Measurement update method, apparatus, system, storage media, and computing device

US11520771B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11520771-B2
Application numberUS-201916698377-A
CountryUS
Kind codeB2
Filing dateNov 27, 2019
Priority dateNov 30, 2018
Publication dateDec 6, 2022
Grant dateDec 6, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, apparatuses, systems, storage media, and computing devices for updating a measurement are disclosed. One of the methods includes: detecting that an application device initiates a measurement update, wherein the measurement update includes at least one of: an object update that updates a measurement object, and a policy update that updates a policy; and performing measurement update processing upon verifying that the measurement update satisfies a predetermined condition, wherein the measurement update processing includes performing an update process on at least one of content included in an execution of a measurement process, and wherein the measurement process includes calculating a measurement object using a predetermined algorithm, comparing a calculation result with a pre-stored verification reference value, and determining that an integrity of the measurement object is not corrupted if a comparison result is consistent.

First claim

Opening claim text (preview).

What is claimed is: 1. A method implemented by one or more processors of a computing device, the method comprising: detecting that an application device initiates a measurement update, the measurement update comprising at least one of: an object update that updates a measurement object; and a policy update that updates a policy; and performing a measurement update processing upon verifying that the measurement update satisfies a predetermined condition, wherein: the measurement update processing comprises performing an update process on at least one of content included in an execution of a measurement process, the measurement process comprising: calculating a measurement object using a predetermined algorithm; comparing a calculation result with a pre-stored verification reference value; and determining that an integrity of the measurement object is not corrupted in response to determining that a comparison result is consistent; and the performing the measurement update processing comprises at least one of: performing the measurement update processing and performing a synchronization with a policy control center after the measurement update processing is completed; and initiating an update request to the policy control center to complete the measurement update processing for the application device. 2. The method of claim 1 , wherein: in response to determining that the measurement update is the object update, the performing the measurement update processing and performing the synchronization with the policy control center after the update process is completed comprises: updating a locally stored measurement object to a new measurement object content; returning a feedback about a completion of the updating of the locally stored measurement object to the application device; and synchronizing the new measurement object content with the policy control center. 3. The method of claim 1 , wherein: in response to determining that the measurement update is the object update, the initiating the update request to the policy control center to complete the measurement update processing for the application device comprises: determining a new measurement object content; and after signing an update request comprising the new measurement object content using a private key, sending the signed update request to the policy control center, the policy control center controlling a local update to store the new measurement object content, and storing the new measurement object content. 4. The method of claim 3 , wherein the sending the signed update request to the policy control center comprises: performing a hash calculation on the new measurement object content to obtain a hash value for the new measurement object content; and after signing the hash value using the private key, sending the signed hash value to the policy control center. 5. The method of claim 3 , wherein the new measurement object content comprises at least one of: a new measurement object; a new measurement policy for measuring the new measurement object; or a new verification policy corresponding to the new measurement policy. 6. The method of claim 1 , wherein: in response to determining that the measurement update is a policy update and before performing the measurement update processing, the method further comprises: determining an operation feature of an operation performed on a policy file in response to determining that a policy is updated; and in response to determining that the operation feature is a write operation performed on the policy file and a write instruction inputted in the application device is legitimate, allowing the measurement update processing to be performed by the write operation on the policy file. 7. The method of claim 1 , wherein the performing the measurement update processing and performing the synchronization with the policy control center after the measurement update processing is completed comprise: updating a locally stored policy file through a write operation on the locally stored policy file; returning a feedback about an update completion of the locally stored policy file to the application device; and synchronizing the updated locally stored policy file with the policy control center. 8. The method of claim 1 , wherein the performing the measurement update processing and performing the synchronization with the policy control center after the measurement update processing is completed comprise: determining a new policy file; signing the update request that comprises the new policy file using a private key; and sending the signed update request to the policy control center. 9. The method of claim 8 , wherein the new policy file comprises at least one of: a new measurement policy file; or a new verification file corresponding to the new measurement policy file. 10. One or more computer readable media storing executable instructions that, when executed by one or more processors, cause the one or more processors to perform acts comprising: receiving a measurement update request sent by a measurement update monitoring component, the measurement update request being triggered by the measurement update monitoring component in response to detecting a measurement update of an application device, the measurement update request comprising at least one of: an object update request for requesting an update of a measurement object; and a policy update request for requesting an update of a policy; and performing measurement update processing in response to verifying that the measurement update monitoring component is legitimate, the measurement update processing comprising performing an update process on at least one of content included in an execution of a measurement process. 11. The one or more computer readable media of claim 10 , wherein the measurement process comprises: calculating a measurement object using a predetermined algorithm; comparing a calculation result with a pre-stored verification reference value; and determining that an integrity of the measurement object is not corrupted in response to determining that a comparison result is consistent. 12. The one or more computer readable media of claim 10 , wherein the performing the measurement update processing comprises: under a circumstance that the measurement update request comprises a new measurement object content obtained by the measurement update monitoring component that has completed an update of the measurement object, or a new policy file obtained by the measurement update monitoring component that has completed an update of a policy file corresponding to the policy, performing a synchronization of the new measurement object content or the new policy file through a method of synchronization operations performed by a policy control center and the measurement update monitoring component. 13. The one or more computer readable media of claim 12 , wherein: before performing the synchronization of the new measurement object content or the new policy file, the method further comprises: verifying the new measurement object content or the new policy file, and triggering the synchronization of new measurement object content or the new policy file upon a successful verification; or receiving the measurement update request sent by the measurement update monitoring component comprises, the receiving comprising receiving the measurement update request signed by a private key of the measurement update monitoring component. 14. The one or more computer readable media of claim 10 , wherein the performing the measurement update proce

Assignees

Inventors

Classifications

  • Hash tables · CPC title

  • G06F21/57Primary

    Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • G06F8/65Primary

    Updates (security arrangements therefor G06F21/57) · CPC title

  • Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title

  • Ensuring data consistency and integrity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11520771B2 cover?
Methods, apparatuses, systems, storage media, and computing devices for updating a measurement are disclosed. One of the methods includes: detecting that an application device initiates a measurement update, wherein the measurement update includes at least one of: an object update that updates a measurement object, and a policy update that updates a policy; and performing measurement update pro…
Who is the assignee on this patent?
Alibaba Group Holding Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/57. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 06 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).