Method and device for establishing data transmission channel
By using the signature and verification of the secure processor signature file in the data transmission between the encrypted virtual machine and the data server, the problem of reducing data transmission security caused by the virtual machine monitor software vulnerability is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- CN202111604681.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-24
AI Technical Summary
Virtual machine monitors are prone to software vulnerabilities, resulting in reduced security of data transmission between encrypted virtual machines and data servers.
The signature file signed by the secure processor using the chip private key, contains the virtual machine public key and the metric value to be checked by the encrypted virtual machine, and is checked and checked, generates a data transmission key, and is encrypted by the virtual machine public key and sent to the encrypted virtual machine.
Improve the security of data transmission between the encrypted virtual machine and the data server, prevent malicious acquisition and tampering, and ensure the security of the data transmission key.
Smart Images

Figure CN114282242B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of cloud computing technology, and in particular to a method and device for establishing a data transmission channel of an encrypted virtual machine. Background Art
[0002] With the development of cloud computing technology, more and more companies are beginning to deploy business systems on the cloud and provide services to customers in the form of virtual machines. Since encrypted virtual machines can provide more secure memory encryption functions, cloud computing service providers usually protect the data transmitted and used by users by deploying encrypted virtual machines. Specifically, they use the password management system and virtual machine monitor provided by the platform center to establish a secure data transmission channel between the encrypted virtual machine and the user's data server, and ensure the security of data access.
[0003] However, virtual machine monitors are prone to software vulnerabilities, which greatly reduces the security of data transmission between encrypted virtual machines and data servers.
[0004] Therefore, how to improve the security of data transmission between the encrypted virtual machine and the data server becomes a technical problem that needs to be solved by those skilled in the art. Summary of the invention
[0005] In view of this, embodiments of the present application provide a method and device for establishing a data transmission channel to improve the security of data transmission between an encrypted virtual machine and a data server.
[0006] In a first aspect, an embodiment of the present application provides a method for establishing a data transmission channel, applicable to a data server, comprising:
[0007] Receiving a signature file sent by a pre-started encrypted virtual machine, the signature file including a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine, the signature file being signed by a security processor using a chip private key;
[0008] Verifying the signature file using the chip public key that matches the chip private key;
[0009] When the signature verification passes, the metric value to be verified is verified using the pre-stored expected metric value corresponding to the metric value to be verified;
[0010] When the to-be-verified metric value is consistent with the expected metric value, generating a data transmission key;
[0011] The data transmission key is encrypted using the virtual machine public key to obtain an encrypted data transmission key, and the encrypted data transmission key is sent to the encrypted virtual machine so that the encrypted virtual machine can use a virtual machine private key that matches the virtual machine public key to decrypt the encrypted data transmission key, obtain the data transmission key, and establish the data transmission channel.
[0012] In a second aspect, an embodiment of the present application provides a method for establishing a data transmission channel, which is applicable to an encrypted virtual machine, including:
[0013] Sending a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine;
[0014] Receive the encrypted data transmission key obtained by encrypting the data transmission key with the virtual machine public key, and decrypt the encrypted data transmission key with the virtual machine private key that matches the virtual machine public key to obtain the data transmission key, and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by the chip public key that matches the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
[0015] In a third aspect, an embodiment of the present application provides a device for establishing a data transmission channel, applicable to a data server, including:
[0016] A receiving unit, adapted to receive a signature file sent by a pre-started encrypted virtual machine, wherein the signature file includes a virtual machine public key and a metric value to be verified of the encrypted virtual machine, and the signature file is signed by a security processor using a chip private key;
[0017] A signature verification unit, adapted to verify the signature of the signature file using a chip public key that matches the chip private key;
[0018] a verification unit, adapted to verify the metric value to be verified using a pre-stored expected metric value corresponding to the metric value to be verified when the signature verification passes;
[0019] a key generation unit, adapted to generate a data transmission key when the metric value to be verified is consistent with the expected metric value;
[0020] The encryption unit is suitable for encrypting the data transmission key by using the virtual machine public key to obtain the encrypted data transmission key, and sending the encrypted data transmission key to the encryption virtual machine so that the encryption virtual machine can use the virtual machine private key matching the virtual machine public key to decrypt the encrypted data transmission key, obtain the data transmission key, and establish the data transmission channel.
[0021] In a fourth aspect, an embodiment of the present application provides a device for establishing a data transmission channel, which is applicable to an encrypted virtual machine, including:
[0022] An encrypted virtual machine sending unit, adapted to send a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine;
[0023] The encrypted virtual machine receiving unit is suitable for receiving an encrypted data transmission key obtained by encrypting a data transmission key with the virtual machine public key, and decrypting the encrypted data transmission key with a virtual machine private key matching the virtual machine public key to obtain the data transmission key, and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by the chip public key matching the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
[0024] The method for establishing a data transmission channel provided in the embodiment of the present application receives a signature file signed by a security processor using a chip private key, and uses the chip public key corresponding to the chip private key to verify the signature to ensure the source of the signature file, and then uses the expected measurement value to verify the measurement value to be verified in the signature file, and verifies that the information related to the encrypted virtual machine has not been tampered with. On the basis of ensuring the consistency of the two, a data transmission key is generated, and after being encrypted by using the virtual machine public key in the signature file, it is sent to the encrypted virtual machine to ensure that the data transmission key will not be maliciously obtained during the transmission process, thereby improving its security, thereby improving the security of the data to be transmitted when the data transmission key is used for encryption, and realizing the establishment of a data channel that can safely transmit data. In this way, the signature file is signed by the security processor using the chip private key, the signature device is hardware, and the private key used is also a hardware private key, thereby avoiding the leakage of the signature private key due to software vulnerabilities, improving the authenticity of the signature file, ensuring the validity of the verification result of the measurement value to be verified in the signature file, and the authenticity of the two parties connected by the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel between the encrypted virtual machine and the data server, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0026] Figure 1 A flow chart of a method for establishing a data transmission channel;
[0027] Figure 2 A flow chart of a method for establishing a data transmission channel provided in an embodiment of the present application;
[0028] Figure 3 A schematic diagram of an encrypted virtual machine image and a boot program for a method for establishing a data transmission channel provided in an embodiment of the present application;
[0029] Figure 4 A schematic diagram of the deployment of an encrypted virtual machine for the method for establishing a data transmission channel provided in an embodiment of the present application;
[0030] Figure 5 A flowchart of a virtual machine startup of a method for establishing a data transmission channel provided in an embodiment of the present application;
[0031] Figure 6 A framework diagram of a device for establishing a data transmission channel provided in an embodiment of the present application;
[0032] Figure 7 Another framework diagram of the device for establishing a data transmission channel provided in an embodiment of the present application. DETAILED DESCRIPTION
[0033] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0034] For ease of understanding, the existing method for establishing a data transmission channel is first introduced below.
[0035] Please refer to Figure 1 , Figure 1 A flow chart of a method for establishing a data transmission channel.
[0036] It should be noted that Figure 1The method for establishing a data transmission channel shown is specifically a method for establishing a data transmission channel required when a data provider uses an algorithm model provided by an algorithm model provider (not shown in the figure) on a virtual machine applied for from a platform provider (i.e., a platform center) to perform operations on data, wherein the data provider includes a data server 110, and the platform center includes a password management system 120, a virtual machine 130, a virtual machine monitor 140, and a virtual machine 150.
[0037] like Figure 1 As shown, the process of establishing the data transmission channel involves the aforementioned data server 110, password management system 120, virtual machine 130, virtual machine monitor 140 and virtual machine 150, wherein the password management system 120 and virtual machine monitor 140 are software provided and maintained by the platform center, the password management system 120 is used to create and manage the keys in the process of establishing the data transmission channel, and the virtual machine monitor 140 is suitable for managing each virtual machine; the data server 110 is a server for storing data by the data provider.
[0038] Specifically, the steps for establishing a data transmission channel include:
[0039] In step S11, the password management system 120 creates a transmission key pair (a data key and an encrypted data key).
[0040] Among them, the data key is directly created by the password management system 120 and is used to encrypt data in the data server, including a data public key and a data private key. The encrypted data key is generated by encrypting the data key (data public key) using the user key and is used as a label for the encrypted data. The user key is generated by the data server 110.
[0041] The password management system 120 is provided by the platform center for use by each data server 110 , so the data keys of all virtual machines of the platform center are stored inside the password management system 120 , and memory accesses of all virtual machines of the platform center are received.
[0042] In step S12, the virtual machine 130 measures the algorithm model and the disk image to generate a disk image measurement value and an algorithm model measurement value.
[0043] It is easy to understand that virtual machine 130 is the virtual machine used by the platform center to start virtual machine 150 (equivalent to an encrypted virtual machine). Because the platform center is trusted, the disk image measurement values and algorithm model measurement values generated by virtual machine 130 are both expected measurement values that can be trusted.
[0044] The algorithm model is provided by the algorithm model provider. Specifically, the algorithm model can be an AI algorithm model or a non-AI algorithm model.
[0045] Before performing data calculations, the algorithm model can be stored in a disk image file in advance.
[0046] The disk image includes a virtual machine image of the virtual machine 150 and a boot program for starting the virtual machine 150, specifically, an operating system of the virtual machine 150. It is easy to understand that before loading the virtual machine image, the virtual machine 150 cannot run the data provided by the algorithm model calculation data server 110.
[0047] In step S13, the virtual machine 130 packages the disk image and the algorithm model.
[0048] The virtual machine 130 uses the tools provided by the platform center to package the disk image and the algorithm model, wherein the packaging is for more efficient transmission of the disk image and the algorithm model, and the disk image and the algorithm model may not be packaged.
[0049] In step 14 , the virtual machine 130 sends the measurement values and the packaged file to the password management system 120 .
[0050] After the virtual machine 130 sends the measurement values and the packaged file to the password management system 120, the password management system 120 stores the measurement values as expected measurement values for subsequent key authentication condition verification.
[0051] It is easy to understand that steps S12, S13 and S14 must be executed in sequence, but step S11 is not necessarily executed before step S12, as long as it is executed before the virtual machine 150 obtains the data ciphertext and the encryption data key in step S19.
[0052] In step S15 , the virtual machine 130 sends a request to start the virtual machine 150 to the virtual machine monitor 140 .
[0053] After the virtual machine 130 sends the measurement values and the packaged file to the password management system 120 , the virtual machine 130 sends a request to start the virtual machine 150 to the virtual machine monitor 140 , requesting the virtual machine monitor 140 to start the virtual machine 150 .
[0054] In step S16 , the virtual machine monitor 140 starts the virtual machine 150 .
[0055] Specifically, the virtual machine monitor 140 may start the virtual machine 150 using the disk image in the specified packaged image.
[0056] Of course, the disk image includes the boot loader used by the startup program.
[0057] In step S17 , the virtual machine 150 is started and runs.
[0058] It can be seen that after the above steps S13 and S15-S17, the startup of the virtual machine 150 is achieved.
[0059] Steps S12 and S14 are used to obtain and send the expected metric value for verifying the started virtual machine 150.
[0060] After starting the virtual machine 150, for subsequent data processing, it is necessary to establish a data transmission channel between the virtual machine 150 and the data server 110, please continue to refer to the following description:
[0061] In step S18 , the virtual machine 150 generates a model public key and a model private key.
[0062] Of course, the model public key needs to be securely and reliably transmitted to the password management system 120 , and the model private key needs to be securely stored in the virtual machine 150 .
[0063] In step S19 , the virtual machine 150 obtains the data ciphertext and the encrypted data key from the data server 110 .
[0064] The data ciphertext is obtained by encrypting the data in the encryption data server 110 using the data key created in step S11.
[0065] As described in the above step S11 , the function of the encrypted data key is to identify the virtual machine 150 to which the ciphertext data is to be sent, so that the data server 110 correctly transmits the ciphertext data to the ciphertext virtual machine 150 .
[0066] Of course, at this time, the virtual machine 150 does not have a data key yet, which is not enough to decrypt the data ciphertext.
[0067] In step S20 , the virtual machine 150 requests the virtual machine monitor 140 to perform signature authentication on the file to be signed.
[0068] After the virtual machine 150 is started, it not only generates a model public key and a model private key, but also generates the measurement values to be verified for each module, which may specifically include disk image measurement values and AI algorithm model measurement values, etc. In order to establish a data transmission path, it is necessary to verify each measurement value to be verified. For this purpose, the virtual machine 150 sends the model public key, the encrypted data key and the measurement values of each module to the virtual machine monitor 140, and requests the virtual machine monitor 140 to sign and authenticate the file to be signed.
[0069] In step S21 , the virtual machine monitor 140 signs the file to be signed.
[0070] The virtual machine monitor 140 signs the file to be signed, which includes the model public key, the encrypted data key and the measurement values of each module (disk image measurement values and AI algorithm model measurement values, etc.), to obtain a signature file. Specifically, the monitor private key is used to sign the signature file, and its monitor public key can be obtained reliably through public channels.
[0071] After the signed signature file is obtained, it is sent back to the virtual machine 150 .
[0072] In step S22 , the virtual machine 150 receives the signature file sent back by the virtual machine monitor 140 , and sends it to the password management system 120 .
[0073] In step S23, the password management system 120 verifies the signature file and the metric value.
[0074] Before reading the key in the received signature file, the password management system 120 needs to perform signature verification and metric value verification. Only when the signature verification and metric value verification are all met, can the key in the signature file be obtained.
[0075] Of course, the signature file can contain multiple measurement values of different data. The correct verification of each measurement value means that the corresponding data has not been tampered with. Only when all measurement values are correct can it be ensured that the information corresponding to the measurement value is complete and has not been tampered with.
[0076] The signature file is verified using the monitor public key. If the verification is successful, the encrypted data key and measurement value are taken out from the signature file and the measurement value is verified.
[0077] The disk image metric value and the algorithm model metric value to be verified in the signature file are verified with each expected metric value sent by the virtual machine 130 to the password management system 120 in step S14.
[0078] Since the expected measurement values of different virtual machines are stored in the password management system 120, in order to distinguish different virtual machines, thereby selecting the corresponding expected measurement values stored in the password management system 120 and implementing the verification of the corresponding measurement values, the signature file received by the password management system 120 should include a label indicating the identity of the virtual machine 150. In a specific embodiment, the label can be an encrypted data key.
[0079] When the signature verification is passed, after taking out each measurement value from the signature file, compare the measurement value with the expected measurement value to see if they are consistent. If they are consistent, execute step S24. Otherwise, it indicates that the data corresponding to the measurement value, that is, the corresponding part of the virtual machine 150, has been tampered with and is at risk of being stolen by malicious parties. In this case, the password management system needs to perform exception processing. Specifically, it can be to notify the platform center to take the currently connected encrypted secret virtual machine offline.
[0080] Of course, if the signature verification fails, the password management system needs to perform exception processing. Specifically, it can notify the platform center to take the currently connected encrypted virtual machine offline.
[0081] In step S24 , the password management system 120 encrypts the data public key using the model public key in the signature file to obtain a key ciphertext, and sends it to the virtual machine 150 .
[0082] It is easy to understand that the key ciphertext can also be sent to the virtual machine 150 via the encrypted data key identifier.
[0083] In step S25 , the virtual machine 150 decrypts the received key ciphertext using the model private key to obtain the data public key.
[0084] In step S26, the virtual machine 150 decrypts the data ciphertext with the data public key to obtain the data plaintext, and processes the data in the data plaintext through the algorithm model.
[0085] In this way, based on the above process, virtual machine 150 obtains the data public key, and a data transmission channel is established between data server 110 and virtual machine 150, so as to securely transmit the data of data server 110 to virtual machine 150, and securely transmit the result back to data server 110.
[0086] It can be seen that the key to establishing the data transmission channel is to send the model public key used to encrypt the data public key to the password management system securely and without tampering. To this end, the following operations are performed:
[0087] A model public key and a model private key are generated by the virtual machine 150 , wherein the virtual machine 150 stores the model private key and does not transmit it to any other device, while transmitting the model public key.
[0088] In order to ensure the transmission of the model public key, a signature file signed by the virtual machine monitor 140 is used. The virtual machine monitor 140 uses the internally stored virtual machine private key to sign and authenticate the transmitted file to be signed. The password management system 120 verifies the signature file through the virtual machine public key to ensure that the signature file comes from the virtual machine monitor 140, to ensure that the file in the signature file is the same as the file received by the virtual machine monitor 140 for authentication and signature, and has not been tampered with.
[0089] In order to ensure that the model public key in the signature file is the model public key of the virtual machine 150, the measurement values in the signature file are further compared with the measurement values of the files such as the image of the virtual machine 150 started and stored in the password management system 120. Then, it can be determined that the virtual machine that sends a request to authenticate the signature file to the virtual machine monitor 140 is the virtual machine 150 started by the virtual machine 130, thereby determining the source of the model public key in the signature file.
[0090] It can be seen that the virtual machine monitor 140 in the prior art plays an important role in ensuring security. The virtual machine private key in the virtual machine monitor 140 and the measurement value of the file for starting the virtual machine 150 stored in the password management system 120 are important comparison bases for ensuring security. However, the virtual machine monitor 140 is software provided and maintained by the platform center. Due to factors such as software vulnerabilities, it is difficult to ensure that the above data will not be leaked or tampered with.
[0091] For example, after stealing the virtual machine private key of the virtual machine monitor 140, the thief can forge a signature file and send it to the password management system 120. After that, whether directly tampering with the measurement values saved by the password management system 120 or stealing the measurement values from the password management system 120, the thief can pass the wrong model public key to the data server 110, thereby establishing a data transmission channel between the data server 110 and the thief and stealing the data of the data server 110. The existing solutions cannot establish a secure transmission channel to ensure the security of the transmitted data.
[0092] In order to solve the aforementioned problems, the embodiments of the present application provide a method, device and system for establishing a data transmission channel, so as to more securely establish the data transmission channel and protect the security of the transmitted data.
[0093] For ease of understanding, the following Figure 2 , a method for establishing a data transmission channel provided in an embodiment of the present application is introduced.
[0094] Please refer to Figure 2 , Figure 2 A flow chart of a method for establishing a data transmission channel provided in an embodiment of the present application.
[0095] like Figure 2 As shown, the method for establishing a data transmission channel provided in the embodiment of the present application mainly involves a platform center 210, a data server 220 and an encrypted virtual machine 230.
[0096] In step S30 , the encryption virtual machine 230 sends a signature file signed by the security processor using the chip private key.
[0097] It is easy to understand that, combined with the above description, before establishing the data transmission channel, it is necessary to first start the encryption virtual machine 230. Therefore, the data transmission channel provided in the embodiment of the present application is established after the encryption virtual machine 230 is started.
[0098] For ease of understanding, the description of starting the encrypted virtual machine 230 is first given. Of course, before starting the encrypted virtual machine 230, relevant configurations need to be performed first. For this purpose, the configuration process of the encrypted virtual machine is first described:
[0099] Please refer to Figure 3 and Figure 4 , Figure 3 A schematic diagram of an encrypted virtual machine image and a boot program for a method for establishing a data transmission channel provided in an embodiment of the present application; Figure 4 A schematic diagram of the deployment of an encrypted virtual machine for the method for establishing a data transmission channel provided in an embodiment of the present application.
[0100] Before the encrypted virtual machine is started, when the platform center 210 receives a request from the data server 220 to provide an encrypted virtual machine, it first needs to configure the boot program and the encrypted virtual machine 230 according to the request.
[0101] It is easy to understand that the boot program is a program that starts the operating system. The physical host that loads the virtual machine image and the boot program first runs the boot program and starts the virtual machine according to the boot program, that is, starts the operating system of the virtual machine.
[0102] The boot program may be provided by the platform center 210 .
[0103] The encrypted virtual machine image may include the aforementioned platform configuration module provided by the platform center 210 and the algorithm model provided by the algorithm model provider 250, such as Figure 3 As shown. Among them, the platform configuration module may specifically include:
[0104] The CPU model of the encrypted virtual machine deployment;
[0105] Validity period of the encrypted virtual machine image (used to ensure that the encrypted virtual machine performs confidential computing services within the specified time. If the validity period expires, it will be automatically offline).
[0106] However, in order to improve the security of the encrypted virtual machine, in another specific implementation, when establishing the encrypted virtual machine image, not only the platform configuration module can be provided by the platform center 210, but also a security module can be further provided. Specifically, the security module can be provided by the data server 220, such as Figure 4 As shown, the security module may specifically include:
[0107] The network monitoring module is used to ensure that the network can only transmit data with the expected data server 220. When illegal transmission occurs, the data packet is intercepted and data processing is immediately stopped, and the platform center 210 is notified to offline the entire encrypted virtual machine (confidential computing service);
[0108] The input and output monitoring module is used to monitor the activities of all external devices except the network, and only allows one-way data transmission, that is, the encrypted virtual machine 230 can read data from the external device, but cannot write data to the external device, to ensure data security.
[0109] Once data is written to an external device, the data packet is intercepted and data processing is immediately stopped, and the platform center 210 is notified to take the entire encrypted virtual machine (confidential computing service) offline.
[0110] The network service module is used to transmit data to the IP port specified by the data server 220.
[0111] The data server 220 is the user side, and the security module provided by the data server 220 can improve the security of data transmission.
[0112] In this way, after configuration, the encryption virtual machine 230 includes a platform configuration module, an algorithm model and a security module.
[0113] Of course, in order to further ensure the mutual recognition and integrity of the configurations provided by the parties and prevent tampering, after each party provides the relevant configuration, an audit can be conducted among the parties, and then the encrypted virtual machine 230 can be started. In order to subsequently implement the measurement of the encrypted virtual machine 230 after startup, the measurement value reviewed and approved by all parties will be used as the expected measurement value.
[0114] Specifically, the platform center 210 can measure the boot program and platform configuration it provides respectively, obtain a first boot program measurement value and a first platform module measurement value, and send the first boot program measurement value and the boot program, as well as the first platform module measurement value and the platform configuration to other parties. The other parties measure the received boot program and platform configuration respectively, obtain a second boot program measurement value and a second platform module measurement value, compare the first boot program measurement value and the second boot program measurement value, and compare the first platform module measurement value and the second platform module measurement value. If they are consistent, then the review is completed, the integrity of the boot program and the platform configuration is guaranteed, and the expected boot program measurement value and the expected platform module measurement value are obtained.
[0115] As for the security module, the data server 220 measures the security module to obtain a first security module measurement value, and sends the first security module measurement value and the security module to other parties. The other parties measure the received security module to obtain a second security module measurement value, and compare the first security module measurement value with the second security module measurement value. If they are consistent, it means that the audit is completed, the integrity of the security module can be guaranteed, and the expected measurement value of the security module can be obtained.
[0116] The algorithm model provider measures the algorithm model to obtain a first model measurement value, and sends the first model measurement value and the algorithm model to other parties. The other parties measure the received algorithm model to obtain a second model measurement value, and compare the first model measurement value with the second model measurement value. If they are consistent, then the review is completed, the integrity of the algorithm model can be guaranteed, and the expected measurement value of the model can be obtained.
[0117] After completing the review by all parties, an audited encrypted virtual machine 230 including platform configuration, security module and algorithm model can be obtained, and its corresponding encrypted virtual machine image can be stored in the platform center 210 for use when the encrypted virtual machine is started. That is, the encrypted virtual machine image used to start the encrypted virtual machine includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all audited by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model, so as to reduce the possibility of the started encrypted virtual machine being tampered with.
[0118] In order to ensure the integrity of each part when establishing the subsequent data transmission channel, the expected measurement values obtained above and confirmed by all parties can be stored in the data server 220 or the password management system provided by the platform center. Since the data server 220 is more reliable, the expected measurement values can be stored in the data server 220.
[0119] It is easy to understand that when the encrypted virtual machine configuration is implemented by both the platform center 210 and the data server 220, the expected measurement value includes the measurement value confirmed by at least the platform center and the data server; when the algorithm model is also provided by the algorithm model provider, the expected measurement value includes the measurement value confirmed by the platform center, the data server and the algorithm model provider.
[0120] It can be seen that the expected measurement value obtained after multiple audits and confirmation has higher integrity and security, and will not be tampered with due to the influence of the platform center 210.
[0121] Of course, in addition to the aforementioned expected measurement values, the entire encrypted virtual machine image can also be measured to obtain the expected measurement value of the virtual machine image, and stored in the data server 220 or the password management system to determine the integrity of the entire encrypted virtual machine image.
[0122] In order to ensure the security and integrity of the expected measurement value of the virtual machine image, in some specific implementations, the expected measurement value of the virtual machine image may also be audited by various parties.
[0123] It is easy to understand that, in other embodiments, each expected measurement value may also be a measurement value that has not been reviewed by all parties but is only provided by the corresponding configuration provider.
[0124] For the convenience of description, the following embodiments are described by taking the storage of each expected metric value in the data server 220 as an example.
[0125] After completing the configuration of the encrypted virtual machine 230, the encrypted virtual machine 230 can be started based on the configuration.
[0126] In a specific implementation, the encrypted virtual machine 230 can be started by a physical host, and the physical host allocates the encrypted virtual machine 230 through the platform center 210 of the encrypted virtual machine 230. For details, please refer to Figure 5 , Figure 5 A flowchart of a virtual machine startup method for establishing a data transmission channel provided in an embodiment of the present application.
[0127] like Figure 5 As shown, the steps of starting the encrypted virtual machine of the method for establishing a data transmission channel provided in the embodiment of the present application may include:
[0128] In step S41 , the platform center 210 allocates a physical host 240 to the encrypted virtual machine 230 .
[0129] When the platform center 210 allocates a physical host in response to a request from the data server 220 , it needs to consider allocating the physical structure required to support the operation of the encrypted virtual machine and the implementation of the algorithm model.
[0130] When starting the virtual machine, a specific physical host is assigned to the encrypted virtual machine according to the CPU model in the aforementioned platform configuration module. It is easy to understand that the physical host required for this application must include a security processor.
[0131] The security processor is a dedicated processor responsible for security and is a hardware structure located on the physical host supporting the encrypted virtual machine 230, specifically located inside the chip of the physical host.
[0132] In step S42 , the physical host 240 obtains the boot program and the encrypted virtual machine image of the encrypted virtual machine 230 .
[0133] According to the above description, when performing relevant configuration, the boot program and the encrypted virtual machine image are stored in the platform center 210. When the encrypted virtual machine needs to be started, the physical host 240 obtains the boot program and the encrypted virtual machine image for starting the encrypted virtual machine 240 from the platform center 210.
[0134] In step S43, the physical host 240 sends the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified.
[0135] Since the boot program is sent from the platform center 210 to the physical host 240, that is, the boot program is provided by the platform center 210, the data server 220 cannot determine the integrity and security of the boot program. Figure 2 ) is to start the virtual machine with a correct and untampered boot program and prevent the data in the encrypted virtual machine from being stolen by tampering with the boot program. Before starting the virtual machine, the boot program to be verified measurement value can be obtained first.
[0136] In this embodiment, in order to improve the integrity of the acquired expected measurement value of the boot program, the boot program can be sent to the security processor so that the security processor measures the boot program to obtain the measurement value of the boot program to be verified, so that it can be compared with the expected measurement value of the boot program to determine the integrity and security of the boot program.
[0137] In step S44, the physical host 240 obtains the boot program verification metric value sent back by the security processor, and starts the encrypted virtual machine according to the encrypted virtual machine image and the boot program.
[0138] After completing the acquisition of the to-be-verified metric value of the boot program, the physical host 240 starts the encrypted virtual machine 230 based on the boot program and the encrypted virtual machine image.
[0139] In this way, when the virtual machine is started, the boot program used is measured by the security processor in hardware, which can not only provide the boot program measurement value to be verified for the subsequent verification of the boot program, but also ensure the correspondence between the boot program measurement value to be verified and the boot program, and avoid tampering with the boot program measurement value to be verified when obtaining the boot program measurement value to be verified through software, thereby avoiding the occurrence of a situation where a boot program measurement value to be verified that is consistent with the expected measurement value of the boot program is obtained based on the tampered boot program.
[0140] Of course, in another specific implementation, the boot program may also be measured by a virtual machine monitor. Using a virtual machine monitor to measure the boot program can reduce the burden on the security processor.
[0141] In this way, after the above process, the startup of the encrypted virtual machine 230 can be achieved.
[0142] In order to establish a data transmission channel, after the encrypted virtual machine 230 is started, please continue to refer to Figure 2 , the encryption virtual machine will further generate each to-be-verified measurement value, so as to be verified with each of the previously-acquired expected measurement values. It is easy to understand that each to-be-verified measurement value generated by the encryption virtual machine corresponds to each of the previously-acquired expected measurement values.
[0143] In order to ensure the security of the transmission key used to encrypt the data to be transmitted, the transmission key needs to be encrypted before transmission and decrypted after being received by the encrypted virtual machine 230. Therefore, the encrypted virtual machine 230 needs to generate a virtual machine public key and a virtual machine private key, and transmit the virtual machine public key to the data server 220.
[0144] In order to prevent the expected measurement values and the virtual machine public key from being tampered with during the transmission process, the method for establishing a data transmission channel provided in the present application sends the measurement values to be verified and the virtual machine public key through a signature file. It is easy to understand that the measurement values to be verified in the signature file should also include the boot program measurement values to be verified generated by the security processor.
[0145] It should be noted that, in a specific implementation, in the method for establishing a data transmission channel provided in an embodiment of the present application, the signature file sent by the encrypted virtual machine 230 is authenticated by a secure processing signature, and the signature key used for signature authentication is the chip private key stored in the secure processor.
[0146] The chip private key is burned into the security processor inside the chip when the chip is produced, so that the chip private key can be saved in the form of hardware. The chip private key only exists inside the chip and can only be obtained inside the chip. It will not be leaked to the outside of the chip in any form. Therefore, the chip private key is more secure.
[0147] In this way, the security processor uses the chip private key stored in itself to sign and authenticate the received file that needs to be signed. The security processor is a hardware structure and can only be obtained inside the chip. Therefore, it can avoid the impact of software vulnerabilities on the security of the chip private key, thereby ensuring the security of the chip private key.
[0148] In step S31 , the data server 220 receives the signature file sent by the pre-started encryption virtual machine 230 .
[0149] After the encryption virtual machine 230 sends the signature file, the data server 220 first receives the signature file.
[0150] Of course, as mentioned above, the signature file includes the virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine, and the signature file is signed by the security processor using the chip private key.
[0151] In step S32, the data server 220 determines whether the signature file is verified using the chip public key that matches the chip private key. If the verification is successful, step S33 is executed; if the verification is not successful, step S34 is executed.
[0152] The chip public key refers to the chip public key corresponding to the chip private key that signs the signature file. It is easy to understand that both the chip public key and the chip private key belong to the security processor that signs the signature file.
[0153] Specifically, the data server 220 may apply for the chip public key from the chip manufacturer in advance according to the information sent by the platform center 210, and store it in the data server 220, so that after receiving the signature file, the signature can be directly verified.
[0154] If the signature verification passes, it means that the signature file is a file signed by the security processor of the physical host where the encrypted virtual machine 230 is located, and step S33 can be executed. If the signature verification fails, it means that the signature file is not the required file or has been tampered with, and step S34 is executed.
[0155] In step S33, it is determined whether the verification of the metric value to be verified using the pre-stored expected metric value corresponding to the metric value to be verified is successful. If the verification is successful, step S35 is executed; if the verification is not successful, step S36 is executed.
[0156] Of course, the expected measurement value corresponding to the measurement value to be verified and pre-stored in the data server 220 refers to the expected measurement value obtained in the aforementioned encryption virtual machine configuration phase, and specifically can be a measurement value obtained after review by all parties.
[0157] The said party audit refers to the method in which the encrypted virtual machine image and the boot program are jointly audited by the providers of the various components of the encrypted virtual machine image. For the specific audit method and the method for obtaining each expected measurement value, please refer to the previous description and will not be repeated here.
[0158] In a specific embodiment, as mentioned above, the expected metric value includes a corresponding metric value confirmed by at least the platform center and the data server.
[0159] In this way, the expected measurement value is at least confirmed by both the platform center 210 and the data server 220, so as to ensure that the expected measurement value is accurate and has not been tampered with, thereby ensuring the accuracy of the judgment result.
[0160] Specifically, the to-be-verified metric value includes the to-be-verified metric value of the boot program and the to-be-verified metric value of the virtual machine image. Correspondingly, the expected metric value includes the expected metric value of the boot program and the expected metric value of the virtual machine image.
[0161] By verifying the boot program's to-be-verified metric value with the boot program's expected metric value, it can be ensured that the encrypted virtual machine 230 is started with a correct, untampered boot program, and the data in the encrypted virtual machine can be prevented from being stolen by tampering with the boot program; by verifying the virtual machine image's to-be-verified metric value with the virtual machine image's expected metric value, it can be ensured that the overall integrity and security of the encrypted virtual machine 230 are guaranteed, and that the started virtual machine is the virtual machine assigned to the corresponding data server 220 and has not been tampered with, thereby ensuring data security during the data processing process.
[0162] In another specific embodiment, based on the above description, in order for the encrypted virtual machine to protect the running data, the encrypted virtual machine image also includes a security module, and the security module is first started when the encrypted virtual machine is started to monitor and record abnormal behavior. In this case, in order to ensure the integrity of the security module, the to-be-verified metric value also includes the security module to-be-verified metric value of the security module provided by the data server, and the expected metric value also includes the security module expected metric value.
[0163] By setting up a security module in the encrypted virtual machine, the abnormal status of the data running in the encrypted virtual machine can be monitored to improve the security of the data transmission process. By verifying the security module's to-be-verified metric value with the security module's expected metric value, it is ensured that the security module running the encrypted virtual machine has not been tampered with, thereby preventing security risks caused by tampering with the security module.
[0164] Specifically, as mentioned above, the security module includes: a network monitoring module, a network service module and an input / output monitoring module.
[0165] Among them, the network monitoring module is suitable for ensuring that the network can only transmit data with the expected server. When illegal transmission occurs, it intercepts the data packet and immediately stops data processing, and notifies the service center to take the entire confidential computing business offline.
[0166] The network service module is suitable for transmitting data to the IP port specified by the data source.
[0167] The input and output monitoring module is suitable for monitoring all peripheral activities except the network, and only allows one-way data transmission, that is, the virtual machine can read data from the peripheral but cannot write data to the peripheral, to ensure data security
[0168] In this way, it is possible to monitor various aspects of network transmission, input and output, and the monitoring content is more comprehensive.
[0169] In a specific embodiment, in order to ensure the integrity and security of the platform configuration module provided by the platform center 210 used by the started encrypted virtual machine 230, the measurement value to be verified also includes the platform module measurement value to be verified of the platform configuration module provided by the platform center. Of course, the expected measurement value also includes the platform module expected measurement value.
[0170] In this way, if the encrypted virtual machine image sent by the platform center lacks some modules or contains tampered modules, the measurement values to be verified placed in the signature file of the encrypted virtual machine 230 will be deviated, which can be easily verified and discovered by the data server 220, thereby ensuring the integrity and security of each module.
[0171] Of course, the purpose of the data server 220 applying for the encrypted virtual machine 230 from the platform center 210 is to use the algorithm model for calculation. Therefore, in order to further ensure the integrity of each information, in another specific implementation, it is also necessary to ensure that the algorithm model running in the encrypted virtual machine 230 has not been tampered with. In this case, the measurement value to be verified also includes the model measurement value to be verified of the algorithm model, and the expected measurement value also includes the model expected measurement value. Since the algorithm model is provided by the algorithm model provider, the expected measurement value includes the measurement value confirmed by the platform center, the data server and the algorithm model provider.
[0172] It is easy to understand that, in this case, each of the expected measurement values is a measurement value confirmed by the platform center, the data server and the algorithm model provider.
[0173] Specifically, the algorithm model may be an AI algorithm model, and the algorithm provider may be an AI algorithm model provider.
[0174] In this way, by verifying each metric value to be verified and the corresponding expected metric value, it is ensured that the boot program and encrypted virtual machine image sent by the platform center 210 to the physical host 240 are determined during the configuration process, reviewed by all parties, and have not been tampered with.
[0175] In step S34, the currently connected encrypted virtual machine 230 is offline.
[0176] If the signature verification fails, it means that a malicious party is trying to impersonate the encryption virtual machine 230 and hand over the wrong public key to the data server 220, so that the data server 220 encrypts the transmission public key with the wrong public key to further obtain the transmission public key, thereby impersonating the encryption virtual machine 230 to establish a data transmission channel with the data server 220 and steal the data transmitted by the data server.
[0177] Therefore, the data server should immediately notify the platform center 210 to take offline the currently connected encrypted virtual machine 230 to ensure data security.
[0178] In step S35, a data transmission key is generated.
[0179] If the signature verification passes and all the metrics to be verified pass verification, it means that the signature file sent is signed by the security processor and the internal relevant information has not been tampered with. The integrity and security of the encrypted virtual machine 230 can be determined, thereby generating a data transmission key.
[0180] In step S36, the currently connected encrypted virtual machine 230 is offline.
[0181] If the signature verification passes, but the verification of each metric to be verified fails, it means that although the signature file is indeed signed by the security processor, the encrypted virtual machine 230 has been tampered with, and there is a risk of leakage. The data transmission channel should not be established with the encrypted virtual machine 230. Therefore, it is necessary to offline the currently connected encrypted virtual machine 230.
[0182] In step S37, the data transmission key is encrypted using the virtual machine public key to obtain an encrypted data transmission key, and the encrypted data transmission key is sent to the encryption virtual machine.
[0183] When the signature verification passes and all the metric values to be verified pass the verification, the security of the virtual machine key can be determined. Then, after the data transmission key is generated, in order to ensure the security of the data transmission key transmission process, the data transmission key is encrypted using the virtual machine public key to obtain the encrypted data transmission key, and the encrypted data transmission key is sent to the encrypted virtual machine.
[0184] In step S38, the encrypted data transmission key is decrypted using the virtual machine private key that matches the virtual machine public key to obtain the data transmission key and establish the data transmission channel.
[0185] After the encryption virtual machine 230 obtains the encrypted data transmission key, it uses the virtual machine private key that matches the virtual machine public key to decrypt the encrypted data transmission key to obtain the data transmission key, thereby realizing the establishment of a data transmission channel.
[0186] Before being transmitted to the encrypted virtual machine 230, the data in the data server 220 is first encrypted using the data transmission key to obtain encrypted data, and then the encrypted data is transmitted to the data server 220. After receiving the encrypted data, the data server 220 decrypts it using the obtained data transmission key, thereby obtaining the decrypted data and realizing secure data transmission.
[0187] The method for establishing a data transmission channel provided in the embodiment of the present application first obtains the expected measurement values of the encrypted virtual machine 230 through review by all parties, and saves them in the data server 220 to verify whether the started encrypted virtual machine is started according to the module provided by all parties that has not been tampered with; then, the security processor of the physical host 240 corresponding to the encrypted virtual machine 230 uses the chip private key to sign the virtual machine public key and each measurement value to be verified of the encrypted virtual machine 230, and sends them to the data server; finally, when the signature verification and the measurement value to be verified are verified, the data server 220 encrypts the generated data transmission public key with the obtained virtual machine public key, and sends it to the encrypted virtual machine 230, thereby completing the establishment of the data transmission channel.
[0188] Therefore, the method for establishing a data transmission channel provided in the embodiment of the present application uses a chip private key to sign a signature file through a security processor. The signature device is hardware, and the private key used is also a hardware private key, thereby avoiding the leakage of the signature private key due to software vulnerabilities, improving the authenticity of the signature file, ensuring the validity of the verification results of the metric values to be verified in the signature file, and the authenticity of the two parties connected to the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server.
[0189] Of course, in order to solve the aforementioned problem, the embodiment of the present application may also provide a method for establishing a data transmission channel, which is applicable to an encrypted virtual machine and may specifically include the following steps:
[0190] Sending a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine;
[0191] Receive the encrypted data transmission key obtained by encrypting the data transmission key with the virtual machine public key, and decrypt the encrypted data transmission key with the virtual machine private key that matches the virtual machine public key to obtain the data transmission key, and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by the chip public key that matches the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
[0192] It is easy to understand that the specific steps of the method for establishing a data transmission channel for an encrypted virtual machine provided in the embodiment of the present application are the same as the specific steps of the method for establishing a data transmission channel for a data server described above. For specific steps, please refer to Figure 2 The description of steps S30-S38 shown is not repeated here.
[0193] In this way, the signature file is signed by the chip private key through the security processor. The signature device is hardware, and the private key used is also a hardware private key, which can avoid the leakage of the signature private key due to software vulnerabilities, improve the authenticity of the signature file, ensure the validity of the verification result of the metric to be verified in the signature file, and the authenticity of the two parties connected in the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel between the encrypted virtual machine and the data server, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server.
[0194] In some embodiments, the encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include:
[0195] Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are provided by the platform center;
[0196] Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified;
[0197] The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
[0198] For the specific content of starting the encrypted virtual machine, please refer to the specific description of step S30, which will not be repeated here.
[0199] In some embodiments, the encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
[0200] In some embodiments, the metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, the metric values to be verified of the security module of the security module provided by the data server, the metric values to be verified of the platform module of the platform configuration module provided by the platform center, and the model metric values to be verified of the algorithm model; the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, the expected metric values of the security module, the expected metric values of the platform module, and the expected metric values of the model; the expected metric values include metric values confirmed by the platform center, the data server, and the algorithm model provider.
[0201] The present application also provides a device for establishing a data transmission channel, which is applicable to a data server. Figure 6 , Figure 6 A framework diagram of a device for establishing a data transmission channel provided in an embodiment of the present application.
[0202] like Figure 6 As shown, a device for establishing a data transmission channel includes:
[0203] The receiving unit 31 is adapted to receive a signature file sent by a pre-started encrypted virtual machine, wherein the signature file includes a virtual machine public key and a metric value to be verified of the encrypted virtual machine, and the signature file is signed by a security processor using a chip private key;
[0204] The signature verification unit 32 is adapted to verify the signature of the signature file using a chip public key that matches the chip private key;
[0205] A verification unit 33, adapted to verify the metric value to be verified using a pre-stored expected metric value corresponding to the metric value to be verified when the signature verification passes;
[0206] a key generation unit 34, adapted to generate a data transmission key when the metric value to be verified is consistent with the expected metric value;
[0207] The encryption unit 35 is suitable for using the virtual machine public key to encrypt the data transmission key to obtain the encrypted data transmission key, and sending the encrypted data transmission key to the encrypted virtual machine so that the encrypted virtual machine can use the virtual machine private key matching the virtual machine public key to decrypt the encrypted data transmission key, obtain the data transmission key, and establish the data transmission channel.
[0208] In this way, the signature file is signed by the chip private key through the security processor. The signature device is hardware, and the private key used is also a hardware private key, which can avoid the leakage of the signature private key due to software vulnerabilities, improve the authenticity of the signature file, ensure the validity of the verification result of the metric to be verified in the signature file, and the authenticity of the two parties connected in the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel between the encrypted virtual machine and the data server, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server.
[0209] In a specific embodiment, the device for establishing the data transmission channel is applicable to a data server.
[0210] In a specific embodiment, the encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include:
[0211] Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are both provided by the platform center;
[0212] Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified;
[0213] The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
[0214] In this way, when the virtual machine is started, the boot program used is measured by the security processor in hardware, which can not only provide the boot program measurement value to be verified for the subsequent verification of the boot program, but also ensure the correspondence between the boot program measurement value to be verified and the boot program, and avoid tampering with the boot program measurement value to be verified when obtaining the boot program measurement value to be verified through software, thereby avoiding the occurrence of a situation where a boot program measurement value to be verified that is consistent with the expected measurement value of the boot program is obtained based on the tampered boot program.
[0215] In a specific embodiment, the encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model, so as to reduce the possibility of the started encrypted virtual machine being tampered with.
[0216] In a specific embodiment, the expected metric value includes a metric value confirmed by at least the platform center and the data server.
[0217] In a specific embodiment, the to-be-verified metric value includes the to-be-verified metric value of the boot program and the to-be-verified metric value of the virtual machine image, and the expected metric value includes the expected metric value of the boot program and the expected metric value of the virtual machine image.
[0218] In a specific embodiment, the to-be-verified metric value further includes a security module to-be-verified metric value of the security module provided by the data server, and the expected metric value further includes an expected security module metric value.
[0219] In a specific embodiment, the security module includes: a network monitoring module, a network service module and an input / output monitoring module.
[0220] In a specific embodiment, the to-be-verified metric values further include the to-be-verified metric values of the platform modules of the platform configuration module provided by the platform center, and the expected metric values further include the expected metric values of the platform modules.
[0221] In a specific embodiment, the metric values to be verified also include model metric values to be verified of the algorithm model, and the expected metric values also include model expected metric values, and the expected metric values include metric values confirmed by the platform center, the data server, and the algorithm model provider.
[0222] The present application also provides a device for establishing a data transmission channel, which is suitable for a confidential virtual machine. Figure 7 , Figure 7 Another framework diagram of the device for establishing a data transmission channel provided in an embodiment of the present application.
[0223] like Figure 7 As shown, the device for establishing a data transmission channel provided in an embodiment of the present application includes:
[0224] The encrypted virtual machine sending unit 41 is adapted to send a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each metric value to be verified of the encrypted virtual machine;
[0225] The encrypted virtual machine receiving unit 42 is suitable for receiving an encrypted data transmission key obtained by encrypting the data transmission key using the virtual machine public key, and decrypting the encrypted data transmission key using a virtual machine private key matching the virtual machine public key to obtain the data transmission key and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by using the chip public key matching the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
[0226] In this way, the signature file is signed by the chip private key through the security processor. The signature device is hardware, and the private key used is also a hardware private key, which can avoid the leakage of the signature private key due to software vulnerabilities, improve the authenticity of the signature file, ensure the validity of the verification result of the metric to be verified in the signature file, and the authenticity of the two parties connected in the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel between the encrypted virtual machine and the data server, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server.
[0227] In some embodiments, the encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include:
[0228] Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are provided by the platform center;
[0229] Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified;
[0230] The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
[0231] In some embodiments, the encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
[0232] In some embodiments, the metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, the metric values to be verified of the security module of the security module provided by the data server, the metric values to be verified of the platform module of the platform configuration module provided by the platform center, and the model metric values to be verified of the algorithm model; the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, the expected metric values of the security module, the expected metric values of the platform module, and the expected metric values of the model; the expected metric values include the metric values confirmed by the platform center, the data server, and the algorithm model provider.
[0233] An embodiment of the present application also provides a system for establishing a data transmission channel. The electronic device may include the device for establishing a data transmission channel provided in the embodiment of the present application.
[0234] In this way, the signature file is signed by the chip private key through the security processor. The signature device is hardware, and the private key used is also a hardware private key, which can avoid the leakage of the signature private key due to software vulnerabilities, improve the authenticity of the signature file, ensure the validity of the verification result of the metric to be verified in the signature file, and the authenticity of the two parties connected in the data channel, thereby realizing the encryption and secure transmission of the data transmission key, establishing a data transmission channel between the encrypted virtual machine and the data server, realizing the encryption and secure transmission of data, and improving the security of data transmission between the encrypted virtual machine and the data server.
[0235] Although the embodiments of the present application are disclosed above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be subject to the scope defined by the claims.
Claims
1. A method for establishing a data transmission channel, It is characterized in that For data servers, including: Receiving a signature file sent by a pre-started encrypted virtual machine, the signature file including a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine, the signature file being signed by a security processor using a chip private key; Verifying the signature file using the chip public key that matches the chip private key; When the signature verification passes, the metric value to be verified is verified using the pre-stored expected metric value corresponding to the metric value to be verified; When the to-be-verified metric value is consistent with the expected metric value, generating a data transmission key; The data transmission key is encrypted using the virtual machine public key to obtain an encrypted data transmission key, and the encrypted data transmission key is sent to the encrypted virtual machine so that the encrypted virtual machine can use a virtual machine private key that matches the virtual machine public key to decrypt the encrypted data transmission key, obtain the data transmission key, and establish the data transmission channel.
2. The method for establishing a data transmission channel according to claim 1, It is characterized in that The encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include: Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are provided by the platform center; Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified; The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
3. The method for establishing a data transmission channel as claimed in claim 2, It is characterized in that The encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
4. The method for establishing a data transmission channel as claimed in claim 2, It is characterized in that The expected measurement value includes a measurement value confirmed by at least the platform center and the data server.
5. The method for establishing a data transmission channel as claimed in claim 4, It is characterized in that The metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, and the metric values to be verified of the security module of the security module provided by the data server, and the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, and the expected metric values of the security module.
6. The method for establishing a data transmission channel as claimed in claim 5, It is characterized in that The security module includes: a network monitoring module, a network service module and an input / output monitoring module.
7. The method for establishing a data transmission channel as claimed in claim 5, It is characterized in that The to-be-verified metric values also include the to-be-verified metric values of the platform modules of the platform configuration module provided by the platform center, and the expected metric values also include the expected metric values of the platform modules.
8. The method for establishing a data transmission channel as claimed in claim 5, It is characterized in that The metric values to be verified also include the model metric values to be verified of the algorithm model, and the expected metric values also include the model expected metric values, and the expected metric values include the metric values confirmed by the platform center, the data server and the algorithm model provider.
9. A method for establishing a data transmission channel, It is characterized in that Applicable to encrypted virtual machines, including: Sending a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine; Receive the encrypted data transmission key obtained by encrypting the data transmission key with the virtual machine public key, and decrypt the encrypted data transmission key with the virtual machine private key that matches the virtual machine public key to obtain the data transmission key, and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by the chip public key that matches the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
10. The method for establishing a data transmission channel according to claim 9, It is characterized in that The encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include: Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are provided by the platform center; Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified; The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
11. The method for establishing a data transmission channel according to claim 10, It is characterized in that The encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
12. The method for establishing a data transmission channel according to claim 11, It is characterized in that The metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, the metric values to be verified of the security module of the security module provided by the data server, the metric values to be verified of the platform module of the platform configuration module provided by the platform center, and the model metric values to be verified of the algorithm model; the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, the expected metric values of the security module, the expected metric values of the platform module, and the expected metric values of the model; the expected metric values include the metric values confirmed by the platform center, the data server, and the algorithm model provider.
13. A device for establishing a data transmission channel, It is characterized in that For data servers, including: A receiving unit, adapted to receive a signature file sent by a pre-started encrypted virtual machine, wherein the signature file includes a virtual machine public key and a metric value to be verified of the encrypted virtual machine, and the signature file is signed by a security processor using a chip private key; A signature verification unit, adapted to verify the signature of the signature file using a chip public key that matches the chip private key; a verification unit, adapted to verify the metric value to be verified using a pre-stored expected metric value corresponding to the metric value to be verified when the signature verification passes; a key generation unit, adapted to generate a data transmission key when the metric value to be verified is consistent with the expected metric value; The encryption unit is suitable for encrypting the data transmission key by using the virtual machine public key to obtain the encrypted data transmission key, and sending the encrypted data transmission key to the encryption virtual machine so that the encryption virtual machine can use the virtual machine private key matching the virtual machine public key to decrypt the encrypted data transmission key, obtain the data transmission key, and establish the data transmission channel.
14. The device for establishing a data transmission channel according to claim 13, It is characterized in that The encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include: Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are both provided by the platform center; Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified; The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
15. The device for establishing a data transmission channel according to claim 14, It is characterized in that The encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
16. The device for establishing a data transmission channel according to claim 14, It is characterized in that The expected measurement value includes a measurement value confirmed by at least the platform center and the data server.
17. The device for establishing a data transmission channel according to claim 16, It is characterized in that The metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, and the metric values to be verified of the security module of the security module provided by the data server, and the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, and the expected metric values of the security module.
18. The device for establishing a data transmission channel according to claim 17, It is characterized in that The security module includes: a network monitoring module, a network service module and an input / output monitoring module.
19. The device for establishing a data transmission channel according to claim 17, It is characterized in that The to-be-verified metric values also include the to-be-verified metric values of the platform modules of the platform configuration module provided by the platform center, and the expected metric values also include the expected metric values of the platform modules.
20. The device for establishing a data transmission channel according to claim 17, It is characterized in that The metric values to be verified also include the model metric values to be verified of the algorithm model, and the expected metric values also include the model expected metric values. The expected metric values include metric values confirmed by the platform center, the data server and the algorithm model provider.
21. A device for establishing a data transmission channel, It is characterized in that Applicable to encrypted virtual machines, including: An encrypted virtual machine sending unit, adapted to send a signature file signed by a security processor using a chip private key, wherein the signature file includes a virtual machine public key of the encrypted virtual machine and each to-be-verified metric value of the encrypted virtual machine; The encrypted virtual machine receiving unit is suitable for receiving an encrypted data transmission key obtained by encrypting a data transmission key with the virtual machine public key, and decrypting the encrypted data transmission key with a virtual machine private key matching the virtual machine public key to obtain the data transmission key, and establish the data transmission channel, wherein the data transmission key is generated by the data server when the signature file is verified by the chip public key matching the chip private key, and the metric value to be verified is verified to be consistent with the pre-stored expected metric value corresponding to the metric value to be verified.
22. The device for establishing a data transmission channel according to claim 21, It is characterized in that The encrypted virtual machine is started by a physical host, and the physical host is allocated to the encrypted virtual machine by a platform center of the encrypted virtual machine. The steps of starting the encrypted virtual machine include: Obtaining a boot program and an encrypted virtual machine image of the encrypted virtual machine, wherein the boot program and the encrypted virtual machine image are provided by the platform center; Sending the boot program to the security processor so that the security processor measures the boot program to obtain a boot program measurement value to be verified; The boot program verification metric value sent back by the security processor is obtained, and the encrypted virtual machine is started according to the encrypted virtual machine image and the boot program.
23. The device for establishing a data transmission channel as claimed in claim 22, It is characterized in that The encrypted virtual machine image includes a platform configuration module, a security module and an algorithm model, and the platform configuration module, the security module and the algorithm model are all reviewed by three parties: the platform center, the data server and the algorithm model provider for providing the algorithm model.
24. The device for establishing a data transmission channel as claimed in claim 23, It is characterized in that The metric values to be verified include the metric values to be verified of the boot program, the metric values to be verified of the virtual machine image, the metric values to be verified of the security module of the security module provided by the data server, the metric values to be verified of the platform module of the platform configuration module provided by the platform center, and the model metric values to be verified of the algorithm model; the expected metric values include the expected metric values of the boot program, the expected metric values of the virtual machine image, the expected metric values of the security module, the expected metric values of the platform module, and the expected metric values of the model; the expected metric values include the metric values confirmed by the platform center, the data server, and the algorithm model provider.
Citation Information
Patent Citations
Virtual-dedicated-channel-based establishment method for high-credibility mobile security communication channel
CN102547688A
Method, system and device for ensuring mirror image integrity of virtual machine
CN111625871A