Secure dataset management

By creating keyword indexes in a trusted execution environment, managing and securely accessing data sets in an untrusted execution environment, the challenges of porting difficulty and security improvement in data storage applications in the trusted execution environment in the prior art are solved, and a more efficient and secure data storage solution is achieved.

CN110489971BActive Publication Date: 2025-05-23MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN201810462520.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-05-15
Publication Date
2025-05-23
Estimated Expiration
2038-05-15

AI Technical Summary

Technical Problem

The prior art requires a lot of modification when porting data storage applications to a trusted execution environment, which leads to high overhead and difficult to widely use, and it is difficult to achieve higher security without changing the hardware configuration of existing data storage systems.

Method used

Secure management of data sets is achieved by creating keyword indexes in a trusted execution environment for managing and secure access to data sets in an untrusted execution environment. The method includes obtaining records in the dataset, creating keyword indexes in a trusted execution environment based on the record's keywords, and updating the keyword index when the records are added or deleted in the dataset.

Benefits of technology

This method simplifies the migration process of data storage applications in a trusted execution environment, reduces overhead, and improves data storage security without changing the hardware configuration of existing data storage systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110489971B_ABST
    Figure CN110489971B_ABST
Patent Text Reader

Abstract

According to the implementation of the present disclosure, a scheme for secure data set management is proposed. In the scheme, a data set including at least one record is obtained, and the records in the at least one record include at least: a keyword for identifying the record, and a value corresponding to the keyword. Then, based on the respective keywords of the at least one record, a keyword index is created in a trusted execution environment. The keyword index herein describes a keyword set of at least one record. Through the scheme, a keyword index can be created for the records in the data set in a trusted execution environment, and based on the keyword index, the data set can be managed in a more secure and reliable manner to detect anomalies that may occur in the data set.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] With the development of data storage technology and data security technology, data storage solutions based on encryption-decryption technology have been developed to improve the security of data storage. However, stored data are usually threatened by malicious programs such as viruses or many other risks, so it is expected to develop a more secure and reliable data storage environment. Especially for financial institutions or institutions such as government agencies, it is necessary to further improve the security of data management. At present, data security technologies with higher security levels have been proposed. For example, a trusted execution environment (Trusted Execution Environment, abbreviated as TEE) based on hardware and / or software can effectively isolate threats from the outside world and provide a secure and protected execution environment for applications.

[0002] However, on the one hand, the trusted execution environment is usually expensive, and the computing resources and storage resources provided are limited. On the other hand, when it is desired to transplant existing data storage-based applications into the trusted execution environment, it is usually necessary to modify both the existing applications and the data storage to adapt to the trusted execution environment, and modifying the existing applications and data storage will inevitably incur additional overhead. Therefore, it is desirable to provide a technical solution that can improve the security of applications, especially those based on data storage, in a more convenient and reliable manner. Summary of the invention

[0003] According to the implementation of the present disclosure, a solution for secure data set management is provided. In the solution, a data set including at least one record is obtained, and the record in the at least one record includes at least: a keyword for identifying the record, and a value corresponding to the keyword; based on the respective keywords of the at least one record, a keyword index is created in a trusted execution environment, and the keyword index describes a keyword set of the at least one record.

[0004] This Summary is provided to introduce a selection of concepts in a simplified form that are further described in the Detailed Description below. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS

[0005] Figure 1 A block diagram schematically illustrates a computing environment capable of implementing multiple implementations of the present disclosure;

[0006] Figure 2 A schematic diagram of a secure data set management solution according to an implementation of the present disclosure is shown;

[0007] Figure 3 A flowchart of a method for secure data set management according to one implementation of the present disclosure is schematically shown;

[0008] Figure 4 A flowchart of a method for adding a new record to a data set according to one implementation of the present disclosure is schematically shown;

[0009] Figure 5 Schematically illustrates a detailed block diagram for secure data set management according to one implementation of the present disclosure;

[0010] Fig. 6A and Figure 6B Schematically showing a block diagram for detecting anomalies in a data set according to an implementation of the present disclosure;

[0011] Figure 7 A block diagram for managing a blockchain-based database according to one implementation of the present disclosure is schematically shown; and

[0012] Figure 8 A block diagram for managing a relational database according to one implementation of the present disclosure is schematically shown.

[0013] In these drawings, the same or similar reference symbols are used to designate the same or similar elements. DETAILED DESCRIPTION

[0014] The present disclosure will now be discussed with reference to several example implementations. It should be understood that these implementations are discussed only to enable those skilled in the art to better understand and thus implement the present disclosure, and do not imply any limitation on the scope of the present subject matter.

[0015] As used herein, the term "including" and variations thereof are to be interpreted as open-ended terms meaning "including but not limited to". The term "based on" is to be interpreted as "based at least in part on". The terms "an implementation" and "an implementation" are to be interpreted as "at least one implementation". The term "another implementation" is to be interpreted as "at least one other implementation". The terms "first", "second", etc. may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0016] Currently, several companies have developed their own trusted execution environments. For example, The company has developed a technology called Software Guard Extensions (SGX). SGX can protect applications and corresponding data stores (for example, databases) from being disclosed or modified. The technology makes this protection possible by using enclave technology, that is, deploying applications and databases in protected execution areas in memory. Based on SGX technology, applications that expect higher security guarantees can be placed in enclaves. Applications running in enclaves are protected from attacks by malicious programs, and even the operating system or hypervisor cannot affect the applications and databases in the enclave. In this way, a hardware-based trusted execution environment can be provided.

[0017] At present, software-based trusted execution environment technology solutions have also been proposed. For example, The Windows Virtual Secure Mode (VSM) developed by the company is an example of a software-based trusted execution environment. Based on VSM technology, it can provide higher security for applications and data without the need to purchase additional specialized hardware.

[0018] It will be understood that although SGX technology and VSM technology are used as specific examples of trusted execution environments in the context of this disclosure, those skilled in the art will understand that with the advancement of technology, more trusted execution environments can be developed. And the trusted execution environment described in this disclosure can be other execution environments that have been developed currently or will be developed in the future.

[0019] At present, technical solutions for migrating existing applications and databases into a trusted execution environment have been developed. In one technical solution, the database and the applications for accessing the database can all be migrated into the trusted execution environment. However, this requires a great deal of manpower and time, and places extremely high demands on various resources of the trusted execution environment (e.g., computing resources and storage resources). Therefore, this technical solution is difficult to be widely used, especially difficult to be applied to applications involving large amounts of data.

[0020] In another technical solution, the application and the interface part associated with accessing the database in the application can be transplanted into the trusted execution environment. Although this method can reduce the various overheads involved during the transplantation to a certain extent, this technical solution still requires a large number of technicians to rewrite the code of the database interface part, and the technical level of the technicians is relatively high.

[0021] Therefore, it is desirable to provide a technical solution that can improve the security of applications and data storage in a convenient and effective manner. Further, it is desirable that the technical solution can be compatible with existing data storage systems and achieve more secure data storage without changing the hardware configuration of the existing data storage systems as much as possible.

[0022] Example Environment

[0023] The basic principles and several example implementations of the present disclosure are explained below with reference to the accompanying drawings. Figure 1 Schematically illustrates a block diagram of a computing environment 100 capable of implementing multiple implementations of the present disclosure. Figure 1 As shown, the computing environment 100 may include execution environments with different security levels. For example, based on the SGX technology or VSM technology described above, the computing device 190 may include a trusted execution environment 170 with a higher security level, and an application 172 may be run in the trusted execution environment 170. Further, the computing device 190 may communicate with an untrusted execution environment 180 with a lower security level in the outside world. For example, an application 172 in the trusted execution environment 170 may access a data set 182 in the untrusted execution environment 180.

[0024] In this example environment, the trusted execution environment 170 can be based on, for example, The SGX technology solution developed by the company or by The VSM technical solution developed by the company. The untrusted execution environment 180 herein may refer to a conventional computing environment, in other words, a conventional computing environment that does not use SGX technology or VSM technology. It will be understood that although only SGX and VSM technologies are used as specific examples of the trusted execution environment 170 in this disclosure, with the emergence of more data security technologies, the trusted execution environment 170 herein may be any trusted execution environment that is now known or will be developed in the future.

[0025] It should be understood that Figure 1 The computing device 190 shown is merely exemplary and should not constitute any limitation on the functionality and scope of the implementation described in the present disclosure. Figure 1 As shown, computing device 190 includes a computing device in the form of a general-purpose computing device 190. Components of computing device 190 may include, but are not limited to, one or more processors or processing units 110, memory 120, storage device 130, one or more communication units 140, one or more input devices 150, and one or more output devices 160.

[0026] In some implementations, the computing device 190 can be implemented as various user terminals or service terminals. The service terminal can be a server, a large computing device, etc. provided by various service providers. The user terminal is such as any type of mobile terminal, fixed terminal or portable terminal, including a mobile phone, a site, a unit, a device, a multimedia computer, a multimedia tablet, an Internet node, a communicator, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an e-book device, a gaming device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. It is also foreseeable that the computing device 190 can support any type of interface for the user (such as a "wearable" circuit, etc.).

[0027] Processing unit 110 may be a real or virtual processor and is capable of performing various processes according to a program stored in memory 120. In a multi-processor system, multiple processing units execute computer executable instructions in parallel to increase the parallel processing capabilities of computing device 190. Processing unit 110 may also be referred to as a central processing unit (CPU), a microprocessor, a controller, or a microcontroller.

[0028] The computing device 190 typically includes a plurality of computer storage media. Such media may be any available media accessible to the computing device 190, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 120 may be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 130 may be a removable or non-removable medium and may include a machine-readable medium such as a memory, a flash drive, a disk, or any other medium that can be used to store information and / or data and can be accessed within the computing device 190.

[0029] The computing device 190 may further include additional removable / non-removable, volatile / non-volatile storage media. Figure 1 Not shown in the figure, a disk drive for reading or writing from a removable, nonvolatile disk and an optical disk drive for reading or writing from a removable, nonvolatile optical disk may be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data medium interfaces.

[0030] The communication unit 140 enables communication with another computing device via a communication medium. Additionally, the functions of the components of the computing device 190 can be implemented in a single computing cluster or multiple computing machines that can communicate via a communication connection. Therefore, the computing device 190 can operate in a networked environment using a logical connection with one or more other servers, a personal computer (PC), or another general network node.

[0031] Input device 150 may be one or more various input devices, such as a mouse, keyboard, tracking ball, voice input device, etc. Output device 160 may be one or more output devices, such as a display, a speaker, a printer, etc. Computing device 190 may also communicate with one or more external devices (not shown) through communication unit 140 as needed, such as storage devices, display devices, etc., communicate with one or more devices that allow a user to interact with computing device 190, or communicate with any device that allows computing device 190 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).

[0032] You can Figure 1 The method for secure data set management is implemented in the computing device 190 shown. By adopting the method disclosed in the present invention, it is possible to ensure that the application 172 in the trusted execution environment 170 accesses the data set 182 in the untrusted execution environment 180 in a more secure and reliable manner. In summary, a communication interface can be established between the trusted execution environment 170 and the untrusted execution environment 180 to improve the security of the data set 182.

[0033] How it works

[0034] In the following, the various figures describe in detail the working principle of the solution of the present disclosure. According to the implementation of the present disclosure, a solution for secure data set management is provided. Figure 2 Briefly describe the program. Figure 2 Schematically shows a schematic block diagram 200 for secure data set management according to one implementation of the present disclosure. Figure 2 As shown, between the application 172 in the trusted execution environment 170 and the data set 182 in the untrusted execution environment 180, a security management module 210 may be provided as an interface between the application 172 and the data set 182. The security management module 210 receives a request from the application 172 and accesses the data set 182 based on the request. Then, the security management module 210 returns the result from the data set 182 to the application 172.

[0035] In this implementation, the data set 182 may include a plurality of records 230, 232, etc., and each record may include a key 220 for identifying the record and a value 222 corresponding to the key 220. For example, the data set 182 may store data about a bank account, in which case the key 220 may represent, for example, the account name, and the value 222 may represent, for example, the account balance. It will be appreciated that although in Figure 2 The data set 182 including two fields, a keyword and a value, is schematically shown in FIG. 1 . In other implementations, the data set 182 may include more fields. For example, the data set 182 may also include other attributes of the account, such as gender, occupation, etc.

[0036] It will be understood that since the data set 182 is deployed in the untrusted execution environment 180, it is vulnerable to attacks by malicious programs such as viruses. The malicious program may add new records to the data set 182, for example, inserting records of accounts that do not exist therein. Alternatively, the malicious program may also delete records of normal accounts from the data set 182. At this time, even if the application 172 runs in the secure and reliable trusted execution environment 170, since the data security in the data set 182 in the untrusted execution environment 180 has been destroyed, the application 172 will obtain an erroneous result.

[0037] like Figure 2 As shown, in order to improve the security of the data set 182, the implementation of the present disclosure provides a security management module 210 and a keyword index 212. Specifically, a data set 182 including at least one record may be obtained. Then, based on the respective keywords 220 of at least one record in the data set 182, a keyword index 212 is created in the trusted execution environment 170. Here, the keyword index 212 may describe a keyword set of at least one record, and may be used to manage the data set 182 with a higher security level.

[0038] In the implementation of the present disclosure, the keyword index 212 records the set of keywords in the data set 182 obtained under normal conditions. Even if an abnormality occurs in the data set 182 later (for example, new account information is added by a malicious program), by comparing the keyword index 212 constructed based on the correct data set with the keywords in the data set 182, it can be determined whether there is an abnormality in the data set 182. In this way, the security of the data set 182 can be improved, thereby ensuring the reliability of the application 172 in the trusted execution environment 170.

[0039] Example Process

[0040] In the following, we will refer to Figure 3 The detailed operation process of the method disclosed in the present invention is described in detail. Figure 3A flowchart 300 of a method for secure data set management according to one implementation of the present disclosure is schematically shown. Figure 3 As shown, a data set 182 including at least one record may be obtained 310. In this implementation, each record in the at least one record includes at least: a keyword 200 for identifying the record, and a value 222 corresponding to the keyword. It will be appreciated that the data set 182 may be obtained in different ways. For example, since the application 172 runs in the trusted execution environment 170, the data from the application 172 may be considered to be authentic and reliable data. Thus, the data set 182 may be obtained when the application 172 adds a record to the data set 182. For another example, the records in the data set 182 may also be obtained at any time point during the period when the data set 182 is confirmed to be normal. At this point, since the records in the data set 182 are correct and have not been attacked by malicious programs, the keyword index 212 created based on the records in the obtained data set 182 will be safe and reliable, and thus may serve as a basis for subsequent management of the data set 182.

[0041] Then, a keyword index 212 may be created 320 in the trusted execution environment 170 for managing the data set 182 based on the respective keywords 220 of the at least one record. Here, the keyword index 212 describes a set of keywords of the at least one record. It will be appreciated that the keyword index 212 may be created in a variety of ways. For example, in a simplified implementation, a list may be created, and the keywords of all records in the data set 182 may be added to the list to form the keyword index 212. For another example, a set may also be created, and the keywords of all records in the data set 182 may be added to the set to form the keyword index 212.

[0042] It will be understood that when the data set 182 includes a large number of records, the keyword index 212 created in the list or set manner described above will take up a large amount of storage space and may cause low retrieval efficiency when the data set 182 is managed later. Therefore, the keyword index 212 can also be created based on a hash function. Specifically, each keyword 220 in the data set 182 can be mapped to a bit in the bitmap through a hash function. When it is necessary to determine whether a specific keyword is included in the keyword index 212, the value of the bit corresponding to the specific keyword in the bitmap can be found. Based on the above principles, those skilled in the art can use different hash functions to create the keyword index 212. Specifically, since the Bloom filter has huge advantages in storage space and search time, the keyword index 212 can be implemented based on the Bloom filter.

[0043] It will be understood that during the operation of the application 172, the application 172 may add new records to the data set 182. For example, in the above example of the bank account database, when a user opens a new account at the bank, a new account record may be added to the data set 182. In this case, in addition to updating the records in the data set 182, the content of the keyword index 212 also needs to be updated.

[0044] Specifically, Figure 4 Schematically illustrates a flowchart 400 of a method for adding a new record to a data set 182 according to one implementation of the present disclosure. Figure 4 As shown, if a request to add a new record to the data set 182 is received 410, the keyword index 212 can be updated 420 based on the keyword of the new record and the new record can be added to the data set 182. It will be understood that although Figure 4 The operations of updating the keyword index 212 and adding a new record to the data set 182 are shown in a serial manner. In other implementations, the above operations can be performed in parallel or in a reverse order.

[0045] It will be understood that during the operation of the application 172, the application 172 may delete existing records from the data set 182. For example, in the above bank account database example, when a user cancels an account from the bank, the record of the existing account may be deleted from the data set 182. At this time, in addition to updating the records in the data set 182, the content of the keyword index 212 also needs to be updated.

[0046] It will be understood that, although the present disclosure describes a case where new records can be added to the data set 182 and existing records can be deleted from the data set 182, in some cases, only new records can be added to the data set 182, but existing records can not be deleted from it. For example, assuming that the application 172 is an application that monitors the running status of the computing device 190, as the computing device 190 runs, the application 172 will insert new log data into the data set 182 at a predetermined time interval. At this time, it is not allowed to delete the existing logs from the data set 182.

[0047] Example implementation in a trusted execution environment

[0048] According to an exemplary implementation of the present disclosure, in order to manage the data set 182 in a more secure and reliable manner, a keyword index 212 may be created in the trusted execution environment 170. Figure 5 More specific implementations in the trusted execution environment 170 are described in detail. Figure 5 Schematically shows a detailed block diagram 500 for security management of a data set 182 according to one implementation of the present disclosure. Figure 5As shown, the security management module 210 according to the present disclosure may be deployed in the trusted execution environment 170 .

[0049] It will be understood that since the security level provided by the trusted execution environment 210 is much higher than that of the untrusted execution environment 180, creating and storing the keyword index 212 in the trusted execution environment 170 will ensure that the keyword index 212 itself is secure and that the keyword index 212 is protected from attacks by malicious programs such as viruses. At this point, the keyword index 212 is trustworthy and can be used as a basis for subsequent comparison with each keyword in the data set 182. In this way, the security of the data set 182 can be further improved.

[0050] In an exemplary implementation of the present disclosure, the security management module 210 may further include a cache 510. At this time, if an access request for accessing the data set 182 is received, a record associated with the access request may be added to the cache 510 in the trusted execution environment 170 (e.g., Figure 5 170). It will be appreciated that the number of various resources included in the trusted execution environment 170 is limited. In some implementations, the size of the cache 510 may be set based on factors such as the specific configuration of the trusted execution environment 170 and the requirements of the application 172 for data access efficiency. The cache 510 may be updated, for example, according to the least recently used principle. In this implementation, the cache 510 is located inside the trusted execution environment 170, which can provide higher security on the one hand and faster response speed for the application 172 on the other hand.

[0051] In an exemplary implementation of the present disclosure, the method according to the present disclosure may be executed in a trusted execution environment 170. For example, the following may be deployed: Figure 5 The security management module 210 shown in FIG. 1 (e.g., implemented as a computer program) is loaded into the trusted execution environment 170. In this implementation, the security management module 210, the keyword index 212, and the cache 510 for performing security management on the data set 182 are all deployed in the trusted execution environment 170. In this way, it can be ensured that all factors involved in performing security management are secure. Therefore, it can be considered that Figure 5 All operations performed within the illustrated trusted execution environment 170 are secure.

[0052] Check the status of the dataset

[0053] In an exemplary implementation of the present disclosure, it is possible to determine whether there is an anomaly in the data set 182 based on whether the keywords in the data set 182 match the keywords in the keyword index 212. Taking the data set 182 storing the bank account information described above as an example, it is assumed that the data set 182 located in the untrusted execution environment 180 is attacked and a new account record is added thereto. At this time, by comparing the keywords in the data set 182 with the keyword index 212, it can be found that the new account record does not exist in the keyword index 212, and then it can be determined whether there is an anomaly in the data set 182.

[0054] It will be understood that when the keyword index 212 is implemented in different ways, the way of judging "match" / "no match" may be different. For example, when the list / set described above is used to implement the keyword index 212, when a specific keyword is included in the list / set, the specific keyword is considered to match the keyword index 212; otherwise, it is considered to not match. For another example, when the hash function described above is used to implement the keyword index 212, by checking the value of the bit corresponding to the specific keyword in the keyword index 212, a "match" / "no match" result can be obtained. In one example, if the value of the bit corresponding to the specific keyword is "1" (or other predefined values), the judgment result is "match", otherwise the judgment result is "no match".

[0055] In an exemplary implementation of the present disclosure, the above comparison operation may be performed periodically. Alternatively, the above comparison operation may also be performed when an access request for the data set 182 is received. Specifically, it may be determined whether an abnormality occurs in the data set 182 based on whether the comparison result is "match" / "mismatch".

[0056] In an exemplary implementation of the present disclosure, a target keyword associated with a request may be determined based on a received request. Here, the target keyword refers to a keyword of a record that is expected to be accessed and is defined in the request. For example, for a request to access a record related to ALICE, the target keyword is "ALICE". For example, assume that the keyword index 212 includes ALICE and BOB. If a request to read a record with a keyword of ALICE is received, it may first be checked whether there is a record with a keyword of ALICE in the data set 182. If so, the found record is returned to the trusted execution environment 170 in an encrypted form. If the decryption is successful in the trusted execution environment 170 environment, it is determined that the record with a keyword of ALICE is a record that originally existed in the data set 182, and is not a record added by a malicious program. At this point, it may be determined that the data set 182 is in a normal state, and the found target record is returned. Alternatively, if a record with a keyword of ALICE is found in the data set 182, it may also be first determined whether the keyword ALICE exists in the keyword index 212. If so, it indicates that the data set 182 is normal and subsequent decryption operations may be performed. In this way, it is possible to determine in advance whether the returned encrypted record is authentic, and only perform subsequent decryption operations if it is authentic.

[0057] In an exemplary implementation of the present disclosure, it is assumed that the keyword index 212 includes ALICE and BOB. If a request to read a record with the keyword TOM is received, a search may be performed in the data set 182 to determine whether a target record with the keyword TOM is included. If the target record including the keyword TOM is not found in the database 182, it may be further determined whether the keyword TOM exists in the keyword index 212. If not, an indication that there is no record with the keyword TOM in the data set 182 may be returned. At this point, the data set 182 is in a normal state.

[0058] The above has already introduced the situation that the data set 182 is in a normal state. Fig. 6A and Figure 6B How to detect anomalies in data set 182 is described in detail. Fig. 6A A block diagram 600A for detecting anomalies in a data set according to one implementation of the present disclosure is schematically shown. Fig. 6A The keyword index 620A created by the implementation of the present disclosure is shown, and the keyword index 620A includes two keywords ALICE and BOB. It should be noted that since the keyword index 620A is created and stored in the trusted execution environment 170, the keyword index 620A can be considered safe and reliable.

[0059] Assume that the data set 610A located in the untrusted execution environment 180 has been attacked and a record about a new account TOM has been added therein. At this time, when a read request 630A for reading information about the account TOM from the data set 610A is received, an encrypted record 640A (which records that the balance of the account TOM is 3,000 yuan) can be returned from the data set 610A. In the trusted execution environment 170, if the decryption fails, it means that the keyword TOM does not exist in the keyword index 620A. Therefore, it can be determined that the record about the account TOM in the data set 610A is added by a malicious program, and then it can be determined that there is an abnormality in the data set 610A. Alternatively, it can also be determined first whether the keyword TOM exists in the keyword index 620A without performing decryption, and if it does not exist, it can be directly determined that the data set 610A is abnormal. In this way, in addition to the existing data security management based on encryption-decryption, an additional data security management solution can also be provided.

[0060] Figure 6B A block diagram 600B for detecting anomalies present in a data set 182 according to an implementation of the present disclosure is schematically shown. Figure 6B The keyword index 620B created by the implementation of the present disclosure is shown, and the keyword index 620B includes three keywords: ALICE, BOB, and TOM. It should be noted that since the keyword index 620B is created and stored in the trusted execution environment 170, the keyword index 620B can be considered safe and reliable.

[0061] Assume that the data set 610B in the untrusted execution environment 180 is attacked and the record of the account TOM is deleted. At this time, when the read request 630B for reading the information about the account TOM from the data set 610B is received, the query result is empty. At this time, since the keyword TOM is included in the keyword index 620B but the query result is empty, it can be determined that the record of the account TOM in the data set 610B is deleted by the malicious program, and it can be determined that there is an abnormality in the data set 610B.

[0062] In the above implementation, whether there is an anomaly in the data set 182 can be determined simply by comparing whether the keywords in the data set 182 match the keyword index 212. In this way, the state of the data set 182 can be detected in a simpler and more effective manner without requiring a large amount of computation.

[0063] Although the above describes the situation where a malicious program can add new records to the data set 182 and delete existing records from the data set 182. For example, when the data set 182 is used to store log records, it can only be detected that a new record is added to the data set 182.

[0064] Example of a dataset

[0065] In the above, a simple data set 182 including an account name and an account balance is used as an example to describe a specific process for security management of a data set 182. In the following, more specific examples of the data set 182 will be described. It should be noted that in the context of the present disclosure, the number of fields included in each record in the data set 182 is not limited. In other implementations, the data set may also include more fields. For example, the data set 182 for storing bank account data may also include other attributes of the account, such as gender, occupation, etc.

[0066] In an exemplary implementation of the present disclosure, the data set 182 may be a data set of a database based on a blockchain, and a record in at least one record in the data set 182 describes the keywords and values ​​of nodes in the blockchain. It will be understood that the blockchain is a chain data structure that combines data blocks in a sequential manner in chronological order, and the data structure of the blockchain provides traceability and verifiable integrity. The data of each node in the blockchain cannot be modified, but the newly added nodes can be added to the end of the blockchain in an additional manner. Since the blockchain technology can effectively prevent the tampering of the data and can record the operation history of the stored data in a more reliable way, the blockchain technology has been widely used.

[0067] See below for Figure 7 More details of applying the method of the present disclosure in a blockchain-based database are described in detail. Figure 7 A block diagram 700 for managing a data set of a blockchain-based database according to one implementation of the present disclosure is schematically shown. Figure 7 The upper part schematically shows a logical view of a blockchain-based database. In this logical view, block 1 (represented by node 710) and block 2 (represented by node 720) have been linked together, and the later node 720 records events that occurred at a later point in time.

[0068] Blockchains can be created based on Merkle trees. It will be understood that Merkle is a tree structure, such as a binary tree or a multi-branch tree. The leaf nodes of a Merkle tree can have values ​​(including data related to the content that is desired to be saved), while the values ​​of non-leaf nodes are calculated based on the values ​​of all leaf nodes below it. For example, in a Merkle hash tree, leaf nodes can store data that needs to be saved (e.g., account information including account names and account balances as described above), while non-leaf nodes store hash values ​​of the contents of the child nodes of the non-leaf nodes.

[0069] In such Figure 7 In the Merkle tree shown, node 710 can record the account information at the first moment, and the child node 712 of node 710 can record, for example, the balance of account ALICE as 1,000 yuan. Assuming that at the second moment, 500 yuan is transferred from account ALICE to account BOB, the balances in account ALICE and account BOB will change at this time. Node 720 can record the information of each account at the second moment. For example, leaf nodes 728 and 730 can record the balances of account ALICE and account BOB at the second moment as 500 yuan and 500 yuan respectively. Leaf node 724 can record the transfer operation from account ALICE to account BOB. The data of other intermediate nodes can be determined according to the principle of Merkle.

[0070] Figure 7 The lower part shows a physical view for storing a blockchain-based database. In the physical view, data in each node is stored in a "keyword-value" manner. For example, record 740 stores information about block 1, where the hash value of block 1 is stored in the "keyword" field, and the data of block 1 is stored in the "value" field. The data of other nodes in the logical view can also be stored in a similar manner, which will not be repeated here. It will be understood that in Figure 7 The schematic diagram only schematically shows a schematic blockchain storing account information at the first moment and the second moment. In other implementations, the blockchain-based database may also include account information at more moments, or may also include more complex operations such as deposits, withdrawals, and transfers.

[0071] Based on the principles described above, no matter what the logical view of the blockchain-based database is, the physical storage will include the following: Figure 7 The data set in the physical view shown. Thus, the method described in the present disclosure can be used for the physical storage of the blockchain. In an exemplary implementation of the present disclosure, the data set 182 in the untrusted execution environment 180 described above can be the physical storage of the blockchain. Specifically, each record included in the physical storage of the blockchain can be first obtained, and a keyword index 212 can be constructed based on the corresponding keywords in each record, and used to manage the blockchain database with a higher security level during the operation of the blockchain database. In this implementation, the physical storage of the blockchain itself can be deployed in the untrusted execution environment 180 as described above, and the application 172 for accessing the blockchain database (for example, a bank's account management application) can be deployed in the trusted execution environment 170.

[0072] In this way, the blockchain-based database can benefit from the security guarantee of blockchain technology on the one hand, and on the other hand, the blockchain-based database can also benefit from the additional guarantee provided by the present disclosure of monitoring whether anomalies occur in the physical storage of the blockchain in the trusted execution environment 170. It will be understood that although the above describes the situation where a malicious program may add or delete records to the data set 182 in the untrusted execution environment 180, in the blockchain-based database, since the records in the physical storage based on the blockchain are append-type and immutable, it only involves the situation of detecting whether a record is added to the data set.

[0073] In an exemplary implementation of the present disclosure, the data set 182 in the untrusted execution environment 180 described above may also be a data table in a relational database. Figure 8 A block diagram 800 for managing a relational database according to one implementation of the present disclosure is schematically shown. Specifically, Figure 8 A schematic diagram of a data table for recording a log of an operating system is schematically shown, wherein a keyword field can store timestamp data, and a value field can store the detected state of the operating system. For example, record 810 can represent the state of the operating system at 00:00 on January 1, 2018: the CPU utilization rate is 50%, and the memory utilization rate is 20%. In this implementation, since the log records are additional and cannot be modified, it only involves detecting whether a record has been added to the data set. In an exemplary implementation of the present disclosure, when the data set 182 is a data table of other forms (such as the bank account database described above), anomalies in which a malicious program adds new records to the data set 182 or deletes existing data therefrom can also be detected.

[0074] In this way, Figure 8 On the one hand, the database shown can benefit from the security guarantee of the database itself, for example, based on encryption-decryption technology. On the other hand, the database can also benefit from the additional guarantee provided by the present disclosure on whether anomalies occur in the database in the trusted execution environment 170.

[0075] Example Implementation

[0076] Some example implementations of the present disclosure are listed below.

[0077] In one aspect, the present disclosure provides a computer-implemented method, comprising: obtaining a data set including at least one record, wherein the record in the at least one record includes at least: a keyword for identifying the record, and a value corresponding to the keyword; and creating a keyword index in a trusted execution environment based on the respective keywords of the at least one record, wherein the keyword index describes a keyword set of the at least one record.

[0078] In some implementations, the method further includes: in response to receiving a request to add a new record to the data set, updating the keyword index based on a keyword of the new record; and adding the new record to the data set.

[0079] In some implementations, the method further includes: in response to receiving a request to read a record in a data set, determining a target keyword associated with the request; in response to not finding a target record including the target keyword in the data set, comparing the target keyword with a keyword index; and in response to the target keyword matching the keyword index, providing an indication of an anomaly occurring in the data set.

[0080] In some implementations, the method further includes providing an indication that a record associated with the request is not included in the data set in response to the target keyword not matching the keyword index.

[0081] In some implementations, the method further includes: in response to receiving a request to read a record in a data set, determining a target keyword associated with the request; in response to finding a target record including the target keyword in the data set, comparing the target keyword with a keyword index; and in response to the target keyword matching the keyword index, providing an indication that the target record associated with the request is included in the data set.

[0082] In some implementations, the method further includes providing an indication that an anomaly occurs in the data set in response to the target keyword not matching the keyword index.

[0083] In some implementations, the data set is a data set of a blockchain-based database, and a record in at least one record in the data set describes a key and a value of a node in the blockchain.

[0084] In some implementations, the data set is stored in an untrusted execution environment.

[0085] In some implementations, the method further includes: in response to receiving an access request for accessing the data set, adding a record associated with the access request to a cache in the trusted execution environment.

[0086] In some implementations, the method is performed in a trusted execution environment.

[0087] In another aspect, the present disclosure provides a computer-implemented device. The device includes: a processing unit; and a memory, coupled to the processing unit and containing instructions stored thereon, which, when executed by the processing unit, cause the device to perform the following actions. The actions include: obtaining a data set including at least one record, wherein the record in the at least one record includes at least: a keyword for identifying the record, and a value corresponding to the keyword; based on the respective keywords of the at least one record, creating a keyword index in a trusted execution environment, the keyword index describing a keyword set of the at least one record.

[0088] In some implementations, the actions further include: in response to receiving a request to add a new record to the data set, updating the keyword index based on a keyword of the new record; and adding the new record to the data set.

[0089] In some implementations, the action further includes: in response to receiving a request to read a record in a data set, determining a target keyword associated with the request; in response to not finding a target record including the target keyword in the data set, comparing the target keyword with a keyword index; and in response to the target keyword matching the keyword index, providing an indication of an anomaly occurring in the data set.

[0090] In some implementations, the actions further include providing an indication that a record associated with the request is not included in the data set in response to the target keyword not matching the keyword index.

[0091] In some implementations, the action further includes: in response to receiving a request to read a record in a data set, determining a target keyword associated with the request; in response to finding a target record including the target keyword in the data set, comparing the target keyword with a keyword index; and in response to the target keyword matching the keyword index, providing an indication that the target record associated with the request is included in the data set.

[0092] In some implementations, the actions further include providing an indication that an anomaly occurs in the data set in response to the target keyword not matching the keyword index.

[0093] In some implementations, the data set is a data set of a blockchain-based database, and a record in at least one record in the data set describes a key and a value of a node in the blockchain.

[0094] In some implementations, the data set is stored in an untrusted execution environment.

[0095] In some implementations, the actions further include: in response to receiving an access request to access the data set, adding a record associated with the access request to a cache in the trusted execution environment.

[0096] In some implementations, the method is executed in a trusted execution environment.

[0097] In yet another aspect, the present disclosure provides a non-transitory computer storage medium comprising machine-executable instructions, which when executed by a device cause the device to perform the method of any of the above aspects.

[0098] In yet another aspect, the present disclosure provides a computer program product, which is tangibly stored in a non-transitory computer storage medium and includes machine-executable instructions, which when executed by a device cause the device to perform the method of any of the above aspects.

[0099] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip systems (SOCs), load programmable logic devices (CPLDs), and the like.

[0100] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0101] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0102] In addition, although each operation is described in a specific order, this should be understood as requiring such operation to be performed in the specific order shown or in a sequential order, or requiring that all illustrated operations should be performed to obtain the desired result. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Certain features described in the context of a separate implementation can also be implemented in a single implementation in combination. On the contrary, the various features described in the context of a single implementation can also be implemented in multiple implementations individually or in any suitable sub-combination.

[0103] Although the subject matter has been described in language specific to structural features and / or methodological logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims.

Claims

1. A computer-implemented method, include: A data set is obtained from an external untrusted execution environment having a first security level, the data set comprising at least one record, wherein a record in the at least one record comprises at least: A keyword used to identify the record, and a value corresponding to the keyword; creating a keyword index in a security management module executed in a trusted execution environment based on respective keywords of the at least one record, the trusted execution environment having a second security level, the second security level being higher than the first security level, the keyword index describing a set of keywords of the at least one record, wherein the security management module receives a request from an application executed in the trusted execution environment and accesses the data set in the external untrusted execution environment based on the request, and wherein each keyword of the set of keywords is mapped to a bit in a bitmap by a hash function; After receiving a request for the keyword, searching for the keyword in the data set; After locating the keyword in the data set, returning an encrypted record for the keyword to the trusted execution environment; If it is determined that the keyword is present in the keyword index, decrypting the encrypted record in the security management module executing within the trusted execution environment; and If it is determined that the keyword does not exist in the keyword index, it is determined that there is an anomaly in the data set.

2. The method according to claim 1, further comprising: include: In response to receiving a request from an application in the trusted execution environment to add a new record to the data set, updating the keyword index based on a keyword of the new record; as well as The new record is added to the data set.

3. The method according to claim 1, further comprising: include: In response to receiving a request to read a record in the data set, determining a target keyword associated with the request; In response to not finding a target record including the target keyword in the data set, comparing the target keyword with the keyword index; as well as In response to the target keyword matching the keyword index, an indication of an anomaly occurring in the data set is provided.

4. The method according to claim 3, further comprising: include: In response to the target keyword not matching the keyword index, providing an indication that a record associated with the request is not included in the data set.

5. The method according to claim 1, further comprising: include: In response to receiving a request to read a record in the data set, determining a target keyword associated with the request; In response to finding a target record including the target keyword in the data set, comparing the target keyword with the keyword index; as well as In response to the target keyword matching the keyword index, providing an indication to include a target record associated with the request in the data set.

6. The method according to claim 5, further comprising: include: In response to the target keyword not matching the keyword index, providing an indication that an anomaly occurs in the data set.

7. The method of claim 1 , wherein the data set is a data set of a blockchain-based database, and a record of at least one record in the data set describes a key and a value of a node in the blockchain-based database. The method of claim 1 , wherein the data set is stored in an untrusted execution environment.

9. The method according to claim 1, further comprising: include: In response to receiving an access request for accessing the data set, a record associated with the access request is added to a cache in the trusted execution environment.

10. The method of claim 1, wherein the method is performed in the trusted execution environment.

11. An electronic device, include: Processing unit; as well as A memory coupled to the processing unit and containing instructions stored thereon, which, when executed by the processing unit, cause the electronic device to perform the following actions: A data set is obtained from an external untrusted execution environment having a first security level, the data set comprising at least one record, wherein a record in the at least one record comprises at least: A keyword used to identify the record, and a value corresponding to the keyword; creating a keyword index in a security management module executed in a trusted execution environment based on respective keywords of the at least one record, the trusted execution environment having a second security level, the second security level being higher than the first security level, the keyword index describing a set of keywords of the at least one record, wherein the security management module receives a request from an application executed in the trusted execution environment and accesses the data set in the external untrusted execution environment based on the request, and wherein each keyword of the set of keywords is mapped to a bit in a bitmap by a hash function; After receiving a request for the keyword, searching for the keyword in the data set; After locating the keyword in the data set, returning an encrypted record for the keyword to the trusted execution environment; If it is determined that the keyword is present in the keyword index, decrypting the encrypted record in the security management module executing within the trusted execution environment; and If it is determined that the keyword does not exist in the keyword index, it is determined that there is an anomaly in the data set.

12. The electronic device according to claim 11, wherein the action further include: In response to receiving a request from an application in the trusted execution environment to add a new record to the data set, updating the keyword index based on a keyword of the new record; as well as The new record is added to the data set.

13. The electronic device according to claim 11, wherein the action further include: In response to receiving a request to read a record in the data set, determining a target keyword associated with the request; In response to not finding a target record including the target keyword in the data set, comparing the target keyword with the keyword index; as well as In response to the target keyword matching the keyword index, an indication of an anomaly occurring in the data set is provided.

14. The electronic device according to claim 13, wherein the action further comprises: providing an indication that the dataset does not include a record associated with the request in response to the target keyword not matching the keyword index.

15. The electronic device according to claim 11, wherein the action further comprises: determining a target keyword associated with the request in response to receiving a request to read a record in the dataset; comparing the target keyword with the keyword index in response to finding a target record including the target keyword in the dataset; and providing an indication that the dataset includes a target record associated with the request in response to the target keyword matching the keyword index.

16. The electronic device according to claim 15, wherein the action further comprises: providing an indication that an anomaly occurs in the dataset in response to the target keyword not matching the keyword index.

17. The electronic device according to claim 11, wherein the dataset is a dataset of a blockchain-based database, and the record description in at least one record in the dataset is the keyword and value of a node in the blockchain.

18. The electronic device according to claim 11, wherein the dataset is stored in a trusted execution environment.

19. The electronic device according to claim 11, wherein the action further comprises: adding a record associated with the access request to a cache in the trusted execution environment in response to receiving an access request for accessing the dataset.

20. The electronic device according to claim 11, wherein the action is executed in the trusted execution environment.

21. A computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method according to any one of claims 1-10 is implemented.

Citation Information

Patent Citations

  • Method and device for medical information sharing privacy protection based on blockchain technology

    CN106682530A

  • Data base checking information processor

    JP1997006653A

  • Retrieval system, retrieval method and retrieval program

    JP2014174661A

  • Trusted storage systems and methods

    US20060123250A1

  • Mutually assured data sharing between distrusting parties in a network environment

    US20140283098A1