CN102819694A - TCM (trusted cryptography module) chip, virus scanning method and device for operating TCM chip - Google Patents

TCM (trusted cryptography module) chip, virus scanning method and device for operating TCM chip Download PDF

Info

Publication number
CN102819694A
CN102819694A CN2011101536845A CN201110153684A CN102819694A CN 102819694 A CN102819694 A CN 102819694A CN 2011101536845 A CN2011101536845 A CN 2011101536845A CN 201110153684 A CN201110153684 A CN 201110153684A CN 102819694 A CN102819694 A CN 102819694A
Authority
CN
China
Prior art keywords
virus
detected
content
input
module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2011101536845A
Other languages
Chinese (zh)
Other versions
CN102819694B (en
Inventor
王正鹏
朱贺新
付月朋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nationz Technologies Inc
Original Assignee
Nationz Technologies Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nationz Technologies Inc filed Critical Nationz Technologies Inc
Priority to CN201110153684.5A priority Critical patent/CN102819694B/en
Publication of CN102819694A publication Critical patent/CN102819694A/en
Application granted granted Critical
Publication of CN102819694B publication Critical patent/CN102819694B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Test And Diagnosis Of Digital Computers (AREA)
  • Storage Device Security (AREA)

Abstract

The invention discloses a TCM (trusted cryptography module) chip, a virus scanning method and a device for operating the TCM chip. The TCM chip comprises an input output module, a storage module, a microcontroller and a hardware virus scanning module. The input output module is used for inputting virus database feature information and contents to be scanned to the hardware virus scanning module. The hardware virus scanning module is used for transferring resources in the storage module and the microcontroller to scan the contents to be scanned so as to obtain a scanning result according to the virus database feature information. The input output module is further used for outputting the scanning result. By the TCM chip, risk that a virus scanning engine is infected or tampered is avoided, whether virus exists or not in the contents to be scanned can be known by the TCM chip according to the scanning result, and accordingly the TCM chip is provided with the capacity of virus scanning and the functions of the TCM chip are enhanced.

Description

A kind of TCM chip, look into the equipment of malicious method and operation TCM chip
Technical field
The present invention relates to the Trusted Computing field, particularly, relate in particular to a kind of TCM chip, look into the equipment of malicious method and operation TCM chip.
Background technology
Along with the generally use of computer equipment, computer equipment is deep into each corner of daily life.For example, PC, server, workstation, data center, industry control, net book etc. are worked to live to people and have been brought very big facility, have changed people's life style.Computer equipment has also brought new problem, the computer virus that just people knew when facilitating to people.Computer virus is batch processing or the instruction set that can destroy computer resource, and it has unique replication capacity.And along with being widely used of network, network becomes the main carrier that computer virus is propagated, and network worm then becomes main and the maximum new virus of destructive power.Along with the differentiation of technology, wooden horse combines with virus technology, thereby the wooden horse of virus characteristic or the virus of wooden horse characteristic have occurred obviously having.Computer virus is progressively controlled and consume system resources, and user software, hardware, data, information, resource are taken or destroy, and causes loss difficult to the appraisal.
In order effectively to check the harm of virus or wooden horse, so produced virus killing technology and antivirus software.But because virus all has the camouflage of hiding ability, can not show effect under the usual condition, be difficult to find, therefore how discern key problem and difficult point place that virus then becomes the virus killing technology.Conventional virus method is to start a cover antivirus software; Is furnished with a virus scanning engine in this antivirus software; This scanning engine is responsible for content to be detected is scanned according to certain way (by file, by the sector etc.), thereby judges whether content to be detected is comprised virus.
Virus scanning engine is the core of whole antivirus software, and in the prior art, virus scanning engine all is one section software program, and software itself just exists by the virus infections or the risk of distorting.If this kind software virus scanning engine self is by virus infections, then it just can't bring into play the due effect of antivirus software effectively.And the existing software virus scanning engine also can't the scanning computer operating system nucleus, can't guarantee the security of computer operating system kernel.
Summary of the invention
The technical problem underlying that the present invention will solve is, the equipment of a kind of TCM chip, virus method and operation TCM chip is provided, and can avoid virus scanning engine self by the virus infections and the risk of distorting, and makes the TCM chip have and looks into malicious function.
For solving the problems of the technologies described above, the present invention has adopted following technical scheme:
A kind of TCM chip comprises input/output module, memory module, and microcontroller is characterized in that, said TCM chip also comprises hardware virus scan module; Said input/output module is used for virus base characteristic information and content to be detected are imported said hardware virus scan module; Said hardware virus scan module is used for the virus base characteristic information according to input, calls the content to be detected that the interior resource of said memory module and microcontroller scans input, obtains the scanning result of content to be detected; Said input/output module also is used to export said scanning result.
In an embodiment of the present invention, said hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Said input interface is used to receive said content to be detected; Said virus base input interface is used to receive said virus base characteristic information; Said scanning engine is used for scanning said content to be detected according to said virus base characteristic information through the resource in said memory module of engine operation interface interchange and the microcontroller, obtains the scanning result of content to be detected; Said output interface is used to export said scanning result.
In an embodiment of the present invention, said TCM chip also comprises the enciphering/deciphering module, and said enciphering/deciphering module links to each other with said hardware virus scan module, is used for said virus base characteristic information is carried out enciphering/deciphering.
In an embodiment of the present invention, said scanning result comprises brief introduction to be detected and judged result; Wherein, said brief introduction to be detected comprises the data length and the summary of content to be detected; Said judged result comprises whether content to be detected has virus, and corresponding Virus Type, viral position.
In an embodiment of the present invention, said hardware virus scan module judges whether virulent method is the feature code method to said content to be detected, or is verification and method, or is the behavior detection method.
Simultaneously, the present invention also provides a kind of malicious method of looking into, and may further comprise the steps:
Hardware virus scan module is according to the virus base characteristic information of input/output module input; The resource of calling in memory module and the microcontroller scans the content to be detected that input/output module is imported; Obtain the scanning result of content to be detected, and export said scanning result through input/output module.
In an embodiment of the present invention, said hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Said hardware virus scan module is according to the virus base characteristic information of input/output module input; The resource of calling in memory module and the microcontroller scans the content to be detected that input/output module is imported; Obtain the scanning result of content to be detected, and further comprise through the step that input/output module is exported said scanning result:
Said input interface receives said content to be detected, and said virus base input interface receives said virus base characteristic information;
Said scanning engine scans said content to be detected according to said virus base characteristic information through the resource in said memory module of engine operation interface interchange and the microcontroller, obtains the scanning result of content to be detected;
Said output interface is exported said scanning result.
Simultaneously, the present invention also provides a kind of equipment of the TCM of operation chip, is integrated with above-mentioned arbitrary described TCM chip in the said equipment.
In an embodiment of the present invention, said equipment is computing machine, and said TCM chip consumes the cpu resource in the said TCM chip when looking into poison scanning.
In an embodiment of the present invention, said equipment is computing machine, and said TCM chip is welded on the mainboard of said computing machine.
The invention has the beneficial effects as follows: utilize the hardware virus scan module in the TCM chip,, call the scanning result that content to be detected that the interior resource of memory module and microcontroller scans input obtains content to be detected according to the virus base characteristic information of input.So design; Because the TCM chip utilizes hardware virus scan module to scan content to be detected; Thereby can avoid virus scanning engine self by the virus infections or the risk of distorting, and the TCM chip can know whether there is virus in the content to be detected according to scanning result; Thereby make the TCM chip have and look into malicious ability, strengthened the function of TCM chip.
If the TCM chipset is formed in the equipment that can move the TCM chip, then can promote the security of user environment.For example, can the TCM chipset be formed in the computer equipment, make computing machine when searching virus, can not take the resource of host CPU in the computing machine, thereby the whole work efficiency of high computing machine can be provided.
Description of drawings
Fig. 1 is the composition synoptic diagram of the TCM chip of an embodiment of the present invention;
Fig. 2 is the composition synoptic diagram of the hardware virus scan module of an embodiment of the present invention;
Fig. 3 is the composition synoptic diagram of the TCM chip of the another kind of embodiment of the present invention;
Fig. 4 is the method flow diagram of the another kind of embodiment of the present invention.
Embodiment
Combine accompanying drawing that the present invention is done further explain through embodiment below.
The virus scanning engine itself that exists in the existing virus killing technology exists and possibly or distort by virus infections, and can not bring into play antivirus software effectively should powerful problem.For solving this technical problem, main design of the present invention is: virus scanning engine is made the form of hardware, and so virus scanning engine self then can or not distorted by virus infections, thereby can effectively avoid virus scanning engine itself by the risk of virus infections.
Yet, if the hardware virus scanning engine needs operation normally, just need build minimum hardware system, particularly, need microprocessor, storer, the IOC basic elements of character such as (I/O controllers).This shows, realize that separately the entity cost cost of a hardware virus scanning engine will compare costliness, thereby can't in the current computer environment, use widely.
In the prior art; TCM chip (credible password module; Trusted Cryptography Module) has independently modules such as microprocessor, storer, hash algorithm engine, IOC (I/O controller), symmetry algorithm and asymmetric arithmetic engine, can improve credible wilfulness, completeness of platform, the data security of computing machine.Through being independent of the mode of computer system, and guarantee the safety of bottom hardware and user data based on theory trusty.TCM chip most important function provides an environment trusty, on this basis, realizes the Secure Application of each link such as authentication, digital signature, file encryption-decryption, HD encryption, VPN/PKI authentication, WIFI authentication.The TCM chip can also generate encryption key, realizes the storage of key and the reduction of enciphered data etc.The TCM chip is in extensive use such as PC, notebook, server at present.
This shows that the TCM chip has the hardware system of a minimum.Just think,, the hardware virus scanning engine is integrated in the TCM chip if transform through inner, can be very not big to the influence of TCM production cost of chip.This moment the hardware virus scanning engine just can with resources such as the shared microprocessor of the internal module in the TCM chip, storer, IOC, work together with other modules.
So; The virus scanning engine that has then solved form of software in the prior art is easily by virus infections or problem such as distort; And the hardware virus scanning engine is integrated in the TCM chip, also makes the TCM chip have and look into the ability of poison, thereby can strengthen the function that has the TCM chip now.
By the foregoing invention design, the present invention proposes a kind of TCM chip and look into malicious method.
Because a hardware system is wanted and can normally be moved, and comprises 5 elements, i.e. I/O part, storage area, calculating section, specific procedure operation part.
As shown in Figure 1, the TCM chip 1 among the present invention comprises the hardware system of a minimum promptly comprising input/output module 14, memory module 12, microcontroller 13; This TCM chip also comprises hardware virus scan module 11, and wherein, input/output module 14 is used for virus base characteristic information and content to be detected are inputed to hardware virus scan module 11.11 of hardware virus scan modules are used to receive virus base characteristic information and content to be detected; And according to the virus base characteristic information of importing; Call the content to be detected that memory module 12 and microcontroller 13 interior resources scan input; Obtain the scanning result of content to be detected, and input/output module 14 is used for also with the scanning result output that obtains.Wherein, Hardware virus scan module 11 is integrated in the TCM chip; So; Hardware virus scan module 11 just can be in the TCM chip other module, hardware devices such as the input/output module in the shared TCM chip, memory module, microcontroller, thus guaranteed the normal operation of hardware virus scan module 11.Wherein, input/output module also is used for the transferring command word, the startup of control hardware virus scan module 11 and the execution of work, and memory module 12 can also be used for some hardware parameter information of storage hardware virus scan module itself.
Utilize the hardware virus scan module in the TCM chip of the present invention; Can carry out virus scan to content to be detected; So, then avoided virus scan module self by virus infections or distort maybe, can bring into play the due function of hardware virus scan module effectively.And; Hardware virus scan module is integrated in the TCM chip; Resource with the input/output module of the shared TCM chip of other module in the TCM chip, memory module, microcontroller; Content to be detected is scanned, look into malicious ability, strengthened the function of TCM chip afterwards thereby make the TCM chip have.And, when producing this kind improvement TCM chip, need not carry out bigger change, so the TCM chip among the present invention has the low advantage of production cost to existing TCM chip.
As shown in Figure 2, in one embodiment, hardware virus scan module 11 comprises input interface 111, virus base input interface 112, engine operation interface 113 and output interface 114, and scanning engine 115; Particularly, input interface 111 is used to receive the content to be detected of input/output module input; Virus base input interface 112 is used to receive the virus base characteristic information of input/output module input; Scanning engine 115 then according to the virus base characteristic information of input, calls memory module 12 through engine operation interface 113 and scans said content to be detected with microcontroller 13 interior resources, and analyze its content, obtains the scanning result of content to be detected; 114 scanning results that are used to export content to be detected of output interface.Wherein, can be used to receive the different virus base characteristic information that is input to scanning engine 115 through virus base input interface 112.
As shown in Figure 3; In one embodiment, TCM chip 1 comprises that also the TCM chip also comprises enciphering/deciphering module 15, and enciphering/deciphering module 15 links to each other with hardware virus scan module 11; Virus base characteristic information to receiving is encrypted; And when hardware virus scan module 11 needs, just decipher, so, then guaranteed the correctness of virus base characteristic information.Also guarantee the TCM chip in subsequent processes, the correctness of the virus that finds.Need to prove that content to be detected is the killing object of TCM chip, the content-form that content to be detected comprises is very abundant; For example; Content to be detected can be for being stored in the content in the file, perhaps for to be stored in the content in the disk, and also can be for being stored in the content in the logical block.Particularly, hardware virus scan module scans the position and the size of content to be detected.
Similarly, the content of virus base characteristic information then comprises the position feature and the version feature of virus, and promptly this kind virus belongs to that version, the sort of Virus Type, with and particular location etc.
In one embodiment, the scanning result of content to be detected comprises two parts, brief introduction promptly to be detected and judged result.Wherein, brief introduction to be detected comprises the data length and the summary of content to be detected, and judged result comprises then whether content to be detected has virus, and Virus Type, viral position etc.If the scanning engine in the TCM chip judges that content to be detected comprises virus, show in the scanning result of output interface output that then content to be detected comprises the conclusion of virus, and describe out this viral type particularly, with and described position etc.
Certainly, the hardware virus scan module in the TCM chip judges whether virulent method has a variety of content to be detected.For example, can the use characteristic code method, or use verification and method, or the usage behavior detection method.Wherein, the feature code method is to detect the simplest, the minimum method of expense of known viruse.Title, the false alarm rate that this method detected accurately fast, can discern virus be low, according to testing result, can do detoxifcation and handling.
In an embodiment of the present invention, looking into poison with TCM chip use characteristic code method is that example is elaborated.
Preliminary work at first need be gathered known virus base sample, extracts its feature code, obtains the virus base characteristic information.The code that extracts needs suitable length, its objective is the uniqueness of keeping feature code on the one hand, does not need too big spatiotemporal expense on the other hand again.Under the prerequisite that keeps uniqueness, make feature code length short, to reduce space and time overhead as far as possible.Gather the known viruse sample and extract the work comparison consumes resources that feature code forms the virus base characteristic information, generally provide, do not require with the TCM chip here and realize by antivirus software manufacturer.The TCM chip only need search out the virus base characteristic information, and can receive and upgrade the virus base characteristic information and get final product.
Secondly; Scanning engine in the hardware virus scan module is according to the virus base characteristic information that obtains from the virus base input interface; To content to be detected, the resource of calling in microprocessor and the memory module is searched for virus pattern code string or the virus characteristic word that whether comprises in the content to be detected in the virus base characteristic information.If in content to be detected, find to have with the virus base characteristic information in identical virus pattern code because feature code is corresponding one by one with virus, just so can conclude which kind of virus is arranged in the content to be detected.
Particularly, can adopt following steps to handle:
1, imports content to be detected through input interface (ReadPEImage);
2, through virus base input interface (ReadSector) input virus base characteristic information;
3, scanning engine is according to the virus base characteristic information, and the resource of calling in memory module and the little processing through engine operation interface (ExtractPE, CompareDB) scans content to be detected, waits for scanning result.
4, the scanning engine scanning result that will finally obtain is through output interface output.
So, the TCM chip then can know whether include virus in the content to be detected according to scanning result.The advantage of utilizing the feature code method to look into poison is: the title, the false alarm rate that detect accurately fast, can discern virus are low.
Simultaneously, the present invention also provides a kind of malicious method of looking into, and may further comprise the steps:
Hardware virus scan module is according to the virus base characteristic information of input/output module input; The resource of calling in memory module and the microcontroller scans the content to be detected that input/output module is imported; Obtain the scanning result of content to be detected, and export said scanning result through input/output module.
Wherein, hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine.Particularly, look into malicious method and can be divided into following steps:
S1, input interface receive content to be detected; The virus base input interface receives the virus base characteristic information;
S2, scanning engine scan content to be detected according to the virus base characteristic information through the resource in engine operation interface interchange memory module and the microcontroller, obtain the scanning result of content to be detected;
S3, output interface output detect the scanning result of content.
In addition, the present invention also provides a kind of equipment of the TCM of operation chip, is integrated with the TCM chip that comprises above-mentioned arbitrary embodiment in this kind equipment.So; This kind equipment is when the main antivirus applet of operation; Utilize the hardware virus scanning engine in the TCM chip to scan whether comprise virus in the content to be detected, thereby avoided virus scanning engine, can search the virus that possibly exist in the equipment effectively by the risk of virus infections.Scanning content to be detected when comprising virus, then utilize main virus killing degree to carry out correspondingly killing, thereby the security of the content that has guaranteed to store in the equipment promote the security of user environment.This kind equipment can be computing machine, notebook, panel computer, mobile phone etc.
For example, in an embodiment of the present invention, this equipment is specially computing machine, and the TCM chip then is welded on the mainboard of computing machine.This kind computing machine can utilize TCM chip hardware scan module that content to be detected is carried out virus scan when the main antivirus applet of operation.The benefit of design is like this, is to have avoided the hardware virus scanning engine by the risk of virus infections on the one hand, can search the virus that possibly exist in the computing machine effectively; On the other hand, when the TCM chip is carried out virus scan, consumption be the cpu resource in the TCM chip; And the host CPU resource in can the consumption calculations machine; So, the host CPU resource in the computing machine then can go to move other program this moment, treat that hardware scanning module in the TCM chip obtains scanning result after; The host CPU resource is just handled according to scanning result accordingly; So reduce virus search in to the taking of host CPU resource, realized can asynchronous concurrent execution scanning mode of operation, improve the whole work efficiency of computing machine.At last, with TCM chips welding disclosed by the invention on the mainboard of computing machine, so, then can't be from physically cutting off being connected of TCM chip and computing machine.Since the TCM chip be in computer system than bottom, can with the BIOS cooperating, thereby make this kind TCM chip to work in early days at computer starting, further guaranteed the security of computer system.
Above content is to combine concrete embodiment to the further explain that the present invention did, and can not assert that practical implementation of the present invention is confined to these explanations.For the those of ordinary skill of technical field under the present invention, under the prerequisite that does not break away from the present invention's design, can also make some simple deduction or replace, all should be regarded as belonging to protection scope of the present invention.

Claims (10)

1. a TCM chip comprises input/output module, memory module, and microcontroller is characterized in that, said TCM chip also comprises hardware virus scan module; Said input/output module is used for virus base characteristic information and content to be detected are imported said hardware virus scan module; Said hardware virus scan module is used for the virus base characteristic information according to input, calls the content to be detected that the interior resource of said memory module and microcontroller scans input, obtains the scanning result of content to be detected; Said input/output module also is used to export said scanning result.
2. TCM chip as claimed in claim 1 is characterized in that, said hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Said input interface is used to receive said content to be detected; Said virus base input interface is used to receive said virus base characteristic information; Said scanning engine is used for scanning said content to be detected according to said virus base characteristic information through the resource in said memory module of engine operation interface interchange and the microcontroller, obtains the scanning result of content to be detected; Said output interface is used to export said scanning result.
3. according to claim 1 or claim 2 TCM chip is characterized in that said TCM chip also comprises the enciphering/deciphering module, and said enciphering/deciphering module links to each other with said hardware virus scan module, is used for said virus base characteristic information is carried out enciphering/deciphering.
4. according to claim 1 or claim 2 TCM chip is characterized in that said scanning result comprises brief introduction to be detected and judged result; Wherein, said brief introduction to be detected comprises the data length and the summary of content to be detected; Said judged result comprises whether content to be detected has virus, and corresponding Virus Type, viral position.
5. TCM chip as claimed in claim 4 is characterized in that, said hardware virus scan module judges whether virulent method is the feature code method to said content to be detected, or is verification and method, or is the behavior detection method.
6. look into malicious method for one kind, it is characterized in that, may further comprise the steps:
Hardware virus scan module is according to the virus base characteristic information of input/output module input; The resource of calling in memory module and the microcontroller scans the content to be detected that input/output module is imported; Obtain the scanning result of content to be detected, and export said scanning result through input/output module.
7. as claimed in claim 6ly look into malicious method, it is characterized in that said hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Said hardware virus scan module is according to the virus base characteristic information of input/output module input; The resource of calling in memory module and the microcontroller scans the content to be detected that input/output module is imported; Obtain the scanning result of content to be detected, and further comprise through the step that input/output module is exported said scanning result:
Said input interface receives said content to be detected, and said virus base input interface receives said virus base characteristic information;
Said scanning engine scans said content to be detected according to said virus base characteristic information through the resource in said memory module of engine operation interface interchange and the microcontroller, obtains the scanning result of content to be detected;
Said output interface is exported said scanning result.
8. an equipment that moves the TCM chip is characterized in that, is integrated with the arbitrary described TCM chip of claim 1-6 in the said equipment.
9. equipment as claimed in claim 8 is characterized in that, said equipment is computing machine, and said TCM chip consumes the cpu resource in the said TCM chip when looking into poison scanning.
10. equipment as claimed in claim 8 is characterized in that, said TCM chip is welded on the mainboard of said computing machine.
CN201110153684.5A 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip Active CN102819694B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110153684.5A CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110153684.5A CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Publications (2)

Publication Number Publication Date
CN102819694A true CN102819694A (en) 2012-12-12
CN102819694B CN102819694B (en) 2015-12-02

Family

ID=47303804

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110153684.5A Active CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Country Status (1)

Country Link
CN (1) CN102819694B (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103390131A (en) * 2013-07-29 2013-11-13 无锡华御信息技术有限公司 Single computer safety checking system of electronic key based on integrated flash memory
CN107547499A (en) * 2017-05-11 2018-01-05 新华三信息安全技术有限公司 Feature database collocation method and device
CN105468969B (en) * 2015-11-19 2019-02-01 中科创达软件股份有限公司 A kind of method and system promoting antivirus applications security
CN112184212A (en) * 2020-09-17 2021-01-05 深圳市银通商智能卡有限公司 Method for controlling applet operation for IC card

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN200972654Y (en) * 2006-10-18 2007-11-07 何华科技股份有限公司 Universal interface devirus device
CN101382928A (en) * 2008-10-29 2009-03-11 清华大学 Soft computer and implementing method
CN101479706A (en) * 2006-07-03 2009-07-08 英特尔公司 An anti-virus usage model at an exterior panel of a computer
CN101714197A (en) * 2008-09-30 2010-05-26 英特尔公司 Hardware-based anti-virus scan service
CN101901308A (en) * 2009-05-27 2010-12-01 同方股份有限公司 Method for using computer antivirus software

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101479706A (en) * 2006-07-03 2009-07-08 英特尔公司 An anti-virus usage model at an exterior panel of a computer
CN200972654Y (en) * 2006-10-18 2007-11-07 何华科技股份有限公司 Universal interface devirus device
CN101714197A (en) * 2008-09-30 2010-05-26 英特尔公司 Hardware-based anti-virus scan service
CN101382928A (en) * 2008-10-29 2009-03-11 清华大学 Soft computer and implementing method
CN101901308A (en) * 2009-05-27 2010-12-01 同方股份有限公司 Method for using computer antivirus software

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103390131A (en) * 2013-07-29 2013-11-13 无锡华御信息技术有限公司 Single computer safety checking system of electronic key based on integrated flash memory
CN105468969B (en) * 2015-11-19 2019-02-01 中科创达软件股份有限公司 A kind of method and system promoting antivirus applications security
CN107547499A (en) * 2017-05-11 2018-01-05 新华三信息安全技术有限公司 Feature database collocation method and device
CN112184212A (en) * 2020-09-17 2021-01-05 深圳市银通商智能卡有限公司 Method for controlling applet operation for IC card

Also Published As

Publication number Publication date
CN102819694B (en) 2015-12-02

Similar Documents

Publication Publication Date Title
Gopinath et al. A comprehensive survey on deep learning based malware detection techniques
Vellela et al. Strategic Survey on Security and Privacy Methods of Cloud Computing Environment
CN102184372B (en) Reverse-sandbox-based mobilephone payment protection method
Garcia et al. Obfuscation-resilient, efficient, and accurate detection and family identification of android malware
US11693962B2 (en) Malware clustering based on function call graph similarity
US9990583B2 (en) Match engine for detection of multi-pattern rules
US20150163229A1 (en) Data Security and Integrity by Remote Attestation
US9690598B2 (en) Remotely establishing device platform integrity
CN104598815B (en) Recognition methods, device and the client of malice advertising program
US11586735B2 (en) Malware clustering based on analysis of execution-behavior reports
US20190377863A1 (en) Password input method, computer device and storage medium
US20210089684A1 (en) Controlled access to data stored in a secure partition
CN106713618A (en) Processing method of identifying code and mobile terminal
CN102222292B (en) Mobile phone payment protection method
US11556346B2 (en) Security enhancement in hierarchical protection domains
CN102819694A (en) TCM (trusted cryptography module) chip, virus scanning method and device for operating TCM chip
Poudyal et al. Malware analytics: Review of data mining, machine learning and big data perspectives
Kumar et al. A comprehensive survey on hardware-assisted malware analysis and primitive techniques
CN107609412A (en) A kind of method for realizing that mobile terminal safety stores under mobile Internet based on TrustZone technologies
Wu et al. Detection of fake IoT app based on multidimensional similarity
CN103984901A (en) Trusted computer system and application method thereof
WO2019028572A1 (en) Plc automatic trusted configuration method, apparatus, and computer readable storage medium
CN107169354A (en) Multi-layer android system malicious act monitoring method
WO2024035509A1 (en) Identification of a resource attack path by connecting code, configuration, and telemetry
Raghuvanshi et al. Android malware detection using machine learning techniques

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CB03 Change of inventor or designer information

Inventor after: Liang Jie

Inventor after: Liu Xin

Inventor after: Hou Weixing

Inventor after: Wang Zhengpeng

Inventor after: Zhu Hexin

Inventor after: Fu Yuepeng

Inventor before: Wang Zhengpeng

Inventor before: Zhu Hexin

Inventor before: Fu Yuepeng

COR Change of bibliographic data