Checking method, checking device and checking system for processor
First Claim
1. A checking method for a checked processor, comprising:
- determining, by a checking processor, whether the checked processor satisfies a security-sensitive condition including one or more of security-sensitive instruction, processor running mode, security-sensitive input/output operation, security-sensitive application, and user-defined security level, wherein the processor running mode includes an authority level of the checked processor in runtime; and
checking, by the checking processor, the checked processor according to the determination result during at least a part of one running process of the checked processor, wherein checking the checked processor further comprises;
when the checked processor satisfies the security-sensitive condition, checking the checked processor according to a first checking mode during at least a first part of said one running process based on a total checking length of the first checking mode; and
when the checked processor does not satisfy the security-sensitive condition, checking the checked processor according to a second checking mode during at least a second part of said one running process based on a total checking length of the second checking mode;
wherein for said one running process of the checked processor, the total checking length of the first checking mode is longer than the total checking length of the second checking mode, and the longer the total checking length is, the greater a corresponding checking coverage of the total checking length is, wherein checking the checked processor according to the first checking mode comprises prolonging a checking length of a check of the checked processor by the checking processor, increasing the number of checks of the checked processor during said one running process of the checked processor by the checking processor, or both.
1 Assignment
0 Petitions
Accused Products
Abstract
A checking method for a processor is provided. The checking method first determines whether a checked processor satisfies a security-sensitive condition including one or more of security-sensitive instruction, processor running mode, security-sensitive input/output operation, security-sensitive application, and user-defined security level. Then, the checking method checks the checked processor according to a determination result, which further includes: when the checked processor satisfies the security-sensitive condition, checking the checked processor according to a first checking mode; and when the checked processor does not satisfy the security-sensitive condition, checking the checked processor according to a second checking mode; wherein for the same running process of the checked processor, a total checking length of the first checking mode is longer than that of the second checking mode. Also provided is a checking device for a processor and a checking system for a processor.
53 Citations
18 Claims
-
1. A checking method for a checked processor, comprising:
-
determining, by a checking processor, whether the checked processor satisfies a security-sensitive condition including one or more of security-sensitive instruction, processor running mode, security-sensitive input/output operation, security-sensitive application, and user-defined security level, wherein the processor running mode includes an authority level of the checked processor in runtime; and checking, by the checking processor, the checked processor according to the determination result during at least a part of one running process of the checked processor, wherein checking the checked processor further comprises; when the checked processor satisfies the security-sensitive condition, checking the checked processor according to a first checking mode during at least a first part of said one running process based on a total checking length of the first checking mode; and when the checked processor does not satisfy the security-sensitive condition, checking the checked processor according to a second checking mode during at least a second part of said one running process based on a total checking length of the second checking mode; wherein for said one running process of the checked processor, the total checking length of the first checking mode is longer than the total checking length of the second checking mode, and the longer the total checking length is, the greater a corresponding checking coverage of the total checking length is, wherein checking the checked processor according to the first checking mode comprises prolonging a checking length of a check of the checked processor by the checking processor, increasing the number of checks of the checked processor during said one running process of the checked processor by the checking processor, or both. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A checking system, comprising:
-
a checking processor; an input/output recorder; a non-transitory computer readable storage medium stored with programs which, when executed by the checking processor, cause the checking processor to perform operations comprising; determining, by the checking processor, whether a checked processor satisfies a security-sensitive condition including one or more of security-sensitive instruction, processor running mode, security-sensitive input/output operation, security-sensitive application, and user-defined security level, wherein the processor running mode includes an authority level of the checked processor in runtime; and checking, by the checking processor, the checked processor according to the determination result during at least a part of one running process of the checked processor, wherein checking the checked processor further comprises; when the checked processor satisfies the security-sensitive condition, checking the checked processor according to a first checking mode during at least a first part of said one running process based on a total checking length of the first checking mode; and when the checked processor does not satisfy the security-sensitive condition, checking the checked processor according to a second checking mode during at least a second part of said one running process based on a total checking length of the second checking mode; wherein for said one running process of the checked processor, the total checking length of the first checking mode is longer than the total checking length of the second checking mode, and the longer the total checking length is, the greater a corresponding checking coverage of the total checking length is, wherein checking the checked processor according to the first checking mode comprises prolonging a checking length of a check of the checked processor by the checking processor, increasing the number of checks of the checked processor during said one running process of the checked processor by the checking processor, or both. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18)
-
Specification