CN114902223A - 安全隔离方法、装置以及计算机系统 - Google Patents

安全隔离方法、装置以及计算机系统 Download PDF

Info

Publication number
CN114902223A
CN114902223A CN202080090331.2A CN202080090331A CN114902223A CN 114902223 A CN114902223 A CN 114902223A CN 202080090331 A CN202080090331 A CN 202080090331A CN 114902223 A CN114902223 A CN 114902223A
Authority
CN
China
Prior art keywords
security level
access device
security
access
accessed data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202080090331.2A
Other languages
English (en)
Inventor
曾思
曾红义
高健博
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Publication of CN114902223A publication Critical patent/CN114902223A/zh
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F12/00Accessing, addressing or allocating within memory systems or architectures
    • G06F12/14Protection against unauthorised use of memory or access to memory
    • G06F12/1416Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2113Multi-level security, e.g. mandatory access control
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Health & Medical Sciences (AREA)
  • Databases & Information Systems (AREA)
  • Storage Device Security (AREA)
  • Safety Devices In Control Systems (AREA)

Abstract

一种安全隔离方法、装置以及计算机系统。所述安全隔离装置包括请求检测模块和选择模块,请求检测模块用于:接收来自访问设备的访问请求,访问请求携带访问设备的操作信息和访问设备的安全等级相关信息,访问设备的安全等级相关信息用于指示访问设备的安全等级,操作信息用于指示访问设备的操作;选择模块用于:在访问设备的操作为写入操作或RFO操作,且访问设备的安全等级满足安全隔离条件的情况下,隔离访问请求。上述方案能够实现多个安全等级的设备之间的数据的安全交互,提高系统性能。

Description

PCT国内申请,说明书已公开。

Claims (17)

  1. PCT国内申请,权利要求书已公开。
CN202080090331.2A 2020-01-14 2020-01-14 安全隔离方法、装置以及计算机系统 Pending CN114902223A (zh)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/071964 WO2021142612A1 (zh) 2020-01-14 2020-01-14 安全隔离方法、装置以及计算机系统

Publications (1)

Publication Number Publication Date
CN114902223A true CN114902223A (zh) 2022-08-12

Family

ID=76863390

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202080090331.2A Pending CN114902223A (zh) 2020-01-14 2020-01-14 安全隔离方法、装置以及计算机系统

Country Status (4)

Country Link
US (1) US20220350915A1 (zh)
EP (1) EP4083837A4 (zh)
CN (1) CN114902223A (zh)
WO (1) WO2021142612A1 (zh)

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103679049A (zh) * 2013-12-13 2014-03-26 中国航空工业集团公司第六三一研究所 一种针对综合化航电系统的分区间安全访问控制方法
US9836318B2 (en) * 2014-02-21 2017-12-05 Infineon Technologies Ag Safety hypervisor function
GB2539435B8 (en) * 2015-06-16 2018-02-21 Advanced Risc Mach Ltd Data processing memory access control, in which an owning process for a region of memory is specified independently of privilege level
US10212167B2 (en) * 2016-02-27 2019-02-19 Gryphon Online Safety, Inc. Method and system to enable controlled safe internet browsing
US10482289B2 (en) * 2017-08-24 2019-11-19 Qualcomm Incorporated Computing device to provide access control to a hardware resource
CN109606192B (zh) * 2018-12-04 2021-07-30 奇瑞汽车股份有限公司 电动智能汽车的供电系统、方法、装置及存储介质
CN110532781A (zh) * 2019-07-25 2019-12-03 安徽永顺信息科技有限公司 一种基于Hades架构的信息流控制系统

Also Published As

Publication number Publication date
EP4083837A1 (en) 2022-11-02
WO2021142612A1 (zh) 2021-07-22
EP4083837A4 (en) 2023-01-04
US20220350915A1 (en) 2022-11-03

Similar Documents

Publication Publication Date Title
US20220019423A1 (en) Over-The-Air (OTA) Update for Firmware of a Vehicle Component
JP7030046B2 (ja) 不正通信検知方法、不正通信検知システム及びプログラム
US10229547B2 (en) In-vehicle gateway device, storage control method, and computer program product
JP6175579B2 (ja) 電子制御ユニット、車載ネットワークシステム及び車両用通信方法
JP6203365B2 (ja) 不正検知電子制御ユニット、車載ネットワークシステム及び不正検知方法
CN107925600B (zh) 安全处理方法以及服务器
US10187406B2 (en) Method for sensing fraudulent frames transmitted to in-vehicle network
US11848755B2 (en) Anomaly detection device, anomaly detection method, and recording medium
JP2019201423A (ja) 不正検知ルール更新方法、不正検知電子制御ユニット及び車載ネットワークシステム
US8965626B2 (en) Event data recording for vehicles
CN109076016B (zh) 非法通信检测基准决定方法、决定系统以及记录介质
CN109005678B (zh) 非法通信检测方法、非法通信检测系统以及记录介质
CN112367318A (zh) 安全处理方法以及计算机
JP2017138969A (ja) セキュリティサポートおよび耐障害サポートを提供する自動車修正システム
US20190147668A1 (en) Server side security preventing spoofing of vin provisioning service
CN105591858A (zh) 一种车用网关控制方法以及控制装置
CN114902223A (zh) 安全隔离方法、装置以及计算机系统
JP6874102B2 (ja) 不正検知電子制御ユニット、車載ネットワークシステム及び不正検知方法
US11144239B2 (en) Storage controller, storage device, and write control method
WO2016116976A1 (ja) 不正検知ルール更新方法、不正検知電子制御ユニット及び車載ネットワークシステム
WO2020105657A1 (ja) 車載中継装置及び中継方法
CN112333038A (zh) 一种车辆网关检测方法及装置
CN105700507A (zh) 一种车辆网络诊断控制方法及装置
CN105677247B (zh) 一种信息处理方法和电子设备
JP2019125947A (ja) 監視装置、監視方法及びプログラム

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination