 . The electronic device according to claim 10 , wherein the operation of comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment comprises:
forbidding the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a black list; and
allowing the application program corresponding to the target virtual image file to operate in the trusted execution environment in a case where the measurement value of the target virtual image file matches a preset measurement value in a white list.
12 . The electronic device according to claim 10 , wherein prior to the operation of comparing the measurement value of the target virtual image file with the preset measurement value, to allow or forbid, according to the comparison result, the application program corresponding to the target virtual image file to operate in the trusted execution environment, the executable codes further cause, when executed, the processor to execute operations of:
determining a service level, and obtaining, from the configuration file, a preset measurement value corresponding to the service level.
13 . The electronic device according to claim 7 , wherein the executable codes further cause, when executed, the processor to execute operations of:
destroying the measurement value in the specified storage area in a case where operating in the trusted execution environment ends.