Method and apparatus for trusted computing

Automatically obtain and deploy bytecode files through the management device of trusted computing tasks, solving the problem that users need to manually configure the development environment and write applications, and achieving efficient trusted computing tasks.

CN113987518BActive Publication Date: 2025-07-25ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111300491.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-04
Publication Date
2025-07-25
Estimated Expiration
2041-11-04

AI Technical Summary

Technical Problem

When performing trusted computing tasks, users need to configure their own development environment and write trusted computing applications, resulting in high learning costs and low development efficiency.

Method used

It provides a management device for trusted computing tasks, which can automatically obtain the bytecode files of trusted computing applications for users and deploy them to the trusted computing engine of trusted computing services, obtain the calculation results and return them, and supports a variety of default and customized trusted computing methods to reduce the learning cost and repetitive workload of users.

Benefits of technology

By automatically processing trusted computing tasks, users' learning costs are reduced, development efficiency is improved, repetitive workload is reduced, and user experience is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987518B_ABST
    Figure CN113987518B_ABST
Patent Text Reader

Abstract

The present disclosure discloses a method and apparatus for trusted computing. The method is applied to a management apparatus for trusted computing tasks, and the method includes: receiving a trigger request for a trusted computing task of a user; in response to the trigger request, determining a bytecode file of a trusted computing application corresponding to the trusted computing task; deploying the trusted computing application to a trusted computing engine of a trusted computing service according to the bytecode file of the trusted computing application to obtain a calculation result of the trusted computing task; and returning the calculation result to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and particularly to a method and apparatus for trusted computing. Background Art

[0002] A trusted execution environment (TEE) can provide a secure execution environment for trusted computing services in the environment. Therefore, trusted computing services can execute trusted computing tasks on the premise of fully protecting data privacy, so as to provide users with general and verifiable privacy data computing services.

[0003] However, when a user executes a trusted computing task based on a trusted computing service, the user needs to configure a development environment by himself / herself and write a trusted computing application. For ordinary users, the learning cost of writing a trusted computing application is very high, resulting in low development efficiency. Summary of the Invention

[0004] In view of this, the present disclosure provides a method and apparatus for trusted computing to reduce the learning cost of users and improve development efficiency.

[0005] In a first aspect, a method for trusted computing is provided. The method is applied to a management apparatus for trusted computing tasks, and the method includes: receiving a trigger request for a trusted computing task of a user; in response to the trigger request, determining a bytecode file of a trusted computing application corresponding to the trusted computing task; according to the bytecode file of the trusted computing application, deploying the trusted computing application to a trusted computing engine of a trusted computing service to obtain a calculation result of the trusted computing task; and returning the calculation result to the user.

[0006] In a second aspect, a method for trusted computing is provided. The method includes: sending a trigger request for a trusted computing task to a management apparatus for trusted computing tasks, where the trigger request is used to trigger the management apparatus to automatically determine a bytecode file of a trusted computing application corresponding to the trusted computing task, and according to the bytecode file of the trusted computing application, deploying the trusted computing application to a trusted computing engine of a trusted computing service to obtain a calculation result of the trusted computing task; and receiving the calculation result returned by the management apparatus.

[0007] In a third aspect, there is provided a trusted computing device, which is a management device for trusted computing tasks. The device includes: a receiving unit configured to receive a trigger request for a user's trusted computing task; a determining unit configured to, in response to the trigger request, determine a bytecode file of a trusted computing application corresponding to the trusted computing task; a deploying unit configured to deploy the trusted computing application to a trusted computing engine of a trusted computing service according to the bytecode file of the trusted computing application, so as to obtain a calculation result of the trusted computing task; and a returning unit configured to return the calculation result to the user.

[0008] In a fourth aspect, there is provided a trusted computing device, which includes: a sending unit configured to send a trigger request for a trusted computing task to a management device for the trusted computing task, where the trigger request is used to trigger the management device to automatically determine a bytecode file of a trusted computing application corresponding to the trusted computing task, and deploy the trusted computing application to a trusted computing engine of a trusted computing service according to the bytecode file of the trusted computing application, so as to obtain a calculation result of the trusted computing task; and a receiving unit configured to receive the calculation result returned by the management device.

[0009] In a fifth aspect, there is provided a trusted computing device including a memory and a processor. An executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method according to the first aspect or the second aspect.

[0010] In a sixth aspect, there is provided a computer-readable storage medium, on which an executable code is stored. When the executable code is executed, the method according to the first aspect or the second aspect can be implemented.

[0011] In a seventh aspect, there is provided a computer program product including an executable code. When the executable code is executed, the method according to the first aspect or the second aspect can be implemented.

[0012] It can be seen from the technical solutions provided by the present disclosure that after receiving a user's trusted computing task, the management device for the trusted computing task can automatically obtain the code file of the trusted computing application for the user, avoiding the problems of high learning cost and low development efficiency caused by the user configuring the development environment and writing the trusted computing application by himself, thereby reducing the user's learning cost and improving the development efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 FIG. is an example diagram of an existing system architecture applicable to trusted computing.

[0014] Figure 2 FIG. is a schematic flowchart of an existing trusted computing method.

[0015] Figure 3 This is an example diagram of a system architecture applicable to trusted computing provided by an embodiment of the present disclosure.

[0016] Figure 4 This is a schematic flowchart of a method for trusted computing provided by an embodiment of the present disclosure.

[0017] Figure 5 This is an example diagram of a possible implementation of a system applicable to trusted computing provided by an embodiment of the present disclosure.

[0018] Figure 6 This is a schematic structural diagram of a device for trusted computing provided by an embodiment of the present disclosure.

[0019] Figure 7 This is a schematic structural diagram of a device for trusted computing provided by another embodiment of the present disclosure.

[0020] Figure 8 This is a schematic structural diagram of a device for trusted computing provided by yet another embodiment of the present disclosure. Detailed implementation manners

[0021] Next, the technical solutions in the embodiments of the present disclosure will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments.

[0022] To facilitate understanding of the technical solutions in the embodiments of the present disclosure, the terms involved in the embodiments of the present disclosure will be briefly introduced first.

[0023] Trusted Execution Environment (TEE)

[0024] TEE is a concept proposed by the globalplatform organization dedicated to developing, formulating, and releasing security chip technology standards. TEE is a secure computing environment that can completely isolate the execution of operations within the environment from the outside, thereby ensuring the privacy and integrity of the code, applications, and data assets in the environment.

[0025] Compared with multimedia operating systems such as Android and Linux (rich operating system, Rich OS), TEE can provide a more secure execution environment for trusted computing services in the environment. Compared with a single security module (secure element, SE), TEE has stronger extensibility in function. Therefore, TEE has been widely applied in fields such as private data computing and mobile payment.

[0026] Blockchain

[0027] Blockchain is a distributed database technology based on cryptographic techniques and consensus algorithms, suitable for storing simple data with a sequential relationship that can be verified within the system. Blockchain has the characteristics of being distributed, immutable, traceable, secure and trustworthy, and thus can be applied to various scenarios of data deposition. For example, in the logistics application scenario, the logistics platform can upload data such as the source of goods, waybills, transportation tracks, and payment orders in business orders to the logistics blockchain system. Or, in the financial application scenario, the financial platform can upload data such as financial orders, user credit information, and user borrowing amounts to the financial blockchain system.

[0028] Trusted Computing Service

[0029] Trusted computing services can utilize hardware TEE technology to execute trusted computing tasks while fully protecting data privacy, thereby providing users with general and verifiable privacy data computing services. In some embodiments, the trusted computing service may refer to a confidential computing cloud service (C3S).

[0030] There can be various application scenarios for trusted computing services, and the present disclosure does not limit this. In some embodiments, the trusted computing service can be applied to the scenario of cross-verifying on-chain and off-chain data. In this scenario, the trusted computing task can, for example, refer to a data verification task based on the blockchain. In some embodiments, the trusted computing service can be applied to the scenario of cross-platform joint marketing. In this scenario, the trusted computing task can, for example, refer to a privacy computing task for user profiling.

[0031] In some embodiments, when the trusted computing service is applied to the scenario of cross-verifying on-chain and off-chain data, the trusted computing service can serve as an off-chain trusted extension of the blockchain to connect on-chain data with off-chain data sources. For example, based on the off-chain verification data, the authenticity of the data stored in the blockchain can be verified. In this case, the trusted computing service can separately obtain on-chain and off-chain data sources and fuse the on-chain and off-chain data sources for trusted computing.

[0032] Trusted computing services can support multi-party privacy data computing. Privacy data computing can refer to computing with privacy protection enabled, and privacy data is by default invisible to anyone other than the sender. For example, a user can encrypt and send data to the computing node where the trusted computing service is located. After running the trusted computing service in the TEE to complete multi-party privacy data computing, the computing result can be encrypted and recorded in the blockchain.

[0033] In some embodiments, the trusted computing service can adopt a multi-party computing method to complete the multi-party privacy data computing task.

[0034] For example, in the logistics application scenario described above, the authenticity of data in the logistics blockchain system can be verified by means of multi-party computation. As an example, if it is necessary to verify the authenticity of the transportation track data of a certain order stored in the blockchain, the trusted computing service can use the logistics data of the same order obtained from the logistics company as the verification data, and perform a comparison calculation based on the verification data and the transportation track data of the order stored in the blockchain, so as to verify the authenticity of the transportation track data stored in the blockchain.

[0035] For another example, in the financial application scenario described above, the amount of borrowing of a certain natural person stored in the financial blockchain system can be statistically calculated by means of multi-party computation. As an example, the same natural person may borrow money on different P2P (peer-to-peer) platforms. Therefore, each P2P platform may store the amount of borrowing of this natural person on its own platform. The trusted computing service can combine the data of multiple P2P platforms to complete the statistical calculation of the total amount of borrowing of this natural person on these multiple P2P platforms.

[0036] Trusted Computing Application

[0037] The trusted computing application can also be simply referred to as a trusted application (trusted application, TAPP). A TAPP can refer to an application that runs in a TEE and is implemented using verifiable computing technology. In some embodiments, the TAPP can run in a virtual machine within the TEE. For example, the TAPP can run in a WebAssembly (WASM) virtual machine.

[0038] When a user develops a TAPP program, after configuring the corresponding development environment and installing the compilation tool, the user can compile the TAPP code written by himself into a bytecode file of the TAPP. For example, when the TAPP runs in a WASM virtual machine, the user can compile the TAPP code written by himself into WASM bytecode. Then, the user can upload the bytecode file of the TAPP to the trusted computing engine of the trusted computing service, and the trusted computing engine of the trusted computing service interprets and executes the bytecode file of the TAPP to obtain the execution result.

[0039] Figure 1 It is an example diagram of the system architecture of trusted computing. As Figure 1As shown, the system 100 may include a user 110 and a trusted computing service platform 120. The user 110 may communicate and interact with data with the trusted computing service platform 120 to enjoy the trusted computing services provided by the trusted computing service platform 120. For example, the user 110 may submit a trusted computing task to the trusted computing service platform 120 to obtain the calculation result of the trusted computing task.

[0040] The user 110 may communicate and interact with data with the trusted computing service platform 120 through a user terminal. The user terminal may be, for example, different types of devices such as a laptop, a server, a smart phone, a digital assistant, etc.

[0041] The trusted computing service platform 120 may provide trusted computing services and return the calculation result of the trusted computing task to the user. The trusted computing service may embed a virtual machine in the TEE to achieve trusted computing with data confidentiality. Based on this, the user can quickly implement the business logic and obtain the calculation result of the trusted computing task returned by the trusted computing service platform 120 by writing and compiling TAPP code and deploying the compiled TAPP to the trusted computing service platform 120.

[0042] When the user 110 wants to publish, execute, or view the TAPP deployed in the trusted computing service platform 120, it needs to be implemented through a software development kit (SDK).

[0043] When the user 110 needs the trusted computing service platform 120 to provide trusted computing services, after the user 110 configures the development environment and installs the TAPP compilation tool, the user 110 needs to write the TAPP code by itself and compile the TAPP code, and then deploy the bytecode file of the compiled TAPP to the trusted computing service platform 120 (for example, it can be deployed to the trusted computing engine of the trusted computing service), so that the calculation result of the trusted computing task returned by the trusted computing service platform 120 can be received by calling the trusted computing service corresponding to the TAPP.

[0044] In some embodiments, the trusted computing task may refer to a data verification task based on a blockchain. For example, verifying the authenticity of data on the blockchain based on off-chain data sources, or verifying the authenticity of off-chain data based on the data stored on the blockchain. As an implementation manner, when the trusted computing task is a data verification task based on a blockchain, the user can write and compile TAPP code, implement the business logic of verifying data authenticity as a TAPP, and the TAPP can be executed by the trusted computing engine to complete the data verification task based on the blockchain.

[0045] When the trusted computing task is a blockchain-based data verification task, System 100 may further include a blockchain. When the trusted computing service platform 120 executes the blockchain-based data verification task, it may request access to the data in the blockchain, verify its authenticity, or verify the authenticity of off-chain data based on this data.

[0046] The following refers to Figure 1 and Figure 2 , taking the trusted computing task as an example of a blockchain-based data verification task in the logistics application scenario, to illustrate the processing flow of the trusted computing task.

[0047] When the logistics platform needs to verify the authenticity of the transportation track data of a certain order stored in the blockchain, the transportation track data of this order stored in the blockchain can be called the data to be verified; the logistics data of the same order obtained from the logistics company can be called the verification data.

[0048] The user (here it can refer to the logistics platform) 110 can initiate a data verification request to the trusted computing service platform 120. This data verification request may include the storage address of the data to be verified and the request parameters of the verification data. The request parameters of the verification data may refer to the storage address of the verification data of the third party (here it can refer to the logistics company) 130. In addition, the user 110 also needs to specify the specific verification logic (or, verification method) for this data verification. That is, after the user 110 configures the development environment and downloads and installs the TAPP compilation tool, based on the SDK provided by the trusted computing service platform 120, the verification logic can be pre-written into TAPP code in advance, and then the TAPP code can be compiled into WASM bytecode through the installed compilation tool. After that, the user 110 can deploy the compiled WASM bytecode to the trusted computing engine of the trusted computing service.

[0049] After receiving this data verification request, the trusted computing service platform 120 can obtain the data to be verified and the verification data respectively based on this request, and verify the authenticity of the data to be verified based on the TAPP deployed by the user 110 in the trusted computing engine of the trusted computing service. After the trusted computing service platform 120 completes the data verification, it can return the verification result to the user 110.

[0050] As mentioned above, when the user executes the trusted computing task based on the trusted computing service, the user needs to configure the development environment and install the TAPP compilation tool by himself, and also needs to write the TAPP code by himself and compile the TAPP code, and then deploy the bytecode file of the compiled TAPP to the trusted computing engine of the trusted computing service. Therefore, the user needs to have some understanding of the development of TAPP and contract deployment.

[0051] In the prior art, the development of TAPP is generally based on general-purpose programming languages, which requires users to have the development capabilities of general-purpose programming languages. For example, users need to have the development capabilities of C++ and JAVA. Secondly, during the development process, due to the lack of a corresponding integrated development environment (IDE), it is difficult for users to debug and test the TAPP code during the development of TAPP. In addition, the contract deployment steps are also very complex. Therefore, for ordinary users, the learning cost of writing TAPP is very high, resulting in low development efficiency.

[0052] When a user executes a trusted computing task based on a trusted computing service, different TAPPs need to be written for different data sources and different verification logics. Among them, some verification logics are actually very similar. For different users, every time a trusted computing task is executed, the user needs to write a TAPP and then deploy the contract. In fact, different users may use the same verification logic to execute the trusted computing task. Therefore, for trusted execution tasks with different data sources or different verification logics, as well as trusted execution tasks submitted by different users, some repetitive work will be caused. For example, TAPPs with similar or identical functions may be repeatedly developed.

[0053] In addition, when a user executes a trusted computing task based on a trusted computing service, multiple files will be generated every time a trusted computing task is executed. Therefore, when there are more trusted computing tasks, the number of generated files will also increase, making it difficult to manage the trusted computing tasks.

[0054] To solve the above problems, embodiments of the present disclosure provide a method and device for trusted computing, which can avoid the problems of high learning cost and low development efficiency caused by users' self-configuration of the development environment and writing TAPP, thereby reducing the learning cost of users and improving the development efficiency.

[0055] Figure 3 It is an example diagram of the system architecture provided by embodiments of the present disclosure. As Figure 3 shown, the system 300 may include a user 310, a trusted computing service platform 320, and a management device for trusted computing tasks (or, a management platform for trusted computing tasks, a management system for trusted computing tasks) 330. The management device 330 may be software integrated on a server, or may also be an application program integrated on a server.

[0056] The management device 330 may support at least one trusted computing method and store bytecode files corresponding to the at least one trusted computing method. In other words, the management device 330 may provide multiple default trusted computing methods for users, and users may select the trusted computing methods provided by the management device 330 according to their own needs.

[0057] The present disclosure does not specifically limit the trusted computing methods supported by the management device 330. As an example, the management device 330 may support some trusted computing methods with high user usage rates. For example, in the field of logistics applications, the management device 330 may support multiple trusted computing methods such as three-level address verification, origin precise verification, and origin route verification.

[0058] The management device 330 may support user-defined trusted computing methods. When the user adopts a user-defined trusted computing method, after the management device 330 receives the user's trusted computing task, it can automatically obtain the TAPP code file corresponding to the trusted computing task for the user, and compile the TAPP code file into a bytecode file of TAPP. In addition, the management device 330 can also automatically deploy the bytecode file of TAPP to the trusted computing engine of the trusted computing service, and call the corresponding trusted computing service to obtain the calculation result of the trusted computing task.

[0059] The management device 330 can help the user create and manage trusted computing tasks (for example, create and manage trusted computing tasks on a web page), making the creation and management of trusted computing tasks more efficient and convenient. The user does not need to manually manage the files generated in the trusted computing task, thereby improving the user experience.

[0060] The following Figure 4 is used to describe in detail the trusted computing method provided by the embodiments of the present disclosure. The trusted computing method provided by the embodiments of the present disclosure can be applied to Figure 3 the system architecture shown in Figure 4 The method shown is described from the perspective of the interaction between the user and the management device of the trusted computing task. The user can interact with the management device of the trusted computing task through the user terminal.

[0061] In steps 410 to 420, the user sends a trigger request for the trusted computing task to the management device of the trusted computing task, and the management device, in response to the trigger request, determines the bytecode file of the trusted computing application corresponding to the trusted computing task.

[0062] The trusted computing task may refer to a task that the user needs to use the trusted computing service for calculation. In the embodiments of the present disclosure, the user can submit the request for the trusted computing task to the management device, and the management device preprocesses the trusted computing task and then submits it to the trusted computing service platform.

[0063] The management device preprocessing the trusted computing task may mean that when the management device receives the trigger request for the user's trusted computing task, in response to the trigger request, it determines the bytecode file of the trusted computing application corresponding to the trusted computing task.

[0064] In some embodiments, the management device may support at least one trusted computing method, that is, it can provide users with multiple default trusted computing methods. When a user executes a trusted computing task using a trusted computing method supported by the management device, the trigger request for the trusted computing task is used to trigger the management device to execute the trusted computing task using one of the at least one trusted computing method (or, the first trusted computing method). Correspondingly, the management device may, based on the trigger request, select the bytecode file corresponding to the first trusted computing method from the bytecode files of the trusted computing applications stored in the management device.

[0065] As an implementation manner, when the virtual machine in the trusted computing service is a WASM virtual machine, the bytecode file of the TAPP stored in the management device may be a compiled WASM bytecode file.

[0066] The management device can support multiple default trusted computing methods, and pre-compile and deploy the corresponding TAPPs in advance, so that users can directly call the TAPPs deployed in the trusted computing service to execute trusted computing tasks, reducing the repetitive workload of users and improving the efficiency of trusted computing.

[0067] In some embodiments, the management device may support user-defined trusted computing methods. When a user executes a trusted computing task using a user-defined trusted computing method, the trigger request sent by the user to the management device of the trusted computing task may further include a script of the user-defined trusted computing method. After receiving the trigger request based on the user-defined trusted computing method, the management device may automatically parse the script to generate the TAPP corresponding to the trusted computing task. Then, the management device may compile the TAPP corresponding to the trusted computing task to generate a bytecode file of the TAPP.

[0068] In some embodiments, the script of the user-defined trusted computing method may be a domain specific language (DSL) script. After receiving the DSL script sent by the user, the management device may parse the DSL script based on a DSL parser to generate the TAPP corresponding to the trusted computing task.

[0069] Compared with general - purpose programming languages (such as C++, JAVA, etc.), DSL is a semantic model that enables users to understand more easily. In the embodiments of the present disclosure, users can tell the management device what trusted computing tasks need to be executed through DSL scripts, without the need to specifically describe how to do it with a bunch of codes (command statements). For example, in the field of logistics applications, when the data to be verified is the receiving address provided on the logistics platform (field A) and the verification data is the receiving address provided by the logistics company (field B), if a user wants to verify the authenticity of field A, as an example, the user can tell the management device the fields A and B that need to be verified based on the DSL script, without specifically describing how to verify whether fields A and B are consistent.

[0070] The present disclosure does not specifically limit the form of the DSL script. In some embodiments, users can input the DSL script through text language. In some other embodiments, the management device can also provide a graphical interface for users to input the DSL script.

[0071] Compared with users writing TAPPs themselves using general - purpose programming languages, using DSL scripts can lower the usage threshold for users, thereby improving the efficiency of users using trusted computing services to execute trusted computing tasks.

[0072] The present disclosure does not limit the types of trusted computing tasks. In some embodiments, the trusted computing task can be a data verification task. For example, a data verification task based on blockchain. In some embodiments, the trusted computing task can also be a data statistical calculation task. By executing the data verification task based on blockchain in a trusted computing manner, it can further ensure that the data has not been tampered with before being uploaded to the chain.

[0073] The present disclosure does not specifically limit the triggering method of the trigger request for the trusted computing task. For example, it can be triggered by calling a remote RPC interface. Another example is that it can be triggered by calling an openAPI interface. Or, it can also be manually triggered through a web page. Compared with users being able to execute only the TAPPs deployed in the trusted computing engine through the SDK, in the embodiments of the present disclosure, users can interact with the management device based on multiple triggering methods.

[0074] In step 430, the management device deploys the trusted computing application to the trusted computing engine of the trusted computing service according to the bytecode file of the trusted computing application to obtain the calculation result of the trusted computing task.

[0075] In some embodiments, deploying a trusted computing application to the trusted computing engine of a trusted computing service may mean installing and uploading a TAPP to the trusted computing engine of the trusted computing service through the SDK provided by the trusted computing service. Thereafter, the TAPP can be executed for trusted computing by invoking the TAPP interface, and a calculation result can be obtained.

[0076] In step 440, the management device returns the calculation result to the user. After obtaining the corresponding calculation result by invoking the trusted computing service, the management device can forward the calculation result to the user.

[0077] As can be seen from the technical solution of the present disclosure, after receiving a user's trusted computing task, the management device can automatically obtain the code file of the TAPP for the user, avoiding the problems of high learning costs and low development efficiency caused by the user configuring the development environment and writing the TAPP by themselves. In addition, the management device can provide the user with a default trusted computing method to reduce the user's repetitive workload.

[0078] The following Figure 5 gives a specific example of the system architecture that can implement the embodiments of the present disclosure.

[0079] As Figure 5 shown, when a user needs to use the trusted computing service to execute a trusted computing task, the user can create a new trusted computing task and send a trigger request for the trusted computing task to the management device. When sending the trigger request for the trusted computing task, the user can also, according to their own needs, select to use a trusted computing method supported by the management device or select a custom trusted computing method to execute the trusted computing task.

[0080] If the user selects a trusted computing method supported by the management device to execute the trusted computing task, after receiving the trigger request, the management device can directly invoke the TAPP deployed in the trusted computing service.

[0081] The management device can support multiple default trusted computing methods and pre-compile and deploy the corresponding TAPPs in advance, enabling the user to directly invoke the TAPPs deployed in the trusted computing service to execute trusted computing tasks, reducing the user's repetitive workload, and improving the efficiency of trusted computing.

[0082] If the user selects a custom trusted computing method to execute the trusted computing task, when the user sends a trigger request for the trusted computing task, the trigger request may further include a DSL verification script written by the user himself. After receiving the trigger request, the management device can parse the DSL verification script uploaded by the user through a DSL parser. If the management device successfully parses the DSL verification script, it can generate TAPP code that can call the trusted computing service; if the management device fails to parse the DSL verification script, it can directly return the parsing failure result to the user.

[0083] After the management device generates TAPP code based on the DSL verification script uploaded by the user, it can compile the generated TAPP code through a compilation tool. If the compilation is successful, it can directly generate the WASM bytecode file of the TAPP; if the compilation fails, it can directly return the compilation failure result to the user.

[0084] Furthermore, after the management device obtains the compiled WASM bytecode file, it can call the SDK provided by the trusted computing service and deploy the WASM bytecode file to the trusted computing engine of the trusted computing service to generate a TAPP. Then, the management device can execute the trusted computing task by calling the TAPP deployed in the trusted computing service.

[0085] When the user uses a custom trusted computing method to execute the trusted computing task, the user only needs to write a DSL verification script to call the trusted computing service, without the user writing TAPP code by himself, which reduces the learning cost of the user and improves the development efficiency.

[0086] As described above in conjunction with Figures 1 to 5 ,the method embodiments of the present disclosure have been described in detail. Next, in conjunction with Figures 6 to 8 ,the device embodiments of the present disclosure will be described in detail. It should be understood that the descriptions of the method embodiments and the device embodiments correspond to each other. Therefore, for the parts not described in detail, reference may be made to the previous method embodiments.

[0087] Figure 6 FIG. is a schematic structural diagram of a trusted computing device provided by an embodiment of the present disclosure. Figure 6 The device 600 may be a management device for trusted computing tasks. The device 600 may include a receiving unit 610, a determining unit 620, a deploying unit 630, and a returning unit 640. These units will be introduced in detail below.

[0088] The receiving unit 610 may be configured to receive a trigger request for a trusted computing task of a user.

[0089] The determination unit 620 may be configured to determine the bytecode file of the trusted computing application corresponding to the trusted computing task in response to a trigger request.

[0090] The deployment unit 630 may be configured to deploy the trusted computing application to the trusted computing engine of the trusted computing service according to the bytecode file of the trusted computing application, so as to obtain the calculation result of the trusted computing task.

[0091] The return unit 640 may be configured to return the calculation result to the user.

[0092] Optionally, the trusted computing task is a data verification task based on a blockchain.

[0093] Optionally, the management device supports at least one trusted computing method, and the trigger request is used to trigger the management device to execute the trusted computing task by using the first trusted computing method among the at least one trusted computing method. The determination unit 620 is further configured to select the bytecode file corresponding to the first trusted computing method from the bytecode files of the trusted computing applications stored in the management device in response to the trigger request.

[0094] Optionally, the bytecode file of the trusted computing application stored in the management device is a compiled WASM bytecode file.

[0095] Optionally, the trigger request is used to trigger the management device to execute the trusted computing task based on the user-defined second trusted computing method, and the trigger request includes a script of the second trusted computing method. The determination unit 620 is further configured to parse the script in response to the trigger request to generate a trusted computing application corresponding to the trusted computing task; and compile the trusted computing application corresponding to the trusted computing task to generate a bytecode file of the trusted computing application.

[0096] Optionally, the script is a domain-specific language (DSL) script.

[0097] Optionally, the triggering method of the trigger request includes at least one of the following: triggering by calling a remote RPC interface, triggering by calling an openAPI interface, and / or triggering manually through a web page.

[0098] Figure 7 It is a schematic structural diagram of a trusted computing device provided by another embodiment of the present disclosure. The device 700 may be applied to the user's user terminal. The device 700 may include a sending unit 710 and a receiving unit 720. These units will be introduced in detail below.

[0099] The sending unit 710 may be configured to send a trigger request for a trusted computing task to a management device of the trusted computing task. The trigger request is used to trigger the management device to automatically determine a bytecode file of a trusted computing application corresponding to the trusted computing task, and deploy the trusted computing application to a trusted computing engine of the trusted computing service according to the bytecode file of the trusted computing application, so as to obtain a calculation result of the trusted computing task.

[0100] The receiving unit 720 may be configured to receive the calculation result returned by the management device.

[0101] Optionally, the trusted computing task is a data verification task based on a blockchain.

[0102] Optionally, the management device supports at least one trusted computing method, and the trigger request is used to trigger the management device to execute the trusted computing task by using a first trusted computing method among the at least one trusted computing method.

[0103] Optionally, the trigger request is used to trigger the management device to execute the trusted computing task based on a second trusted computing method defined by a user, and the trigger request includes a script of the second trusted computing method.

[0104] Optionally, the script is a domain-specific language (DSL) script.

[0105] Optionally, the triggering manner of the trigger request includes at least one of the following: triggering by calling a remote RPC interface, triggering by calling an openAPI interface, and / or triggering manually through a web page.

[0106] Figure 8 It is a schematic structural diagram of a trusted computing device provided by another embodiment of the present disclosure. Figure 8 The illustrated device 800 may be a computing device with computing capabilities. For example, the device 800 may be a server. The device 800 may include a memory 810 and a processor 820. The memory 810 may be used to store executable code. The processor 820 may be used to execute the executable code stored in the memory 810 to implement the steps in the various methods described above. In some embodiments, the device 800 may further include a network interface 830, and the data exchange between the processor 820 and external devices may be implemented through the network interface 830.

[0107] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present disclosure are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a Digital Video Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.

[0108] Those of ordinary skill in the art will realize that the units and algorithm steps of the examples described in conjunction with the embodiments of the present disclosure can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.

[0109] In several embodiments provided by the present disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in an electrical, mechanical, or other form.

[0110] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0111] In addition, each functional unit in various embodiments of the present disclosure may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit.

[0112] As described above, the above are only specific embodiments of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of changes or substitutions, which should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A method for trusted computing, which is applied to a management device for trusted computing tasks. The method includes: Receiving a trigger request for a trusted computing task from a user; In response to the trigger request, determining a bytecode file of a trusted computing application corresponding to the trusted computing task; According to the bytecode file of the trusted computing application, deploying the trusted computing application to a trusted computing engine of a trusted computing service to obtain a calculation result of the trusted computing task, where the trusted computing service is applied in a trusted execution environment TEE; Returning the calculation result to the user; In the case where the trigger request is used to trigger the management device to execute the trusted computing task based on a second trusted computing method defined by the user, where the trigger request includes a script of the second trusted computing method, The determining, in response to the trigger request, a bytecode file of a trusted computing application corresponding to the trusted computing task includes: In response to the trigger request, parsing the script to generate a trusted computing application corresponding to the trusted computing task; Compiling the trusted computing application corresponding to the trusted computing task to generate a bytecode file of the trusted computing application.

2. The method according to claim 1, wherein the trusted computing task is a data verification task based on a blockchain.

3. The method according to claim 1 or 2, wherein the management device supports at least one trusted computing method. In the case where the trigger request is used to trigger the management device to execute the trusted computing task using a first trusted computing method among the at least one trusted computing method, The determining, in response to the trigger request, a bytecode file of a trusted computing application corresponding to the trusted computing task includes: In response to the trigger request, selecting the bytecode file corresponding to the first trusted computing method from the bytecode files of the trusted computing applications stored in the management device.

4. The method according to claim 3, wherein the bytecode files of the trusted computing applications stored in the management device are pre-compiled WASM bytecode files.

5. The method according to claim 1 or 2, wherein the script is a domain-specific language DSL script.

6. The method according to claim 1 or 2, wherein the triggering method of the trigger request includes at least one of the following: triggering by calling a remote RPC interface, triggering by calling an openAPI interface, and / or triggering manually through a web page.

7. A method for trusted computing, including: Sending a trigger request for a trusted computing task to a management device for trusted computing tasks, where the trigger request is used to trigger the management device to automatically determine a bytecode file of a trusted computing application corresponding to the trusted computing task, and according to the bytecode file of the trusted computing application, deploying the trusted computing application to a trusted computing engine of a trusted computing service to obtain a calculation result of the trusted computing task, where the trusted computing service is applied in a trusted execution environment TEE; Receiving the calculation result returned by the management device; Wherein, the trigger request is used to trigger the management device to execute the trusted computing task based on a second trusted computing method defined by the user, and the trigger request includes a script of the second trusted computing method, and the script is used to parse and generate a trusted computing application corresponding to the trusted computing task, and then compile and generate a bytecode file of the trusted computing application.

8. The method according to claim 7, wherein the trusted computing task is a data verification task based on a blockchain.

9. The method according to claim 7 or 8, wherein the management device supports at least one trusted computing method, and the trigger request is used to trigger the management device to execute the trusted computing task by using a first trusted computing method among the at least one trusted computing method.

10. The method according to claim 7 or 8, wherein the script is a domain-specific language (DSL) script.

11. The method according to claim 7 or 8, wherein the triggering manner of the trigger request includes at least one of the following: triggering by calling a remote RPC interface, triggering by calling an openAPI interface, and / or triggering manually through a web page.

12. A trusted computing device, which is a management device for a trusted computing task, and the device includes: a receiving unit, configured to receive a trigger request for a trusted computing task of a user; a determining unit, configured to, in response to the trigger request, determine a bytecode file of a trusted computing application corresponding to the trusted computing task; a deploying unit, configured to deploy the trusted computing application to a trusted computing engine of a trusted computing service according to the bytecode file of the trusted computing application, so as to obtain a calculation result of the trusted computing task, wherein the trusted computing service is applied to a trusted execution environment (TEE); a returning unit, configured to return the calculation result to the user; In the case where the trigger request is used to trigger the management device to execute the trusted computing task based on the second trusted computing method defined by the user, wherein the trigger request includes a script of the second trusted computing method, the determining unit is configured to: in response to the trigger request, parse the script to generate a trusted computing application corresponding to the trusted computing task; compile the trusted computing application corresponding to the trusted computing task to generate a bytecode file of the trusted computing application.

13. A trusted computing device, including: a sending unit, configured to send a trigger request for a trusted computing task to a management device for a trusted computing task, where the trigger request is used to trigger the management device to automatically determine a bytecode file of a trusted computing application corresponding to the trusted computing task, and deploy the trusted computing application to a trusted computing engine of a trusted computing service according to the bytecode file of the trusted computing application, so as to obtain a calculation result of the trusted computing task, wherein the trusted computing service is applied to a trusted execution environment (TEE); a receiving unit, configured to receive the calculation result returned by the management device; Wherein, the trigger request is used to trigger the management device to execute the trusted computing task based on a second trusted computing method defined by the user, and the trigger request includes a script of the second trusted computing method, and the script is used to parse and generate a trusted computing application corresponding to the trusted computing task, and then compile and generate a bytecode file of the trusted computing application.

14. A trusted computing device, comprising a memory and a processor, wherein executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method according to any one of claims 1-11.

Citation Information

Patent Citations

  • Method, apparatus, and computer-readable medium for obfuscating execution of application on virtual machine

    CN106663025A

  • Active response type trusted Python virtual machine and execution method thereof

    CN110442422A

  • Method and device for dynamically converting service logic and medium

    CN112947934A