A data processing method, system, electronic device, and medium

By introducing software protection extension technology into the data processing system, the client and server work together to decrypt keys and data, solving the problem of key leakage and improving data security and property protection.

CN120567419BActive Publication Date: 2025-10-31LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511005663.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-10-31
Estimated Expiration
2045-07-22

AI Technical Summary

Technical Problem

The keys used to encrypt data in existing technologies are easily leaked, leading to reduced data security.

Method used

By introducing Software Protection Extension (SGX) technology into the data processing system, the client receives encrypted information and sends it to a second server. The second server uses the key in the Software Protection Extension to decrypt the second key, obtains the first key, and then decrypts the encrypted data, ensuring the security of the key and data.

Benefits of technology

It achieves protection of keys and data, avoids the risk of key leakage, improves data security, and protects data ownership.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567419B_ABST
    Figure CN120567419B_ABST
Patent Text Reader

Abstract

This invention discloses a data processing method, system, electronic device, and medium, relating to the field of data processing technology. The client receives encrypted data and an encrypted key from a first server, and also sends encrypted data and an encrypted key to a second server. Therefore, encryption protects both the data and the key. Furthermore, the first server does not directly distribute the first key to the client, meaning the client cannot obtain the first key used to encrypt the data. Thus, neither the first server nor the client will leak the first key, preventing unauthorized users from accessing it. Moreover, the software protection extension technology based on the second server protects the data by creating a secure container. When the client needs decrypted data, it can only access it from the software protection extension of the second server, and cannot retrieve the data from the client's internal storage. Therefore, data ownership protection is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a data processing method, system, electronic device, and medium. Background Technology

[0002] To enhance data security, relevant technologies encrypt the data. When an authorized user uses the data, the copyright holder must also provide the decryption key to the authorized user.

[0003] However, since the data copyright owner and authorized users both obtain the decryption key, they may leak the key to unauthorized users, allowing unauthorized users to use the key to decrypt the encrypted data and thus use it, resulting in reduced data security.

[0004] Therefore, how to avoid the leakage of the keys used to encrypt data is a technical problem that urgently needs to be solved by those in this field. Summary of the Invention

[0005] The present invention provides a data processing method, system, electronic device, and medium to at least solve the problem of reduced data security caused by the leakage of keys used in encrypting data in related technologies.

[0006] This invention provides a data processing method applied to a client in a data processing system. The data processing system also includes a first server and a second server. The client connects to both the first and second servers, and the first server connects to the second server. The first server is the server of the data owner, and the second server is a server with deployed software protection extensions. The method includes:

[0007] Receive encrypted information sent by a first server; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using a first key, and a second key obtained by encrypting the first key;

[0008] The encrypted information is sent to the second server; so that the second server can use the key in the software protection extension to decrypt the second key to obtain the first key, and use the first key to decrypt the encrypted data information to obtain the decrypted data;

[0009] The decrypted data from the second server is then processed.

[0010] The beneficial effect of this invention lies in the following: In this method, the client in the data processing system receives encrypted information sent by the first server and sends the encrypted information to the second server. The second server uses the key in the software protection extension to first decrypt the second key (i.e., the key used to encrypt the first key) to obtain the first key (i.e., the key used to encrypt the data). Then, the first key is used to decrypt the encrypted data information to obtain the decrypted data. Finally, the client then calls the decrypted data from the second server for processing. Firstly, in this process, the client receives encrypted data and the encrypted key from the first server, and the client also sends encrypted data and the encrypted key to the second server. Therefore, data and key protection are achieved through encryption. Furthermore, the first server does not directly send the first key (i.e., the unencrypted key) to the client; that is, the client cannot obtain the first key used to encrypt the data. Therefore, there is no risk of the first server and client leaking the first key, thus preventing the first server and client from leaking the key to unauthorized users. Furthermore, the software protection extension of the second server stores the key used to decrypt the second key. Since the software protection extension technology itself has hardware-level protection mechanisms for keys and data, ensuring their security through multiple technologies, it provides a high level of protection, thus improving the security of keys and data. Secondly, if the first server directly sends unencrypted data to the client, the client will store this data internally, affecting the data ownership of the first server. However, the method provided by this invention, based on the software protection extension technology of the second server, protects the data by creating a secure container. When the client needs decrypted data, it can only retrieve it from the software protection extension of the second server, and cannot retrieve the data internally, thus achieving protection of data ownership.

[0011] The present invention also provides a data processing system, comprising: a client, a first server, and a second server, wherein the client is connected to the first server and the second server respectively, and the first server is connected to the second server; wherein the first server is the server of the data owner, and the second server is a server with software protection extensions deployed.

[0012] The first server is used to: send encrypted information to the client; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using the first key, and a second key obtained by encrypting the first key;

[0013] The client is used to: receive encrypted information sent by the first server; send the encrypted information to the second server; and process the decrypted data from the second server.

[0014] The second server is used to: upon receiving encrypted information from the client, decrypt the second key using the key in the software protection extension to obtain the first key, and then use the first key to decrypt the encrypted data information to obtain the decrypted data.

[0015] The present invention also provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of any of the above-described data processing methods.

[0016] The present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of any of the above-described data processing methods. Attached Figure Description

[0017] To more clearly illustrate the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A schematic diagram of a data processing system provided in an embodiment of the present invention;

[0019] Figure 2 A flowchart of a data processing method provided in an embodiment of the present invention;

[0020] Figure 3 This is a schematic diagram illustrating a method for protecting artificial intelligence models based on a software-protected extended computing environment, as provided in an embodiment of the present invention. Detailed Implementation

[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present invention.

[0022] It should be noted that, in the description of this invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0023] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] Figure 1 This is a schematic diagram of a data processing system provided in an embodiment of the present invention, such as... Figure 1 As shown, the data processing system includes client 1, first server 2, and second server 3. Client 1 connects to both first server 2 and second server 3, and first server 2 connects to second server 3. First server 2 is the server of the data owner, and second server 3 is a server with Software Guard Extensions (SGX) deployed.

[0025] This invention provides a data processing method for a client in a data processing system. Figure 2 A flowchart of a data processing method provided in an embodiment of the present invention, such as... Figure 2 As shown, the method includes:

[0026] S10: Receive encrypted information sent by the first server; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using the first key, and a second key obtained by encrypting the first key;

[0027] S11: Send the encrypted information to the second server; so that the second server can use the key in the software protection extension to decrypt the second key to obtain the first key, and use the first key to decrypt the encrypted data information to obtain the decrypted data;

[0028] S12: Process the decrypted data from the second server.

[0029] The data is not limited and is determined based on the actual situation. The data sent by the first server to the client is usually data that the client does not have. For example, training a high-precision AI model for a vertical domain requires a lot of resources. Therefore, when the client needs the AI ​​model, it usually needs to download the model from the first server. In this case, the first server is also called the server that provides the model download service, and the data is specifically the AI ​​model.

[0030] To ensure data security, the first server needs to encrypt the data before sending it to the client. In addition, in order to decrypt the data and avoid losing the encryption key, in this embodiment of the invention, the first server uses a first key to encrypt the data and a second key to encrypt the data before transmitting the encrypted information.

[0031] It is worth noting that the first server can proactively transmit the encrypted information to the client; alternatively, the client can send a request to the first server to retrieve data, and the first server can then return the encrypted information to the client in response. To avoid invalid data transmission, in practice, the client sends a request to the first server to retrieve data, and the first server returns the encrypted information to the client in response. That is, the first server does not proactively transmit the encrypted information to the client to avoid invalid data transmission.

[0032] After receiving the encrypted information from the first server, the client cannot obtain the first encryption key because it is currently encrypted, and therefore cannot decrypt the data. The client then forwards the encrypted information transmitted from the first server to the second server.

[0033] The second server deploys a Software Protection Extension (SGX). This SGX contains a key for decrypting the second key. Therefore, after receiving encrypted information from the client, the second server can use the key in the SGX to decrypt the second key, thus obtaining the first key. After obtaining the first key, it can then use it to decrypt the encrypted data, obtaining the decrypted data (i.e., plaintext data). Because the SGX technology itself has hardware-level protection mechanisms for both keys and data, ensuring their security through multiple technologies, it provides a high level of protection, significantly enhancing the security of keys and data.

[0034] It should be noted that if the first key is encrypted using a symmetric encryption algorithm, the key stored in the software protection extension is the same as the second key, and the key stored in the software protection extension is transmitted to the software protection extension environment via the network; the second key is decrypted using the key stored in the software protection extension to obtain the first key; if the first key is encrypted using an asymmetric encryption algorithm, the private key in the software protection extension matches the second key, and the second key is decrypted using the private key in the software protection extension to obtain the first key.

[0035] In this method, depending on the encryption algorithm used to encrypt the key, the software protection extension can decrypt the key using a private key pre-installed in itself, or it can decrypt the key using a symmetric key transmitted to itself, thus improving the decryption flexibility.

[0036] After the second server receives the decrypted data, it retrieves the data from the second server when the client needs to use it. It's important to note that because the software protection extension technology protects data by creating a secure container, the client can only access the decrypted data from the second server and cannot directly access the decrypted data internally.

[0037] In this method, the client in the data processing system receives encrypted information from the first server and sends it to the second server. The second server uses a key from the software protection extension to decrypt the second key (the key used to encrypt the first key) to obtain the first key (the key used to encrypt the data). Then, the first key is used to decrypt the encrypted data, resulting in decrypted data. Finally, the client processes the decrypted data from the second server. Firstly, in this process, the client receives encrypted data and the encrypted key from the first server, and also sends encrypted data and the encrypted key to the second server. Therefore, encryption protects both the data and the key. Furthermore, the first server does not directly send the first key (the unencrypted key) to the client; the client does not obtain the first key used to encrypt the data. Thus, there is no risk of the first server or client leaking the first key, preventing unauthorized users from accessing it. Furthermore, the software protection extension of the second server stores the key used to decrypt the second key. Since the software protection extension technology itself has hardware-level protection mechanisms for keys and data, ensuring their security through multiple technologies, it provides a high level of protection, thus improving the security of keys and data. Secondly, if the first server directly sends unencrypted data to the client, the client will store this data internally, affecting the data ownership of the first server. However, the method provided by this invention, based on the software protection extension technology of the second server, protects the data by creating a secure container. When the client needs decrypted data, it can only retrieve it from the software protection extension of the second server, and cannot retrieve the data internally, thus achieving protection of data ownership.

[0038] To ensure data security within the software protection extension, in some embodiments, before receiving the encrypted information sent by the first server, the following steps are included:

[0039] A first request for characterizing the software protection extension environment verification is sent to a second server, so that the second server generates information for characterizing the response to the first request based on the first request; wherein the information for characterizing the response to the first request includes at least the environment information of the software protection extension;

[0040] Receive information sent by the second server that represents a response to the first request;

[0041] The environmental trustworthiness of the software protection extension is determined based on the information used to characterize the response to the first request;

[0042] Once the environment is determined to be trustworthy, a second request to identify the data acquisition is sent to the first server, and the process proceeds to receiving encrypted information sent by the first server.

[0043] The environmental information of the software protection extension includes at least the following: a unique identifier for the software protection extension, software protection extension certificate information, metadata information for the memory layout, and the security version of the central processing unit. The first request also includes a first random number; the information representing the response to the first request further includes information after signing the first random number using the private key of the software protection extension certificate.

[0044] The first random number is not limited and is determined based on the actual situation. In this method, before sending a data request to the first server, the client first verifies the trustworthiness of the software protection extension environment. Only after the trustworthiness verification is passed does the client send the data request to the first server. When the requested data is transmitted to the software protection extension, data security is improved. In addition, a random number is set in the first request. Since the random number makes each request unique, even if the request content is the same, the different random numbers will treat the request as a new request, improving the security of the request. Moreover, the response request information contains a private key signature. Since the private key signature can prove that the information does indeed come from the second server and has not been tampered with since it was sent, the client can verify the signature, thereby ensuring the authenticity and security of the information.

[0045] When the client sends a second request to the first server, to ensure the security of subsequent transmissions to the second server, in some embodiments, the second request also includes information representing a unique identifier for the software protection extension. After receiving the second request and before sending the encrypted information to the client, the first server further includes:

[0046] Extract the information from the second request that represents the unique identifier of the software protection extension;

[0047] A third request for verifying the environment of the software protection extension is sent to the second server based on the information of the unique identifier used to characterize the software protection extension, so that the second server can generate information for responding to the third request based on the third request; wherein the information for responding to the third request includes at least the environment information of the software protection extension;

[0048] Receive information sent by the second server that represents a response to the third request;

[0049] The environmental trustworthiness of the software protection extension is determined based on the information used to characterize the response to the third request.

[0050] Once the environment is determined to be trustworthy, the process proceeds to sending encrypted information to the client.

[0051] In addition, the third request also contains a second random number; the information used to characterize the response to the third request also includes information on the second random number after it has been signed with the private key of the Software Protection Extended Certificate.

[0052] The second random number is not limited and is determined based on the actual situation. In this method, before sending the encrypted information to the client, the first server verifies the trustworthiness of the software protection extension environment. Only after the trustworthiness verification is passed does it send a data request to the client. When the requested data is transmitted to the software protection extension, data security is improved. In addition, setting a random number in the third request enhances the security of the request itself. Moreover, the response request information includes a private key signature, ensuring the authenticity and security of the information.

[0053] In order to obtain information for identifying a unique identifier used to characterize a software protection extension, in some embodiments, obtaining information for identifying a unique identifier used to characterize a software protection extension includes:

[0054] Obtain the code segment, data segment, and stack of the software protection extension;

[0055] Connect the code segment, data segment, and stack data segment of the software protection extension, and obtain the fields after the first connection;

[0056] Perform a hash operation on the fields after the first concatenation and obtain the first result of the hash operation;

[0057] Based on the first result, information is determined to identify a unique identifier for characterizing the software protection extension.

[0058] The target request includes a first request or a third request. The determination of the environmental trustworthiness of the software protection extension based on information used to characterize the response to the target request includes:

[0059] Extract public key information from the Software Protection Extended Certificate information;

[0060] Use the public key information to decrypt the signature and obtain the original data digest;

[0061] Perform a hash calculation on the data to be verified to obtain a digest of the data to be verified; wherein, the data to be verified is a first random number or a second random number;

[0062] Compare the original data digest with the data digest to be verified to see if they are consistent;

[0063] If the original data digest matches the data digest to be verified, the signature is considered valid.

[0064] After confirming the signature is valid, obtain the unique identifier used to characterize the software protection extension sent by the second server in response to the target request;

[0065] On the local end, perform a hash operation on the fields after the first connection and obtain the second result of the hash operation; where the local end is either the client or the first server;

[0066] If the information used to characterize the software protection extension sent by the second server when responding to the target request is equal to the second result, the environmental trustworthiness of the software protection extension is determined to be a trustworthy situation.

[0067] Conversely, if the environment for the software protection extension is deemed untrustworthy, then the trustworthiness of the environment is determined to be untrustworthy.

[0068] In this method, the code segment, data segment, and stack data segment of the software protection extension are obtained, and the fields after the first connection are acquired. Then, a hash operation is performed on the fields after the first connection, which improves the security of the unique identity of the software protection extension. Furthermore, the trustworthiness of the software protection extension environment is ensured by verifying the trustworthiness of the software protection extension environment.

[0069] In addition to the encrypted data information obtained by encrypting data using the first key and the second key obtained by encrypting the first key, as described above, in order to ensure the security of the first key, in some embodiments, the encrypted information also includes information for a unique identifier used to characterize the software protection extension.

[0070] The second key obtained by the first server after encrypting the first key includes:

[0071] After obtaining the second random number and the information used to characterize the software protection extension, the resulting field after the second concatenation is obtained;

[0072] Obtain the third result obtained by hashing the fields after the second concatenation, and use the third result as the first key;

[0073] Obtain the public key of the Software Protection Extension Certificate and the algorithm used to encrypt the first key;

[0074] The first key is encrypted using the public key of the software protection extended certificate and the algorithm used to encrypt the first key to obtain the second key.

[0075] In this method, when obtaining the first key, the first key is bound to the Software Protection Extension (SPLE) hardware environment, which restricts its use to the specified SPLE computing environment and limits its use in unauthorized hardware environments, thus ensuring the security of the key. Furthermore, the key is encrypted based on the SPLE public key, which utilizes the hardware-level security features provided by SPLE technology to ensure the high security of the public key generation and storage process, thereby enhancing the credibility and security of the entire encryption process.

[0076] The above text describes a data processing method. To help those skilled in the art better understand this method, the following example illustrates the method by showing a client requesting an artificial intelligence model from a first server. In this case, the first server is a server providing model download services. Figure 3 This is a schematic diagram illustrating a method for protecting artificial intelligence models based on a software-protected extended computing environment, as provided in an embodiment of the present invention. Figure 3 As shown, the method includes:

[0077] S13: The client sends a software protection extended environment verification request to the second server;

[0078] S14: The second server returns software protection extended environment information to the client;

[0079] S15: The client sends a request to the first server to download the model;

[0080] S16: The first server sends a software protection extended environment verification request to the second server;

[0081] S17: The second server returns software protection extended environment information to the first server;

[0082] S18: The first server sends encrypted information containing the model to the client;

[0083] S19: The client sends encrypted information containing the model to the second server;

[0084] S20: The second server decrypts the model;

[0085] S21: The second server sends a message to the client indicating whether the model decryption was successful or failed;

[0086] S22: After receiving the message that the model has been successfully decrypted, the client accesses the decrypted model on the second server.

[0087] In this process, the client's main function is to provide software protection extended computing environment verification, download the artificial intelligence model from the first server, deploy it in the software protection extended computing environment, and call the artificial intelligence model to provide users with relevant artificial intelligence application services.

[0088] The primary function of the first server is to provide an AI model download service based on a user-specific and software-protected extended computing environment. The downloaded models are encrypted to prevent them from being stolen or leaked.

[0089] The model preprocessing module in the second server preprocesses the model to obtain the decrypted model. The main function of the model preprocessing module is to provide information on the extended computing environment based on software protection, and it is also responsible for decrypting the user's artificial intelligence model. The decrypted model provides artificial intelligence model service calls to the client (i.e., the user application).

[0090] The specific processing procedure is as follows:

[0091] 1) The client sends a verification request to the software-protected extended computing environment, which includes a user-defined challenge such as a random number Nonce1 with a length of at least 64 bits;

[0092] 2) Upon receiving the request, the model preprocessing module initializes the Software Protection Extension (SPE) computing environment and generates an SPE computing environment information report. The report includes the unique identifier MRENCLAVE of the SPE, the SGX certificate, Enclave metadata, and the CPU security version. Finally, the module signs the above information and the random number Nonce1 in the user request with the SGX certificate private key and sends it to the client. MRENCLAVE = hash(SGX code segment || SGX data segment || SGX stack).

[0093] 3) The client verifies the validity of the signature based on the SGX certificate, comparing the MRENCLAVE in the response with the code hash value obtained locally using the same calculation method. If they are equal, it indicates that the software protection extended computing environment is trustworthy. Then, the client requests to download the model from the first server, and the request includes the SGX unique identifier MRENCLAVE information.

[0094] 4) The first server verifies the legitimacy of the user request, extracts the unique SGX identifier MRENCLAVE from the client request, and sends a query verification request to the Software Protection Extended Computing Environment. The request includes a user-defined challenge such as a random number Nonce2 with a length of at least 64 bits.

[0095] 5) When the model preprocessing module receives the request, it queries whether the software protection extended computing environment corresponding to the SGX unique identifier MRENCLAVE exists. It directly collects the software protection extended computing environment information and generates a report. The report includes the SGX unique identifier MRENCLAVE, SGX certificate, Enclave metadata, and CPU security version. Finally, it signs the above information and the random number Nonce2 in the user request with the SGX certificate private key and sends it to the first server.

[0096] 6) The first server verifies the validity of the signature based on the SGX certificate, comparing the MRENCLAVE in the response with the code hash value obtained locally using the same calculation method. If they are equal, the software protection extended computing environment is considered trustworthy. The server records the corresponding SGX certificate public key, and sends the SGX unique identifier MRENCLAVE, encryption key Key2, and the encrypted AI model ModelEnc to the client. The AI ​​model is encrypted using symmetric encryption algorithms such as AES / SM4, where:

[0097] Key1=hash(MRENCLAVE||Nonce2);

[0098] Key2 = SGX public key SM2 / RSA encryption (Key1);

[0099] ModelEnc=Key1 SM4 / AES encryption (artificial intelligence model);

[0100] 7) Upon receiving the encrypted AI model, the client forwards relevant information, including the SGX unique identifier MRENCLAVE, encryption key Key2, and the encrypted AI model ModelEnc, to the software-protected extended computing environment. Because both the model and the encryption key are encrypted, the client cannot obtain the AI ​​model information.

[0101] 8) The model preprocessing module uses the SGX private key to decrypt Key2, obtaining Key1. Then, Key1 is used to decrypt the encrypted AI model ModelEnc, thus obtaining the decrypted AI model. Where:

[0102] Key1 = SGX private key decryption (Key2);

[0103] Artificial intelligence model = Key1 SM4 / AES decryption (ModelEnc);

[0104] 9) The model preprocessing module notifies the client of the successful decryption of the artificial intelligence model;

[0105] 10) The client can then directly call the artificial intelligence model.

[0106] In this method, the decryption key is stored in the software protection extension, and the client does not obtain the decryption key. Therefore, it solves the problem that the model copyright owner and authorized user may leak the key to unauthorized users, and reduces the risk of key loss or theft faced by authorized users in the process of using and saving the model and key.

[0107] The foregoing described in detail a data processing method for a client in a data processing system. This embodiment also provides a data processing method for a first server in a data processing system. The data processing method for a first server in a data processing system provided by this invention includes:

[0108] The information is encrypted to obtain encrypted information; wherein the encrypted information includes at least the encrypted data information obtained by encrypting the data using the first key, and the second key obtained by encrypting the first key;

[0109] The encrypted information is sent to the client; the client then sends the encrypted information to the second server; the second server uses the key in the software protection extension to decrypt the second key to obtain the first key, and uses the first key to decrypt the encrypted data to obtain the decrypted data; the client then calls the decrypted data from the second server for processing.

[0110] The data processing method for the first server in the data processing system provided in this embodiment has the same or corresponding features as the data processing method for the client in the data processing system described above. The data processing method for the client in the data processing system has been described in detail above, and the embodiment of the data processing method for the first server in the data processing system will not be repeated here, but the effect is the same as above.

[0111] This invention also provides a data processing method for a second server in a data processing system. The data processing method for a second server in a data processing system provided in this embodiment includes:

[0112] Receive encrypted information sent by the client; wherein the encrypted information in the client is sent by the first server; the encrypted information includes at least encrypted data information obtained by encrypting data using the first key, and a second key obtained by encrypting the first key;

[0113] Use the key from the software protection extension to decrypt the second key to obtain the first key;

[0114] The encrypted data is decrypted using the first key to obtain the decrypted data.

[0115] It receives a request from the client indicating that it needs to process decrypted data from a second server, and then responds to the client's request using the decrypted data it possesses.

[0116] The data processing method for the second server in the data processing system provided in this embodiment has the same or corresponding features as the data processing method for the client in the data processing system described above. The data processing method for the client in the data processing system has been described in detail above, and the embodiment of the data processing method for the second server in the data processing system will not be repeated here, but the effect is the same as above.

[0117] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0118] This invention also provides a data processing system, including a client, a first server, and a second server. The client is connected to both the first and second servers, and the first server is connected to the second server. The first server is the server of the data owner, and the second server is a server with software protection extensions deployed.

[0119] The first server is used to: send encrypted information to the client; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using the first key, and a second key obtained by encrypting the first key;

[0120] The client is used to: receive encrypted information sent by the first server; send the encrypted information to the second server; and process the decrypted data from the second server.

[0121] The second server is used to: upon receiving encrypted information from the client, decrypt the second key using the key in the software protection extension to obtain the first key, and then use the first key to decrypt the encrypted data information to obtain the decrypted data.

[0122] The data processing system provided in this embodiment has the same or corresponding features as the data processing method applied to the client in the data processing system described above. The data processing method applied to the client in the data processing system has been described in detail above, and the embodiment of the data processing system will not be repeated here, but the effect is the same as above.

[0123] Embodiments of the present invention also provide a data processing apparatus applied to a client in a data processing system. The data processing system further includes a first server and a second server, with the client connected to both the first and second servers, and the first server connected to the second server. The first server is the server of the data owner, and the second server is a server with deployed software protection extensions. The apparatus includes:

[0124] The first receiving module is used to receive encrypted information sent by the first server; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using the first key, and a second key obtained by encrypting the first key;

[0125] The first sending module is used to send the encrypted information to the second server; so that the second server can use the key in the software protection extension to decrypt the second key to obtain the first key, and use the first key to decrypt the encrypted data information to obtain the decrypted data;

[0126] The calling module is used to call the decrypted data from the second server for processing.

[0127] In some embodiments, the data processing apparatus further includes:

[0128] The second sending module is used to send a first request to the second server to characterize the software protection extension environment verification, so that the second server generates information to characterize the response to the first request based on the first request; wherein the information to characterize the response to the first request includes at least the environment information of the software protection extension.

[0129] The second receiving module is used to receive information sent by the second server that represents the response to the first request;

[0130] The first determining module is used to determine the environmental trustworthiness of the software protection extension based on information used to characterize the response to the first request.

[0131] The third sending module is used to send a second request to the first server to indicate that the environment is trustworthy, and to trigger the first receiving module, when the environment is determined to be trustworthy.

[0132] In some embodiments, the data processing apparatus further includes:

[0133] The first extraction module is used to extract information from the second request that represents a unique identifier for the software protection extension;

[0134] The fourth sending module is used to send a third request to the second server to characterize the environment verification of the software protection extension based on the information used to characterize the unique identifier of the software protection extension, so that the second server can generate information to characterize the response to the third request based on the third request; wherein the information to characterize the response to the third request includes at least the environment information of the software protection extension.

[0135] The third receiving module is used to receive information sent by the second server that represents the response to the third request;

[0136] The second determining module is used to determine the environmental trustworthiness of the software protection extension based on the information used to characterize the response to the third request.

[0137] The determination and sending module is used to send encrypted information to the client if the environment is determined to be trustworthy.

[0138] In some embodiments, the data processing apparatus includes a first acquisition module for acquiring information that characterizes a unique identifier for software protection extensions.

[0139] The first acquisition module includes:

[0140] The second acquisition module is used to acquire the code segment, data segment, and stack of the software protection extension;

[0141] The connection and acquisition module is used to connect the code segment, data segment, and stack data segment of the software protection extension, and to acquire the fields after the first connection.

[0142] The first calculation module is used to perform a hash operation on the fields after the first concatenation and obtain the first result of the hash operation;

[0143] The third determining module is used to determine, based on the first result, information for a unique identifier that characterizes the software protection extension.

[0144] In some embodiments, the data processing apparatus includes a fourth determining module for determining the environmental trustworthiness of the software protection extension based on information used to characterize the response to the target request.

[0145] The fourth determination module includes:

[0146] The second extraction module is used to extract public key information from the software protection extended certificate information;

[0147] The decryption module is used to decrypt the signature using public key information to obtain the original data digest;

[0148] The second calculation module is used to perform hash calculations on the data to be verified to obtain a digest of the data to be verified; wherein the data to be verified is a first random number or a second random number;

[0149] The comparison module is used to compare whether the original data digest is consistent with the data digest to be verified; if so, the fifth determination module is triggered.

[0150] The fifth module is used to determine the validity of the signature;

[0151] The third acquisition module is used to acquire, after confirming that the signature is valid, the information sent by the second server in response to the target request to represent the unique identity of the software protection extension.

[0152] The third calculation module is used to perform hash calculations on the fields after the first connection on the local end and obtain the second result of the hash calculation; wherein, the local end is either the client or the first server;

[0153] The sixth determining module is used to determine the trustworthiness of the software protection extension's environment as a trustworthy situation when the information used to characterize the software protection extension sent by the second server when responding to the target request is equal to the second result.

[0154] The seventh determining module is used to determine that the environment trustworthiness of the software protection extension is untrustworthy if the information used to characterize the software protection extension sent by the second server when responding to the target request is not equal to the second result.

[0155] For a description of the features in the embodiment corresponding to the data processing device, please refer to the relevant description in the embodiment corresponding to the data processing method, which will not be repeated here.

[0156] Embodiments of the present invention also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above-described data processing method embodiments.

[0157] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above-described data processing method embodiments when it is run.

[0158] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0159] Embodiments of the present invention also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above data processing method embodiments.

[0160] Embodiments of the present invention also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above-described data processing method embodiments.

[0161] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0162] The data processing method, system, electronic device, and medium provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of the present invention. It should be noted that those skilled in the art can make several improvements and modifications to the present invention without departing from the principles of the present invention, and these improvements and modifications also fall within the protection scope of the present invention.

Claims

1. A data processing method, characterized in that, A client is used in a data processing system, which further includes a first server and a second server. The client connects to the first server and the second server, respectively, and the first server connects to the second server. The first server is the server of the data owner, and the second server is a server with deployed software protection extensions. The method includes: Receive encrypted information sent by the first server; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using a first key, and a second key obtained by encrypting the first key; The encrypted information is sent to the second server; so that the second server can decrypt the second key using the key in the software protection extension to obtain the first key, and use the first key to decrypt the encrypted data information to obtain the decrypted data; wherein, if the first key is encrypted using a symmetric encryption algorithm, the key stored in the software protection extension is the same as the second key, and the key stored in the software protection extension is transmitted to the software protection extension environment via the network; the second key is decrypted using the key stored in the software protection extension to obtain the first key; if the first key is encrypted using an asymmetric encryption algorithm, the private key in the software protection extension matches the second key, and the second key is decrypted using the private key in the software protection extension to obtain the first key; The decrypted data from the second server is then processed. The encrypted information also includes information used to characterize the software protection extension; The second key obtained by the first server after encrypting the first key includes: After obtaining the second random number and the information used to characterize the software protection extension, the second connected field is obtained; the second random number is included in the third request, which is a request sent by the first server to the second server to characterize the software protection extension environment verification based on the information used to characterize the software protection extension. Obtain the third result obtained by performing a hash operation on the fields after the second connection, and use the third result as the first key; Obtain the public key of the Software Protection Extension Certificate and the algorithm used to encrypt the first key; The first key is encrypted using the public key of the Software Protection Extended Certificate and the algorithm used to encrypt the first key to obtain the second key.

2. The data processing method according to claim 1, characterized in that, Before receiving the encrypted information sent by the first server, the method further includes: A first request for characterizing the software protection extension environment verification is sent to the second server, so that the second server generates information for characterizing the response to the first request based on the first request; wherein the information for characterizing the response to the first request includes at least the environment information of the software protection extension; Receive the information sent by the second server that represents the response to the first request; The environmental trustworthiness of the software protection extension is determined based on the information used to characterize the response to the first request. Once the environment is determined to be trustworthy, a second request for data acquisition is sent to the first server, and the process proceeds to the step of receiving encrypted information sent by the first server.

3. The data processing method according to claim 2, characterized in that, The environmental information of the software protection extension includes at least the following: information for a unique identifier of the software protection extension, software protection extension certificate information, metadata information for a memory layout, and the security version of the central processing unit. The first request also includes a first random number; the information used to characterize the response to the first request further includes information after the first random number has been signed with a Software Protection Extended Certificate private key.

4. The data processing method according to claim 3, characterized in that, The second request also includes information for a unique identifier representing the software protection extension. After receiving the second request, and before sending the encrypted information to the client, the first server further includes: Extract the information from the second request that represents the unique identifier of the software protection extension; A third request for verifying the environment of the software protection extension is sent to the second server based on the information of the unique identifier used to characterize the software protection extension, so that the second server can generate information for responding to the third request based on the third request; wherein the information for responding to the third request includes at least the environment information of the software protection extension; Receive the information sent by the second server that represents the response to the third request; The environmental trustworthiness of the software protection extension is determined based on the information used to characterize the response to the third request. Once the environment is determined to be trustworthy, the process proceeds to sending encrypted information to the client.

5. The data processing method according to claim 4, characterized in that, The information used to characterize the response to the third request also includes information after the second random number has been signed with the private key of the Software Protection Extended Certificate.

6. The data processing method according to claim 5, characterized in that, Information used to obtain a unique identifier for software protection extensions includes: Obtain the code segment, data segment, and stack of the software protection extension; Connect the code segment, data segment, and stack data segment of the software protection extension, and obtain the fields after the first connection; Perform a hash operation on the fields after the first concatenation and obtain the first result of the hash operation; Based on the first result, information for a unique identifier used to characterize the software protection extension is determined; The target request includes either the first request or the third request. Determining the environmental trustworthiness of the software protection extension based on information used to characterize the response to the target request includes: Extract public key information from the software protection extended certificate information; The signature is decrypted using the public key information to obtain the original data digest; A hash calculation is performed on the data to be verified to obtain a digest of the data to be verified; wherein, the data to be verified is either the first random number or the second random number; Compare whether the original data digest is consistent with the data digest to be verified; If the original data digest matches the data digest to be verified, the signature is deemed valid. After confirming that the signature is valid, obtain the information of the unique identifier used to characterize the software protection extension sent by the second server when responding to the target request; On the local end, a hash operation is performed on the fields after the first connection, and a second result of the hash operation is obtained; wherein, the local end is the client or the first server; If the information used to characterize the software protection extension sent by the second server when responding to the target request is equal to the second result, the environmental trustworthiness of the software protection extension is determined to be a trustworthy situation. Conversely, if the environment for the software protection extension is deemed untrustworthy, then the trustworthiness of the environment is determined to be untrustworthy.

7. A data processing system, characterized in that, It includes a client, a first server, and a second server. The client is connected to both the first server and the second server, and the first server is connected to the second server. The first server is the server of the data owner, and the second server is a server with software protection extensions deployed. The first server is configured to: send encrypted information to the client; wherein the encrypted information includes at least encrypted data information obtained by encrypting data using a first key, and a second key obtained by encrypting the first key; The client is used to: receive encrypted information sent by the first server; send the encrypted information to the second server; and process the decrypted data in the second server. The second server is configured to: upon receiving the encrypted information sent by the client, decrypt the second key using the key in the software protection extension to obtain the first key, and decrypt the encrypted data information using the first key to obtain decrypted data; wherein, if the first key is encrypted using a symmetric encryption algorithm, the key stored in the software protection extension is the same as the second key, and the key stored in the software protection extension is transmitted to the software protection extension environment via the network; decrypt the second key using the key stored in the software protection extension to obtain the first key; if the first key is encrypted using an asymmetric encryption algorithm, the private key in the software protection extension matches the second key, and decrypt the second key using the private key in the software protection extension to obtain the first key; The encrypted information also includes information used to characterize the software protection extension; The second key obtained by the first server after encrypting the first key includes: After obtaining the second random number and the information used to characterize the software protection extension, the second connected field is obtained; the second random number is included in the third request, which is a request sent by the first server to the second server to characterize the software protection extension environment verification based on the information used to characterize the software protection extension. Obtain the third result obtained by performing a hash operation on the fields after the second connection, and use the third result as the first key; Obtain the public key of the Software Protection Extension Certificate and the algorithm used to encrypt the first key; The first key is encrypted using the public key of the Software Protection Extended Certificate and the algorithm used to encrypt the first key to obtain the second key.

8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the data processing method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the data processing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Internet of Things data privacy protection method based on block chain and trusted hardware

    CN110086804A

  • Cross-domain secure multi-party computing method and device based on trusted execution environment

    CN111082934A