CN102523211B - Terminal trusting method, trusting server and terminal - Google Patents

Terminal trusting method, trusting server and terminal Download PDF

Info

Publication number
CN102523211B
CN102523211B CN201110409560.9A CN201110409560A CN102523211B CN 102523211 B CN102523211 B CN 102523211B CN 201110409560 A CN201110409560 A CN 201110409560A CN 102523211 B CN102523211 B CN 102523211B
Authority
CN
China
Prior art keywords
service
credit
terminal
server
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201110409560.9A
Other languages
Chinese (zh)
Other versions
CN102523211A (en
Inventor
贾佳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN201110409560.9A priority Critical patent/CN102523211B/en
Publication of CN102523211A publication Critical patent/CN102523211A/en
Application granted granted Critical
Publication of CN102523211B publication Critical patent/CN102523211B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Telephonic Communication Services (AREA)

Abstract

The invention provides a terminal trusting method, a trusting server and a terminal. The terminal trusting method comprises the following steps: sending a trusting service request carrying the characteristic information of the terminal to the trusting server; receiving an initial trusting service corresponding to the trusting service request sent by the trusting server, and according to the initial trusting service, dividing a storage region; receiving service integration information sent by the trusting server, and loading the service integration information to the storage region, then taking the storage region as a trusted source; according to the service integration information, establishing a trusted chain, and verifying the trusted chain, if the verification is successful, sending a trusted service acquisition request to the trusting server; and receiving a trusted service corresponding to the trusted service acquisition request sent by the trusting server. According to the terminal trusting method, the trusting server and the terminal provided by the invention, the trust of the terminal can be realized without change of the hardware structure of the terminal, and the flexibility of the terminal trusting is improved.

Description

Terminal credit method, credit server and terminal
Technical field
The present invention relates to the communication technology, relate in particular to a kind of terminal credit method, credit server and terminal.
Background technology
Along with the development of information technology, information has become vital assets, and information security is more and more important.Evaluation work group that international non-profit organization is credible (Trusted Computing Group, be called for short TCG) work up about credible platform module (Trusted Platform Module for different terminal types and platform form, be called for short TPM), a series of complete specifications such as trusted storage and trustable network connection, terminal is for example PC, server, mobile phone, communication network etc., and the defined TPM of these specifications is embedded in various computing terminals for more believable computing basis is provided with the form of hardware conventionally.Although TPM can realize the credible of terminal, this kind of implementation need to change the hardware configuration of terminal, and therefore high to hardware-dependence, trusted source is fixed, and trusts transfer mode and lacks flexibility.
Summary of the invention
The invention provides a kind of terminal credit method, credit server and terminal, realize the credible of terminal not change terminal hardware structure, improve the flexibility of terminal credit.
The invention provides a kind of terminal credit method, comprising:
Send the credit service request of the characteristic information that carries terminal to credit server;
Receive initial credit service corresponding to described credit service request that described credit server sends, divide storage area according to described initial credit service;
Receive the service integrated information that described credit server sends, and described service integrated information is loaded into described storage area, using described storage area as trusted source;
According to the described service integrated information chain that breaks the wall of mistrust, and trust chain is verified, if be proved to be successful, sent credible service acquisition request to described credit server;
Receive described credible service acquisition request that described credit server sends corresponding can telecommunications services.
The invention provides a kind of terminal credit method, comprising:
The credit service request of the characteristic information that carries described terminal that receiving terminal sends, sends initial credit service corresponding to described credit service request according to described credit service request to described terminal;
Generate service integrated information according to described characteristic information, and described service integrated information is sent to described terminal;
Receive the credible service acquisition request that described terminal sends, to described terminal send described credible service acquisition request corresponding can telecommunications services.
The invention provides a kind of terminal, comprising:
The first request sending module, for sending the credit service request of the characteristic information that carries terminal to credit server;
Storage area is divided module, and initial credit service corresponding to described credit service request sending for receiving described credit server divided storage area according to described initial credit service;
Trusted source is set up module, the service integrated information sending for receiving described credit server, and described service integrated information is loaded into described storage area, using described storage area as trusted source;
The second request sending module, for the chain that breaks the wall of mistrust according to described service integrated information, and verifies trust chain, if be proved to be successful, sends credible service acquisition request to described credit server;
Credible service reception module, for receive described credible service acquisition request that described credit server sends corresponding can telecommunications services.
The invention provides a kind of credit server, comprising:
Credit service module, the credit service request of the characteristic information that carries described terminal sending for receiving terminal, sends initial credit service corresponding to described credit service request according to described credit service request to described terminal;
Service integration module, for generate service integrated information according to described characteristic information, and sends to described terminal by described service integrated information;
Credible service module, the credible service acquisition request sending for receiving described terminal, to described terminal send described credible service acquisition request corresponding can telecommunications services.
As shown from the above technical solution, terminal credit method provided by the invention, credit server and terminal, divide storage area according to initial credit service, service integrated information is loaded into storage area, using the storage area that is mounted with service integrated information as trusted source, according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, to realize the credible of terminal.Because service integrated information is provided by credit server, ensure the credibility of trusted source, then carry out successively the foundation of trust chain, trust chain is verified, realize trusting and transmit.Just can realize the credible of terminal without the hardware configuration that changes terminal, improve the flexibility of terminal credit.
Brief description of the drawings
A kind of terminal credit method flow diagram that Fig. 1 provides for the embodiment of the present invention;
The another kind of terminal credit method flow diagram that Fig. 2 provides for the embodiment of the present invention;
The terminal structure schematic diagram that Fig. 3 provides for the embodiment of the present invention;
The credit server architecture schematic diagram that Fig. 4 provides for the embodiment of the present invention.
Embodiment
A kind of terminal credit method flow diagram that Fig. 1 provides for the embodiment of the present invention.As shown in Figure 1, the terminal credit method that the present embodiment provides specifically can be applied to the credit process of terminal, and terminal is specifically as follows mobile phone, panel computer, personal computer etc.The terminal credit method that the present embodiment provides specifically comprises:
Step U10, send the credit service request of characteristic information that carries terminal to credit server;
Terminal specifically can telecommunications services to service provider's acquisition request, and service provider is providing for terminal and can before telecommunications services, will determine that this terminal is trusted terminal.Credit server can carry out the server of credit for the terminal that is used to that service provider arranges.Terminal sends credit service request to credit server, so that credit server carries out credit service to terminal.
Initial credit service corresponding to credit service request that step U20, reception credit server send, divides storage area according to initial credit service;
The credit service request that credit server sends according to terminal, for terminal provides initial credit service.Initial credit service is specially that credit server generates according to the characteristic information of the terminal in credit service request.The characteristic information of terminal is specifically as follows the characteristic information for terminal hardware module and version extraction.Terminal receives initial credit service, and divides storage area according to this initial credit service, and thinking to trust to inject provides storage area.Initial credit service is specially the indication information that carries out memory block division operation in order to indicating terminal.The division of storage area is carried out in the relevant instruction that terminal can be divided according to the memory block of carrying in initial credit service.As carried out the original position of storage area division, area size, form etc. on the storage card of terminal.
The service integrated information that step U30, reception credit server send, and service integrated information is loaded into storage area, using storage area as trusted source;
Service integrated information is specially that authorization server generates according to the characteristic information of terminal, and service integrated information specifically can comprise operating system configuration information, interface between software and hardware configuration information, final drive configuration information and credible service software configuration information etc.Terminal receives the service integrated information that authorization server sends, and service integrated information is loaded into storage area, using storage area as trusted source, realizes trusting and injects.Service integrated information is loaded into and in storage area, is specially integrated service information reproduction to storage area and carries out start-up course.
Step U40, according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, if be proved to be successful, send credible service acquisition request to credit server;
Particularly, this trusted source that terminal provides credit server restarts as new trusted source, and the chain that breaks the wall of mistrust carries out the checking of trust chain in start-up course, realizes trusting and transmits.To the checking of trust chain specifically comprise integrity verification before startup and start in authentication, if be proved to be successful, to credit server send for obtain can telecommunications services credible service acquisition request.
Step U50, receive credible service acquisition request that credit server sends corresponding can telecommunications services.
What now, this terminal just can be used as that trusted terminal receives that credit server provides can telecommunications services.Service provider specifically also can arrange in addition to provide can telecommunications services server for terminal provides can telecommunications services.In actual credit service providing process; specifically can protect this process by security mechanism; credit service can be undertaken by the physical loading mode of off-line, also can be undertaken by the online load mode of safety chain, can improve the fail safe of credit service.
The terminal credit method that the present embodiment provides, divide storage area according to initial credit service, service integrated information is loaded into storage area, using the storage area that is mounted with service integrated information as trusted source, according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, to realize the credible of terminal.Because service integrated information is provided by credit server, ensure the credibility of trusted source, then carry out successively the foundation of trust chain, trust chain is verified, realize trusting and transmit.Just can realize the credible of terminal without the hardware configuration that changes terminal, improve the flexibility of terminal credit.
In the present embodiment, step U20, receives initial credit service corresponding to credit service request that credit server sends, and divides storage area according to initial credit service, specifically can comprise:
Receive the authorization information that credit server sends, and authorization information is verified, if be proved to be successful, receive the initial credit service that credit server sends, divide storage area according to initial credit service by physical isolation mode.
Particularly, the credit service request that first credit server can send according to terminal is verified the identity of terminal, with the legitimacy of verification terminal identity.Send authorization information and initial credit service if be proved to be successful to terminal, so that terminal verifies the identity of credit server, realize the bidirectional safe certification of authentication.Dividing storage area according to initial credit service by physical isolation mode, is physically-isolated for trusting the storage area of injection, has ensured the fail safe of storage area on hardware, and the credibility of the trusted source forming with this is further provided.
In the present embodiment, step U50, receive credible service acquisition request that credit server sends corresponding can telecommunications services after, specifically can also comprise the steps:
Step U60, to can telecommunications services verifying, if be proved to be successful, start can telecommunications services.
The another kind of terminal credit method flow diagram that Fig. 2 provides for the embodiment of the present invention.As shown in Figure 2, the terminal credit method that the present embodiment provides specifically can be applied to the credit process of server side to terminal, and the terminal credit method that is applied to end side that specifically can provide with any embodiment of the present invention coordinates realization, and this repeats no more.The credit server that the terminal credit method that the present embodiment provides can be arranged by service provider is carried out.
The credit method that the present embodiment provides specifically comprises:
The credit service request of the characteristic information that carries terminal that step S10, receiving terminal send, sends initial credit service corresponding to credit service request according to credit service request to terminal;
Step S20, generate service integrated information according to characteristic information, and service integrated information is sent to terminal;
The credible service acquisition request that step S30, receiving terminal send, to terminal send credible service acquisition request corresponding can telecommunications services.
The terminal credit method that the present embodiment provides, send initial credit service corresponding to credit service request according to credit service request to terminal, so that terminal is according to dividing storage area, the characteristic information providing according to terminal generates service integrated information, and service integrated information is sent to terminal, so that service integrated information is loaded into storage area by terminal, using the storage area that is mounted with service integrated information as trusted source, according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, to realize the credible of terminal.Because service integrated information is provided by credit server, ensure the credibility of trusted source, then carry out successively the foundation of trust chain, trust chain is verified, realize trusting and transmit.Just can realize the credible of terminal without the hardware configuration that changes terminal, improve the flexibility of terminal credit.
In the present embodiment, in step S10, send initial credit service corresponding to credit service request according to credit service request to terminal, specifically can comprise:
Credit service request is verified, if be proved to be successful, sent authorization information and initial credit service corresponding to credit service request to terminal.
The terminal structure schematic diagram that Fig. 3 provides for the embodiment of the present invention.As shown in Figure 3, the terminal 81 that the present embodiment provides specifically can realize each step of the terminal credit method that is applied to end side that any embodiment of the present invention provides, and this repeats no more.The terminal 81 that the present embodiment provides specifically comprises that the first request sending module 11, storage area are divided module 12, trusted source is set up module 13, the second request sending module 14 and credible service reception module 15.The first request sending module 11 is for sending the credit service request of the characteristic information that carries terminal 81 to credit server 82.Storage area is divided initial credit service corresponding to credit service request that module 12 sends for receiving credit server 82, divides storage area 31 according to initial credit service.Trusted source is set up the service integrated information that module 13 sends for receiving credit server 82, and service integrated information is loaded into storage area 31, using storage area 31 as trusted source.The second request sending module 14 is for according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, if be proved to be successful, sends credible service acquisition request to credit server 82.Credible service reception module 15 for the credible service acquisition request that receives credit server 82 and send corresponding can telecommunications services.
The terminal 81 that the present embodiment provides, storage area is divided module 12 and is divided storage area 31 according to initial credit service, trusted source is set up module 13 service integrated information is loaded into storage area 31, using the storage area 31 that is mounted with service integrated information as trusted source, the second request sending module 14 is according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, to realize the credible of terminal 81.Because service integrated information is provided by credit server 82, ensure the credibility of trusted source, then carry out successively the foundation of trust chain, trust chain is verified, realize trusting and transmit.Just can realize the credible of terminal 81 without the hardware configuration that changes terminal 81, improve the flexibility of terminal 81 credits.
In the present embodiment, storage area is divided module 12 specifically can also be used for receiving the authorization information that credit server 82 sends, and authorization information is verified, if be proved to be successful, receive the initial credit service that credit server 82 sends, divide storage area 31 according to initial credit service by physical isolation mode.
In the present embodiment, this terminal specifically also can comprise startup module.Start module for to can telecommunications services verifying, if be proved to be successful, starting can telecommunications services.
The credit server architecture schematic diagram that Fig. 4 provides for the embodiment of the present invention.As shown in Figure 4, the credit server 82 that the present embodiment provides specifically can be realized each step of the terminal credit method that is applied to server side that any embodiment of the present invention provides, and this repeats no more.This credit server 82 specifically comprises credit service module 21, service integration module 22 and credible service module 23.The credit service request of what credit service module 21 sent for receiving terminal 81 the carry characteristic information of terminal 81, sends initial credit service corresponding to credit service request according to credit service request to terminal 81.Serve integration module 22 for generate service integrated information according to characteristic information, and service integrated information is sent to terminal 81.The credible service acquisition request that credible service module 23 sends for receiving terminal 81, to terminal 81 send credible service acquisition request corresponding can telecommunications services.
The credit server 82 that the present embodiment provides, credit service module 21 sends initial credit service corresponding to credit service request according to credit service request to terminal 81, so that terminal 81 is according to dividing storage area, service integration module 22 generates service integrated information according to characteristic information, and service integrated information is sent to terminal 81, so that service integrated information is loaded into storage area by terminal 81, using the storage area that is mounted with service integrated information as trusted source, according to the service integrated information chain that breaks the wall of mistrust, and trust chain is verified, to realize the credible of terminal 81.Because service integrated information is provided by credit server 82, ensure the credibility of trusted source, then carry out successively the foundation of trust chain, trust chain is verified, realize trusting and transmit.Just can realize the credible of terminal 81 without the hardware configuration that changes terminal 81, improve the flexibility of terminal 81 credits.
In the present embodiment, credit service module 21 specifically can also be used for credit service request to verify, if be proved to be successful, sends authorization information and initial credit service corresponding to credit service request to terminal 81.
Finally it should be noted that: above embodiment only, in order to technical scheme of the present invention to be described, is not intended to limit; Although the present invention is had been described in detail with reference to previous embodiment, those of ordinary skill in the art is to be understood that: its technical scheme that still can record previous embodiment is modified, or part technical characterictic is wherein equal to replacement; And these amendments or replacement do not make the essence of appropriate technical solution depart from the spirit and scope of various embodiments of the present invention technical scheme.

Claims (10)

1. a terminal credit method, is characterized in that, comprising:
Send the credit service request of the characteristic information that carries terminal to credit server;
Receive initial credit service corresponding to described credit service request that described credit server sends, divide storage area according to described initial credit service;
Receive the service integrated information that described credit server sends, and described service integrated information is loaded into described storage area, using described storage area as trusted source, wherein, described service integrated information is that described credit server generates according to the characteristic information of described terminal;
According to the described service integrated information chain that breaks the wall of mistrust, and trust chain is verified, if be proved to be successful, sent credible service acquisition request to described credit server;
Receive described credible service acquisition request that described credit server sends corresponding can telecommunications services.
2. terminal credit method according to claim 1, is characterized in that, initial credit service corresponding to described credit service request that the described credit server of described reception sends divided storage area according to described initial credit service, comprising:
Receive the authorization information that described credit server sends, and described authorization information is verified, if be proved to be successful, receive the described initial credit service that described credit server sends, divide storage area according to described initial credit service by physical isolation mode.
3. terminal credit method according to claim 1, is characterized in that, what described credible service acquisition request that the described credit server of described reception sends was corresponding can telecommunications services after, also comprise:
Can telecommunications services verify described, if be proved to be successful, can telecommunications services described in starting.
4. a terminal credit method, is characterized in that, comprising:
The credit service request of the characteristic information that carries described terminal that receiving terminal sends, sends initial credit service corresponding to described credit service request according to described credit service request to described terminal;
Generate service integrated information according to described characteristic information, and described service integrated information is sent to described terminal;
Receive the credible service acquisition request that described terminal sends, to described terminal send described credible service acquisition request corresponding can telecommunications services.
5. terminal credit method according to claim 4, is characterized in that, describedly sends initial credit service corresponding to described credit service request according to described credit service request to described terminal, comprising:
Described credit service request is verified, if be proved to be successful, sent authorization information and initial credit service corresponding to described credit service request to described terminal.
6. a terminal, is characterized in that, comprising:
The first request sending module, for sending the credit service request of the characteristic information that carries terminal to credit server;
Storage area is divided module, and initial credit service corresponding to described credit service request sending for receiving described credit server divided storage area according to described initial credit service;
Trusted source is set up module, the service integrated information sending for receiving described credit server, and described service integrated information is loaded into described storage area, using described storage area as trusted source, wherein, described service integrated information is that described credit server generates according to the characteristic information of described terminal;
The second request sending module, for the chain that breaks the wall of mistrust according to described service integrated information, and verifies trust chain, if be proved to be successful, sends credible service acquisition request to described credit server;
Credible service reception module, for receive described credible service acquisition request that described credit server sends corresponding can telecommunications services.
7. terminal according to claim 6, it is characterized in that: described storage area is divided the authorization information that module also sends for receiving described credit server, and described authorization information is verified, if be proved to be successful, receive the described initial credit service that described credit server sends, divide storage area according to described initial credit service by physical isolation mode.
8. terminal according to claim 6, is characterized in that, also comprises:
Start module, for can telecommunications services verifying described, if be proved to be successful, can telecommunications services described in starting.
9. a credit server, is characterized in that, comprising:
Credit service module, the credit service request of the characteristic information that carries described terminal sending for receiving terminal, sends initial credit service corresponding to described credit service request according to described credit service request to described terminal;
Service integration module, for generate service integrated information according to described characteristic information, and sends to described terminal by described service integrated information;
Credible service module, the credible service acquisition request sending for receiving described terminal, to described terminal send described credible service acquisition request corresponding can telecommunications services.
10. credit server according to claim 9, it is characterized in that: described credit service module is also for verifying described credit service request, if be proved to be successful, send authorization information and initial credit service corresponding to described credit service request to described terminal.
CN201110409560.9A 2011-12-09 2011-12-09 Terminal trusting method, trusting server and terminal Active CN102523211B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110409560.9A CN102523211B (en) 2011-12-09 2011-12-09 Terminal trusting method, trusting server and terminal

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110409560.9A CN102523211B (en) 2011-12-09 2011-12-09 Terminal trusting method, trusting server and terminal

Publications (2)

Publication Number Publication Date
CN102523211A CN102523211A (en) 2012-06-27
CN102523211B true CN102523211B (en) 2014-07-23

Family

ID=46294003

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110409560.9A Active CN102523211B (en) 2011-12-09 2011-12-09 Terminal trusting method, trusting server and terminal

Country Status (1)

Country Link
CN (1) CN102523211B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105610822A (en) * 2015-12-28 2016-05-25 东软熙康健康科技有限公司 Credit verifying method and device

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101295340A (en) * 2008-06-20 2008-10-29 北京工业大学 Credible platform module and active measurement method thereof
CN101515316A (en) * 2008-02-19 2009-08-26 北京工业大学 Trusted computing terminal and trusted computing method

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7698507B2 (en) * 2007-02-28 2010-04-13 Intel Corporation Protecting system management mode (SMM) spaces against cache attacks

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101515316A (en) * 2008-02-19 2009-08-26 北京工业大学 Trusted computing terminal and trusted computing method
CN101295340A (en) * 2008-06-20 2008-10-29 北京工业大学 Credible platform module and active measurement method thereof

Also Published As

Publication number Publication date
CN102523211A (en) 2012-06-27

Similar Documents

Publication Publication Date Title
US11824992B2 (en) Secure token refresh
CN112131021B (en) Access request processing method and device
CN110532766B (en) Processing method of trusted application program based on multiple containers and related equipment
KR20170013305A (en) Secure wireless charging
CN101841525A (en) Secure access method, system and client
CN104717648A (en) Unified authentication method and device based on SIM card
CN103167498B (en) A kind of ability control method and system
CN103888422A (en) Security certificate updating method, client and server
CN110971398A (en) Data processing method, device and system
CN111918274B (en) Code number configuration and management method and device, electronic equipment and readable storage medium
CN100550030C (en) On portable terminal host, add the method for credible platform
CN112448956B (en) Authority processing method and device of short message verification code and computer equipment
CN102610045B (en) Trustable mobile payment system and mobile payment method
EP3851983B1 (en) Authorization method, auxiliary authorization component, management server and computer readable medium
CN112688907A (en) Combined type equipment remote certification mode negotiation method and related equipment
CN102984046A (en) Processing method of instant messaging business and corresponding network equipment
CN111062059B (en) Method and device for service processing
CN110248356B (en) Information acquisition method and device
CN112422516B (en) Trusted connection method and device based on power edge calculation and computer equipment
CN103684796A (en) SMI (subscriber identity module) card and personal identity authentication method
CN101807237B (en) Signature method and device
CN102523211B (en) Terminal trusting method, trusting server and terminal
CN205160564U (en) System security starting drive and intelligent terminal
CN105743651A (en) Method and apparatus for utilizing card application in chip security domain, and application terminal
CN107113316A (en) A kind of system and method for APP certifications

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant