A virtual encryption machine platform based on trusted technology and its creation method
By establishing a virtual encryption machine system on the processor platform, the user data is safe, autonomous and controllable, and the security risks and multi-tenant management problems in the traditional encryption machine mode are solved, and the integration of encryption machine and cloud computing platform is achieved and the cost reduction is achieved.
Patent Information
- Application Number
- CN202111440048.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-30
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-11-30
AI Technical Summary
In the traditional encryption machine mode, users cannot achieve data security, autonomous controllability, and cannot adapt to today's multi-tenant cloud service model, which poses security risks and management difficulties.
Establish a software and hardware encryption system on the processor platform that integrates trusted computing modules, divide the trusted execution environment TEE and the ordinary execution environment REE, realize hardware isolation through memory isolation and CPU access permission control, and establish multiple virtual encryption machines to provide different users with a secure and trusted environment and exclusive security service programs.
It realizes the security, independent and controllable user data, avoids exposure of key data to third parties, integrates encryption machines with cloud computing platforms, reduces security construction costs, and improves efficiency.
Smart Images

Figure CN114117412B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer information security, and in particular, to a virtual encryption machine platform based on trusted technology and a method for creating the same. Background Art
[0002] At present, the booming development of the Internet has promoted the continuous prosperity of the information industry. Massive information and data have become key production factors and play an increasingly important role in driving the high-speed development of the whole society. Its related technologies, systems, platforms and applications have been fully penetrated into various fields such as production, consumption, and communication, providing people with diversified and efficient services. However, at the same time, network attacks on large public service information and data platforms occur frequently, malicious infringements on personal information occur frequently, and security incidents such as data tampering and data leakage emerge in an endless stream, seriously endangering the public interest and personal information security of society. Therefore, information and data security has been placed at an unprecedented height of attention, and related technologies have developed rapidly. Among them, data encryption, as an important technical means to ensure information and data security, is widely applied in various fields of production and life.
[0003] An encryption machine is a specific device that provides dedicated security encryption services for users' key information to ensure the confidentiality and integrity of data. It is an important carrier for implementing data encryption technology and is generally used in systems or infrastructures that provide public information services, such as commercial bank systems, social security card systems, integrated business systems, online securities trading systems, DNS systems, etc. It is crucial for ensuring the safe operation of public services and the public interest of society. For example, in the Domain Name System (DNS), the DNSSEC mechanism is usually applied to ensure the security of domain name zone data. It uses asymmetric encryption technology to protect domain name zone data. The confidentiality of the private key and the security of the encryption operation are very important for the overall security of the DNS system. Generally, the private key management and data signature are completed through an encryption machine. Once the encryption machine is compromised or maliciously exploited, it will lead to a complete paralysis of the Internet.
[0004] Currently, most encryption machine services exist in the form of third-party service providers. Users need to purchase corresponding devices and services, entrust the keys to the third party, send the key data to the encryption machine during encryption, and return the result to the user after the encryption operation is completed. The above service method enables the encryption machine manufacturer to have the user's key data. If the encryption machine fails or is invaded, or the data is hijacked during communication, or even the encryption machine manufacturer uses the user data to seek illegal benefits, it will cause great damage to the user and public interests. At the same time, in the face of the current large-scale application of the multi-tenant cloud service model based on platforms such as SaaS, the traditional physical encryption machine deployment solution for a single user has problems such as poor flexibility, difficulty in multi-tenant management and permission control, and inability to achieve distributed deployment, making it difficult to integrate with the existing cloud computing architecture and unable to meet the security encryption requirements of cloud tenants. Summary of the Invention
[0005] The present invention provides a virtual encryption machine platform based on trusted computing technology and a creation method thereof, so as to solve the problems that in the traditional encryption machine mode, users cannot achieve the autonomous and controllable data security, and cannot well adapt to the current multi-tenant cloud service mode. The present invention can eliminate the security risks and hidden dangers brought by exposing users' key data and sensitive operations to a third-party encryption machine, such as system intrusion, data hijacking or malicious utilization, etc.
[0006] The present invention is realized through the following technical solutions:
[0007] In a first aspect, a virtual encryption machine platform based on trusted technology includes: establishing a software and hardware encryption system on a processor platform integrated with a trusted computing module to realize the operation of a trusted execution environment TEE and a normal execution environment REE; dividing mutually independent hardware regions between the REE and the TEE by using memory isolation and CPU access permission control technologies at the bottom layer to achieve mutual isolation; establishing a plurality of virtual encryption machines in the TEE; the virtual encryption machines realize hardware isolation from the normal execution environment REE, establish a secure and trusted environment for CAs of different users and assign exclusive security service programs TAs thereto, and effectively manage them;
[0008] Wherein, the CA is an instance of a user service application program that realizes docking with the TEE in the REE user space; the TA is an instance of an application program that provides a secure encryption service for tenants in the TEE user space.
[0009] In a second aspect, the present application provides a method for creating a virtual encryption machine platform based on trusted technology. The running ARM core is divided into a secure state and a non-secure state based on the TrustZone technology. The secure state corresponds to a system environment with OP-TEE as the trusted execution environment (TEE), and the non-secure state corresponds to a general execution environment (REE). Among them, the TEE provides a secure running and deployment environment for the virtual encryption machine, and private information and related operations are all processed by the trusted application (TA) running in the TEE. The TA is an application program instance that provides secure encryption services for tenants in the TEE user space. The CA is a user service application program instance that realizes the docking with the TEE in the REE user space. Data interaction between the CA and the TA is carried out through the OP-TEE driver to establish shared memory between the TEE and the REE during the mounting process. In terms of hardware isolation, TrustZone uses security extension components to complete the isolation of hardware resources between the TEE and the REE, and constructs an independent hardware secure running environment. In terms of software isolation, OP-TEE uses a microkernel, a library operating system, and integrates a trusted core framework, a trusted communication agent, and a trusted hardware driver to implement a secure operating system. Multiple virtual encryption machines are established in the TEE, and the virtual encryption machines establish exclusive security service programs (TA) for the CAs of different users.
[0010] Further, the security extension components include: TZASC, TZIC, TZPC;
[0011] A secure state read / write signal is added to the system bus to prohibit the REE from accessing the resources in the TEE. In terms of the address space, the address space controller (TZASC) is used to divide a secure address area to reject non-secure access, and the dynamic memory controller (DMC) is attached thereto to achieve secure access to the DRAM (dynamic random access memory).
[0012] The memory adapter (TZMA) can realize the dynamic partitioning of the on-chip RAM, and the low address segment of each partition is used as a secure area;
[0013] The protection controller (TZPC) can set the peripherals as secure peripherals;
[0014] The interrupt controller (TZIC) enables the processor to be unable to capture secure interrupts when in the secure state;
[0015] Further, the hardware isolation is to isolate the resources between the TEE and the REE in terms of memory, cache, interrupt, and peripherals. Specifically, the memory isolation is jointly completed by the MMU and the TZASC. The TEE and the REE have their own independent MMU system control registers, and different execution environments have their own independent page table sets. The virtual address to physical address conversion is completed by their respective logical MMUs, and the address spaces of the TEE and the REE are isolated from each other;
[0016] Peripheral protection is implemented by the TZPC. The device is configured as secure or non-secure through the TZPC. A device configured as secure can only be accessed in a secure environment.
[0017] Interrupt isolation is implemented by the TZIC. The TZIC serves as a first-level interrupt source controller, controlling all external interrupt sources. By programming the relevant registers of the TZIC, which interrupt source is set as a secure interrupt source can be determined.
[0018] Furthermore, before establishing multiple virtual cryptographic machines in the TEE:
[0019] An interface layer needs to be established on top of the secure operating system. By calling the trusted module calculation in the kernel, functions such as certificate management and various mainstream encryption and decryption algorithms are implemented and encapsulated as low-level interface functions for use by upper-layer secure service programs.
[0020] Furthermore, after the virtual cryptographic machines are created:
[0021] The trusted execution environment TEE receives an instruction issued by the user and generates a first instruction.
[0022] According to the first instruction, the trusted execution environment applies to access and configure the TZPC and TZASC, and obtains a first physical memory isolation area.
[0023] The first physical memory isolation area is separated into several memory isolation areas, and the several memory isolation areas correspond to several secure service programs.
[0024] The trusted execution environment sends the secure service program to the user.
[0025] Furthermore, before the trusted execution environment sends the secure service program to the user:
[0026] Create a logical link for communication between the CA and TA in the REE and TEE, and generate a session-unique identification code.
[0027] The TA identifies its identity through the unique identification code. The CA calls the interface to establish a session. The interface calls the driver function to send a call request to the secure monitor mode, notifying the TEE to execute the session creation operation.
[0028] OP-TEE will match or load the corresponding TA according to the unique identification code to complete the session creation.
[0029] Furthermore, the memory isolation area matches different physical memories according to the user's needs.
[0030] Furthermore, there is a unique mapping relationship between the user and the secure service program.
[0031] Furthermore, the virtual encryption machine provides a full-cycle trusted key management mechanism to realize functions such as automatic key generation, secure storage, addition and deletion, backup and recovery. The full-cycle trusted key management mechanism establishes a security service program with data encryption and decryption, signature, and signature verification according to the user requirements.
[0032] The present invention proposes a virtual encryption machine platform based on trusted computing technology and a creation method thereof. Relying on the trusted computing module and secure trusted capabilities integrated in mainstream processors, the trusted execution environment TEE (Trusted Execution Environment) is used to replace the traditional encryption machine system as a new operating carrier for key management and security encryption. A native virtual encryption machine platform based on the processor for multi-tenants is constructed, enabling users to implement their own business systems and the functions of the encryption machine on the same processing platform, completing the integration of the business system and the security system, avoiding the security risks of the user's critical data being invaded, hijacked, and maliciously used in the encryption machine, and truly keeping the critical information in their own hands to achieve secure and autonomous control. At the same time, for the multi-tenant scenario of the cloud platform, multiple virtual encryption machines can be established in the same TEE, and an independent physically isolated secure and trusted environment and exclusive security services are allocated to each cloud tenant to ensure the cloud security of user data.
[0033] The technical solution of this application has the following advantages: 1) The virtual encryption machine platform is integrated with the user business platform to avoid the security risks caused by the exposure of the user's critical data and sensitive operations to a third-party encryption machine, and realize the secure and autonomous control of user data. 2) It realizes the docking and integration of the encryption machine system and the multi-tenant scenario in the cloud computing platform. 3) It eliminates the need for users to continuously pay service fees to the encryption machine service provider, and greatly reduces the cost of user data security construction. 4) The hardware power consumption of establishing multiple virtual encryption machines in the same processor platform is lower than the overall power consumption of the traditional encryption machine, and the efficiency is improved. Brief Description of the Drawings
[0034] In order to more clearly illustrate the technical solution of this application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative labor.
[0035] Figure 1 It is a schematic diagram of TrustZone hardware isolation in a method for creating a virtual encryption machine platform based on trusted technology provided by this application;
[0036] Figure 2 It is a schematic diagram of the OP-TEE structure in a method for creating a virtual encryption machine platform based on trusted technology provided by this application;
[0037] Figure 3 Schematic diagram of a virtual encryption machine platform in a method for creating a virtual encryption machine platform based on trusted technology provided by this application;
[0038] Figure 4 Schematic diagram of the architecture of a trusted key management mechanism in a method for creating a virtual encryption machine platform based on trusted technology provided by this application;
[0039] Figure 5 Schematic diagram of multi-tenant memory isolation in a method for creating a virtual encryption machine platform based on trusted technology provided by this application. Detailed implementation manners
[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0041] Encryption machine services mostly exist in the form of third-party service providers. Users need to purchase corresponding devices and services, entrust the keys to the third party, and send the key data to the encryption machine during encryption, and return the result to the user after the encryption operation is completed. The above service method enables the encryption machine manufacturer to have the user's key data, and once a failure or intrusion occurs, it will cause great damage to the user and public interests. Therefore, this application provides a virtual encryption machine platform and a creation method based on trusted technology, which can complete the integration of the business system and the security system, truly keep the key information in one's own hands, and achieve secure and independent control. By establishing multiple virtual encryption machines, independent secure and trusted environments and exclusive security services can be allocated to each cloud tenant to ensure the cloud security of user data.
[0042] Building a secure and trusted environment TEE is the key to ensuring key and encryption security. At the same time, TEE is also an important development direction in the field of trusted computing. Major processor manufacturers expand the security functions of general-purpose CPUs and add security functions such as memory isolation, data and code encryption, and integrity protection in their special security modes. Typical representatives include Intel's Software Guard Extensions (SGX), ARM TrustZone, AMD SEV (Secure Encrypted Virtualization), and RISC-V Enclave. In addition, foreign manufacturers such as Qualcomm, Samsung, and LG, and domestic manufacturers such as Spreadtrum, MediaTek, VIA, HiSilicon, and Starry also provide solutions that support TEE in many fields such as intelligent terminals and the Internet of Things. The technical solution of this application is not limited, as long as it supports building a secure and trusted environment TEE.
[0043] A virtual encryption machine platform based on trusted technology, comprising: establishing a software and hardware encryption system on a processor platform integrated with a trusted computing module to implement the operation of a trusted execution environment TEE and a normal execution environment REE; dividing mutually independent hardware areas between the REE and the TEE by using memory isolation and CPU access permission control technologies at the bottom layer to achieve mutual isolation; establishing multiple virtual encryption machines in the TEE; the virtual encryption machines implement hardware isolation from the normal execution environment REE, establish a secure and trusted environment for CAs of different users and assign exclusive security service programs TA, and effectively manage them; wherein, the CA is an instance of a user service application program that realizes docking with the TEE in the REE user space; the TA is an instance of an application program that provides security encryption services for tenants in the TEE user space. The technical solution of this application will be described in detail below:
[0044] In the embodiments of the present application, a secure and trusted environment TEE is constructed using the TrustZone technology. Since the TrustZone technology is a hardware security extension technology proposed by ARM, it supports users to independently develop and design specific security systems and is currently widely supported by mobile embedded devices. The TrustZone technology divides the entire ARM system-on-chip into two physically isolated execution regions through processor extension: the Normal World and the Secure World. OP-TEE (Open-source Portable Trusted Execution Environment) is a trusted execution environment built based on ARM's TrustZone technology. The combination of the two can provide hardware-level security protection for system software. Therefore, the present invention uses ARM's TrustZone hardware module to carry the open-source OP-TEE software framework as the basic platform to implement a virtual encryption machine platform based on trusted technology and its creation method.
[0045] TrustZone: Use secure extension components to complete the hardware resource isolation between TEE and REE, and provide an independent hardware security operating environment for the virtual encryption machine; OP-TEE: Use a microkernel, a library operating system, and integrate a trusted core framework, a trusted communication proxy, and a trusted hardware driver to implement a secure operating system and provide a security service program TA for the virtual encryption machine.
[0046] Specifically, based on the TrustZone technology, the running ARM core is divided into a secure state and a non-secure state. The secure state corresponds to a system environment with OP-TEE as the trusted execution environment TEE (Trusted Execution Environment), and the non-secure state corresponds to a general execution environment REE (Rich Execution Environment); among them, TEE provides a secure running and deployment environment for the virtual encryption machine, and private information and related operations are all processed by the trusted application TA (Trust Application) running in TEE. TA is an application program instance that provides secure encryption services for tenants in the TEE user space; CA is a user service application program instance that realizes the docking with TEE in the REE user space; data interaction between CA and TA will be carried out through the shared memory established between TEE and REE during the mounting process by the OP-TEE driver.
[0047] REE runs non-sensitive tasks and logic that have low requirements for operating security based on general hardware and operating systems. TEE, on the other hand, stores critical data based on trusted hardware modules and secure operating systems and performs sensitive encryption operations with higher security requirements. The two are isolated from each other by using technologies such as memory isolation and CPU access permission control at the bottom layer to divide independent hardware areas. TEE has the permission to access REE resources, while REE has no direct access to TEE resources. The construction of TEE minimizes the attack surface of the system. Even when REE is attacked or paralyzed, TEE can still operate normally, ensuring that the critical information stored in it is not damaged.
[0048] As Figure 1 shown, in terms of hardware isolation, TrustZone uses security extension components, including the address space controller TZASC (TrustZone Address Space Controller), Cache, MMU extension, interrupt controller TZIC (TrustZone Interrupt Controller), protection controller TZPC (TrustZone Protection Controller), etc. TrustZone extends the security of the entire processor to achieve hardware isolation. Security status read and write signals are added to the system bus to prohibit REE from accessing resources in TEE. In terms of address space, TZASC is used to divide a secure address area to reject non-secure access, and the dynamic memory controller DMC (Dynamic Memory Controller) is connected to it to achieve secure access to DRAM (Dynamic Random Access Memory). The memory adapter TZMA (TrustZone Memory Adapter) can dynamically divide the on-chip RAM, and the low address segment of each division is used as a secure area. TZPC can set peripherals as secure peripherals. TZIC makes the processor unable to capture secure interrupts when in the secure state. Each entry in the Cache is extended with a status tag and is marked according to the secure state and non-secure state. The processor intelligently uses the Cache in the corresponding state. At the same time, each page table description in the MMU contains a status bit indicating whether the mapped memory is in a secure state.
[0049] At the hardware level, resource isolation between the TEE and REE is completed in terms of memory, cache, interrupts, peripherals, etc., to build an independent hardware secure operating environment, allocate an independent hardware space for the TEE, and prevent the REE from directly accessing it. Specifically, memory isolation is jointly completed by the MMU and TZASC. The TEE and REE have their own independent MMU system control registers. Different execution environments have their own independent page table sets, and the virtual address to physical address conversion is completed by their respective logical MMUs. The address spaces of the TEE and REE are isolated from each other; peripheral protection is implemented by the TZPC. The device is configured as secure or non-secure through the TZPC, and the device configured as secure can only be accessed in a secure environment; interrupt isolation is implemented by the TZIC. The TZIC serves as a primary interrupt source controller, controlling all external interrupt sources. By programming the relevant registers of the TZIC, it is set which interrupt source is a secure interrupt source, so that the interrupts sent by secure devices can only be processed by the secure environment interrupt handler.
[0050] As Figure 2 shown, in terms of software isolation, OP-TEE uses technologies such as microkernel and library operating system, and integrates functions such as a trusted core framework, a trusted communication agent, and a trusted hardware driver to implement a secure operating system. Compared with the general operating system running in the REE environment, the kernel of the secure operating system only integrates kernel core components such as memory management and thread scheduling, as well as security modules unique to trusted computing, making the secure operating system smaller in size and able to effectively reduce the attack surface of the system.
[0051] Before establishing a virtual encryption machine based on the TEE, an interface layer needs to be established on top of the secure operating system. By calling the trusted module calculations in the kernel, functions such as certificate management, various mainstream encryption and decryption algorithms, and security interfaces and system calls involved in the trusted computing module are implemented, and are encapsulated as low-level interface functions for use by upper-layer security service programs.
[0052] As Figure 3 shown, multiple virtual encryption machines can be deployed on the same platform for the virtual encryption machine platform, that is, multiple virtual encryption machines are established in the TEE. The virtual encryption machine creates a secure and trusted environment for different users and designates exclusive security service programs, and effectively manages them. For each cloud tenant, the virtual encryption machine platform will establish a unique mapping relationship between the user process (in the REE) and the exclusive security service program (in the TEE) to ensure that the exclusive security service program serves the designated user; at the same time, independent physical memory that is physically isolated from each other and non-overlapping is allocated to each security service program to ensure that the exclusive security service programs of different users do not affect each other. In addition, according to the actual needs of users, the business function modules provided by the virtual encryption machine platform can be flexibly applied for development to form a customized security solution.
[0053] As Figure 4As shown in the figure, the main business functions of the virtual encryption machine platform are implemented by the upper-layer application program. On the one hand, a full-cycle trusted key and encryption management mechanism needs to be established to store the user's key and critical data in the TEE, which can effectively prevent hackers from invading the system for stealing and misappropriating. At the same time, security control is implemented for operations such as storage, use, deletion, update, and recovery of keys to ensure the confidentiality of critical data and operations. In addition, the data encryption, signature, and signature verification engines will provide the sensitive data with efficient and secure signature, signature verification capabilities, and interfaces that support multiple mainstream algorithms to ensure the integrity of user data.
[0054] As Figure 5 shown in the figure, after the virtual encryption machine platform is created, the executable environment TEE receives the instruction issued by the user and generates the first instruction. According to the first instruction, the kernel of the executable environment applies for accessing the configuration TZPC and TZASC to create the first physical memory isolation area. The first physical memory isolation area is separated into several memory isolation areas, and then the corresponding security service program TA of the user is loaded into the memory isolation area to run. The several memory isolation areas correspond to several security service programs. The virtual encryption machine platform supports establishing multiple security service programs TA that are physically isolated from each other on the physical memory for different services of multiple different users, that is, multiple independent virtual encryption machines, to achieve exclusive security services.
[0055] The memory isolation area matches different physical memories according to the user's needs. The size of the physical memory can be matched with the corresponding size of the memory according to the actual needs of the user. After the memory allocation is completed, the CA and the TA establish a session, create a logical link for communication between the two in the REE and the TEE, and generate a session unique identification code to identify this link. The TA identifies its identity through the unique identification code UUID (Universally Unique Identifier), indicating that the CA binds to the specified TA. The CA will establish a session by calling the interface in libteec. This interface will further call the driver function to send a security monitor mode call request. The security monitor mode is used to complete the switching and communication between the TEE and the REE and notify the TEE to execute the session creation operation. OP-TEE will match or load the corresponding TA according to the UUID to complete the session creation. In addition, data interaction will be carried out between the CA and the TA through the shared memory between the TEE and the REE established during the mounting process by the OP-TEE driver. The TA receives the instructions and data issued by the CA, executes the virtual encryption machine business logic, and returns the results to provide users with secure encryption services.
[0056] The embodiment of this application takes the process of signing the zone file on the CN domain name top-level authoritative resolution master node in the DNS system DNSSEC mechanism as a specific application scenario, and the specific description is as follows:
[0057] The zone file signature function module of the CN domain name top-level authoritative resolution master node will run on a processor platform that supports the ARM TrustZone technology. After the platform starts, it is first divided into a secure state and a non-secure state at the hardware level, corresponding to TEE and REE respectively, where the TEE provides a secure operating and deployment environment for the encryption machine. TrustZone uses security extension components to complete resource isolation between the TEE and the REE in terms of memory, cache, interrupts, peripherals, etc. at the hardware level, and constructs an independent hardware secure operating environment.
[0058] After the platform hardware trusted environment is prepared, OP-TEE will be loaded to build a secure operating system environment that has good support for the TrustZone technology. At the upper layer, it implements the establishment mechanism of CAs and TAs, provides an interface library (libteec) for the REE to use, and a daemon process tee_supplicant for accessing REE resources. At the lower layer, OP-TEE implements the driver and the kernel. The driver is responsible for establishing the underlying channels for interaction between the REE and the TEE. It loads TEE data into the shared memory and triggers the invocation of TAs in the TEE, or vice versa. The kernel implements the switching between the secure state and the non-secure state of the ARM core, interrupt handling, memory and cache management, thread management, system calls, and special operations that support TAs, etc.
[0059] After the secure operating system environment is loaded, the CN zone file signature function module will be started. During the module initialization process, its own CA and the corresponding exclusive security service program TA will be established. At this time, after the CA established by the CN zone file signature issues an instruction to the TEE, the kernel will apply to access the TZPC and TZASC for configuration, create a new physical memory isolation area, and then load the security service program TA corresponding to the CA into the memory isolation area to run. The virtual encryption machine platform can support creating multiple TAs that are physically isolated from each other for different services of different users, that is, multiple independent virtual encryption machines, to achieve exclusive security services.
[0060] After the secure memory allocation of the CN zone file signature TA is completed, the CN zone file signature CA will establish a session with the CN zone file signature TA. In the CA, the session will be established by calling the interface in libteec. This interface will further call the driver function to send a secure monitor mode call (used to complete the switching and communication between the TEE and the REE) request to notify the TEE to execute the session creation operation. OP-TEE will match or load the corresponding TA according to the UUID to complete the session creation. After the session creation is completed, the TA matched according to the UUID will be returned to the CN zone file signature CA.
[0061] After the session is completed, the CN area file signature module will complete the full-cycle management of the area file signature key (ZSK) and the key signature key (KSK) by applying the trusted key management mechanism provided by the virtual encryption machine platform, including operations such as the generation, storage, deletion, and rotation of private keys. At the same time, the platform can implement permission management functions such as administrator login, addition, deletion, and password modification for different levels of administrators.
[0062] Taking the generation and storage process of the private key as an example, the CA first calls the key generation interface to notify the TA to generate an asymmetric encryption key pair (private key and public key). The TA generates the public and private key pair according to the algorithm type and key length provided by the user, and returns the public key to the CA through the shared memory between the TEE and the REE, so that the CN area master node can send the public key to the slave node for area data signature verification; the storage structure of the key is divided into the user layer and the service layer. In the embodiment of the present application, the user layer corresponds to the DNS domain name management user, and the service layer corresponds to the area file signature service in DNS domain name management. The key will be stored in the secure space under the area file signature service in the DNS user, and a fast search and matching interface is provided. For the keys involved in other services of other users, the corresponding TA is responsible for allocating a new secure space for storage, and the keys are isolated from each other.
[0063] The CN area file signature module will complete the area file signature by applying the mainstream cryptographic algorithm interface provided by the virtual encryption machine platform. The CN area file signature module parses the area file data, and sends the resource record collection to be signed to the TA one by one through the CA. The TA calls the hash algorithms (HMAC, SHA, etc.) and asymmetric encryption algorithms (RSA, ECDSA, etc.) interfaces provided by the virtual encryption machine platform to perform the signature operation, and returns the signature result to the CA through the shared memory between the TEE and the REE. The CN area file signature module writes it into the new signature area file to complete the complete signature process of the CN area. In addition to supporting hash algorithms and asymmetric encryption algorithms, the virtual encryption machine platform also supports symmetric encryption algorithms (AES, 3DES, etc.), random number generation algorithms (RANDOM), etc. interfaces.
[0064] The present invention provides a virtual encryption machine platform based on trusted computing technology and a creation method. Relying on the trusted computing module and secure trusted capabilities integrated in mainstream processors, the trusted execution environment TEE (Trusted Execution Environment) is used to replace the traditional encryption machine system as a new operating carrier for key management and secure encryption, and a processor-based native virtual encryption machine platform for multi-tenants is constructed, enabling users to implement their own business systems and the encryption machine function in the same processing platform, achieving the integration of the business system and the security system, avoiding the security risks of the user's critical data being invaded, hijacked, and maliciously exploited in the encryption machine, truly keeping the key information in their own hands, and realizing secure, autonomous, and controllable. At the same time, for the multi-tenant scenario of the cloud platform, multiple virtual encryption machines can be established in the same TEE, and an independent physically isolated secure trusted environment and exclusive security service are allocated to each cloud tenant to ensure the cloud security of user data. The technical solution of the present invention can conveniently and flexibly provide lightweight exclusive security services for different tenants on the same platform, and realize the integrated deployment and construction of the encryption machine and the cloud platform.
[0065] Those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed in the present invention. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present invention are pointed out by the appended claims.
[0066] It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A method for creating a virtual encryption machine platform based on trusted technology, characterized in that, Based on TrustZone technology, the running ARM core is divided into a secure state and a non-secure state. The secure state corresponds to a system environment with OP-TEE as the trusted execution environment (TEE), and the non-secure state corresponds to a normal execution environment (REE). Among them, the TEE provides a secure operating and deployment environment for the virtual encryption machine, and private information and related operations are all processed by the trusted application (TA) running in the TEE. TA is an application program instance that provides secure encryption services for tenants in the TEE user space. The CA is a user service application program instance that realizes the docking with the TEE in the REE user space; data interaction between the CA and the TA will be carried out through the OP-TEE driver to establish a shared memory between the TEE and the REE during the mounting process. In terms of hardware isolation, TrustZone uses security extension components to complete the hardware resource isolation between the TEE and the REE, and constructs an independent hardware secure operating environment. The security extension components include: TZASC, TZIC, TZPC; in terms of software isolation, OP-TEE uses a microkernel, a library operating system, and integrates a trusted core framework, a trusted communication proxy, and a trusted hardware driver to implement a secure operating system. Multiple virtual encryption machines are established in the TEE, and the virtual encryption machines establish exclusive security service programs TA for different users' CAs.
2. A method for creating a virtual encryption machine platform based on trusted technology according to claim 1, characterized in that A secure state read / write signal is added to the system bus to prohibit the REE from accessing the resources in the TEE; in terms of the address space, the address space controller TZASC is used to divide a secure address area to reject non-secure access, and the dynamic memory controller DMC is hung on it to realize the secure access of the DRAM dynamic random access memory. The memory adapter TZMA can realize the dynamic partitioning of the on-chip RAM, and the low address segment of each partition is used as a secure area. The protection controller TZPC can set the peripherals as secure peripherals. The interrupt controller TZIC makes the processor unable to capture secure interrupts when in the secure state.
3. A method for creating a virtual encryption machine platform based on trusted technology according to claim 1, characterized in that, The hardware isolation is to isolate the resources between the TEE and the REE in terms of memory, cache, interrupt, and peripherals; specifically, the memory isolation is jointly completed by the MMU and the TZASC. The TEE and the REE have their own independent MMU system control registers, and different execution environments have their own independent page table sets. The virtual address to physical address conversion is completed by their respective logical MMUs, and the address spaces of the TEE and the REE are isolated from each other. Peripheral protection is implemented by the TZPC. By configuring the device as secure or non-secure through the TZPC, the device configured as secure can only be accessed in a secure environment. Interrupt isolation is implemented by the TZIC. The TZIC is used as a first-level interrupt source controller to control all external interrupt sources, and the secure interrupt sources are set by programming the registers of the TZIC.
4. A method for creating a virtual encryption machine platform based on trusted technology according to claim 1, characterized in that, Before establishing multiple virtual encryption machines in the TEE: An interface layer needs to be established on top of the secure operating system. By invoking the trusted module calculation in the kernel, functions such as certificate management and various mainstream encryption and decryption algorithms are implemented and encapsulated as underlying interface functions for the upper-layer security service programs to use.
5. A method for creating a virtual encryption machine platform based on trusted technology according to claim 1, characterized in that, After the virtual encryption machine is created: The trusted execution environment TEE receives the instructions issued by the user and generates the first instruction. According to the first instruction, the trusted execution environment applies to access the configuration TZPC and TZASC to obtain the first physical memory isolation area. The first physical memory isolation area is separated into several memory isolation areas, and the several memory isolation areas correspond to several security service programs. The trusted execution environment sends the security service program to the user.
6. A method for creating a virtual encryption machine platform based on trusted technology according to claim 5, characterized in that, Before the trusted execution environment sends the security service program to the user: Create a logical link for communication between the CA and TA in the REE and TEE, and generate a session-unique identification code. The TA identifies its identity through the unique identification code. The CA calls the interface to establish a session. The interface calls the driver function to send a call request to the security monitoring mode to notify the TEE to execute the session creation operation. OP-TEE will match or load the corresponding TA according to the unique identification code to complete the session creation.
7. A method for creating a virtual encryption machine platform based on trusted technology according to claim 5, characterized in that, The memory isolation area matches different physical memories according to the user's needs.
8. A method for creating a virtual encryption machine platform based on trusted technology according to claim 6, characterized in that, There is a unique mapping relationship between the user and the security service program.
9. A method for creating a virtual encryption machine platform based on trusted technology according to claim 1, characterized in that, The virtual encryption machine provides a full-cycle trusted key management mechanism to implement functions such as automatic key generation, secure storage, addition and deletion, backup and recovery. The full-cycle trusted key management mechanism establishes a security service program with data encryption and decryption, signature, and verification functions according to the user's needs.
10. A virtual encryption machine platform constructed by the method described in claim 1, characterized in that, It includes: Establish a software and hardware encryption system on a processor platform integrated with a trusted computing module to implement the operation of the trusted execution environment TEE and the normal execution environment REE. Between the REE and the TEE, through the use of memory isolation and CPU access permission control technologies at the bottom layer, independent hardware areas are divided to achieve mutual isolation; multiple virtual encryption machines are established in the TEE; the virtual encryption machine realizes hardware isolation from the normal execution environment REE, establishes a secure and trusted environment for the CAs of different users and designates exclusive security service program TAs for them, and effectively manages them. Among them, the CA is an instance of the user business application program that realizes docking with the TEE in the REE user space. The TA is an instance of the application program that provides security encryption services for tenants in the TEE user space.