Hardware and Software Adaptive Cooperative Query Execution Method Based on Encrypted Database

By introducing software and hard adaptive collaborative query methods into the dense database, the execution method of UDF is dynamically determined, and combined with trusted hardware, the problem of inefficient query of pure software encryption databases is solved, and efficient encrypted data query is achieved.

CN115203235BActive Publication Date: 2025-07-01XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210834480.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-14
Publication Date
2025-07-01
Estimated Expiration
2042-07-14

AI Technical Summary

Technical Problem

In the prior art, the query efficiency of pure software cryptocurrency databases is inefficient, and encrypted databases based on trusted hardware face hardware limitations, such as small memory space, which makes it difficult to effectively solve the efficiency problem of encrypted data query in cloud database systems.

Method used

A software and hardware adaptive collaborative query method for dense state databases is proposed. Through a dynamic decision-making mechanism, the execution mode of user-defined functions (UDF) is dynamically determined as software execution or hardware execution, and combined with trusted hardware to improve query efficiency.

Benefits of technology

It realizes efficient query execution of encrypted data, significantly improves the overall computing query efficiency of the dense database system, and is applicable to current mainstream database systems and trusted hardware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115203235B_ABST
    Figure CN115203235B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for adaptively collaborative query execution based on a confidential database, mainly solving the problem of low query efficiency in a pure software confidential database in the prior art. The implementation steps are as follows: 1) The server adaptively allocates software or hardware execution methods for queries involving UDFs according to a static software-hardware collaborative mechanism; 2) Obtain the statistical results of UDF execution time data; 3) Construct an enclave page cache detector; 4) Use the time data, detector, and decision maker to construct a dynamic software-hardware collaborative mechanism, and adaptively execute queries involving UDFs to obtain ciphertext query results; 6) Return the ciphertext calculation results of UDFs. The present invention can organically combine a confidential data system implemented by pure software and a trusted hardware by using a dynamic decision-making mechanism, can dynamically select the specific execution method for each query calculation, efficiently solve the problem of composite expressions carried in queries, and at the same time speed up queries with the help of trusted hardware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and further relates to encrypted data query. Specifically, it is a software-hardware adaptive collaborative query method for an encrypted database, which can be used to efficiently query encrypted data by dynamically combining trusted hardware in an encrypted database. Background Art

[0002] In recent years, with the wide use of related technologies such as cloud computing in the industrial community, the privacy protection problem of data in cloud database systems has become a major research hotspot. Since encrypted data may lose its original characteristics, such as length, format, etc., there are many restrictions on performing SQL queries on encrypted data. In order to achieve SQL queries on encrypted data, various software- and hardware-based encryption solutions have emerged in recent years.

[0003] Cryptographic solutions, that is, pure software solutions, meet the requirements related to ciphertext queries by designing special encryption algorithms. For example, the well-known homomorphic encryption HE (Homomorphic Encryption), symmetric additive homomorphic encryption SAHE (Symmetric Additive Homomorphic Encryption), and symmetric multiplicative homomorphic encryption SMHE (Symmetric Multiplicative Homomorphic Encryption) allow arithmetic calculations to be performed on encrypted data; for example, order-revealing encryption ORE (Order-Revealing Encryption), where the ciphertext contains the order characteristics of the plaintext and can be used for ciphertext range queries; the encryption scheme of the equal-value encryption scheme is deterministic, and each plaintext corresponds to a unique ciphertext. The above algorithms are introduced to classify and encrypt data, which is stored in the server-side database, and user-defined functions UDF (User Defined Functions) are used to provide a processing method for query operations on ciphertext data. The design of an encrypted database using homomorphic encryption will significantly reduce the calculation speed, especially operations related to homomorphic multiplication. Compared with multiplication on plaintext, its calculation efficiency will decrease by several orders of magnitude, which is unacceptable for online real-time data queries. At the same time, for scenarios where the query statement may contain complex expressions, the current database design does not provide a specific solution.

[0004] As an alternative to cryptography-based privacy protection technologies, the Trusted Execution Environment (TEE) achieves secure computing based on memory isolation through hardware-secured CPUs. It can perform privacy-protected computations while ensuring computational efficiency. For example, Instruction Set Extension (SGX) creates an isolated environment called an Enclave in memory to protect sensitive data and code of applications, safeguarding the confidentiality and integrity of users' critical code and data from malware attacks. The encrypted state database based on trusted hardware uses hardware methods to provide data security. For instance, EnclaveDB stores sensitive data (tables, indexes, and other metadata) in trusted memory to achieve strong security guarantees. The internal data of the trusted execution environment is naturally protected in terms of privacy and integrity, and can also provide richer functions and better performance, avoiding complex and function-limited cryptography scheme designs. Secure and trusted plaintext processing can be directly carried out within the trusted hardware. When using the trusted execution environment to implement the encrypted state database system, most assumptions do not apply to the current actual situation. For example, EnclaveDB assumes that the memory space of the Enclave Page Cache (EPC) is infinitely large, but the reality is the opposite. Moreover, the trusted execution environment itself has security risks, facing problems such as possible vulnerabilities in hardware and side-channel attacks. The use of trusted hardware inevitably introduces additional overheads, such as programs entering and leaving the Enclave and page swapping of data. Therefore, it is difficult for this design to have real applications.

[0005] Currently, pure software encrypted databases have low computational efficiency and cannot solve complex expressions, while encrypted databases based on trusted hardware face hardware limitations such as small memory space. Therefore, there is an urgent need for a more effective method for querying encrypted data in cloud database systems. Summary of the Invention

[0006] The purpose of the present invention is to address the deficiencies of the above-mentioned existing technologies by proposing a software-hardware adaptive collaborative query method for encrypted state databases to solve the problem of low query efficiency in pure software encrypted state databases. First, the user sends a plaintext SQL statement, which is rewritten into a ciphertext SQL statement by the client and then sent to the server. The server parses the ciphertext SQL statement and adaptively distributes the queries involving user-defined functions to software or hardware for execution, returning the ciphertext query result. After decryption by the client, the plaintext query result is returned to the user. The present invention organically combines the pure software-implemented encrypted state data system and trusted hardware using a dynamic decision-making mechanism, which can dynamically select the specific execution method for each query calculation, efficiently solve the problem of composite expressions carried in the query, and at the same time speed up the query with the help of trusted hardware.

[0007] The specific steps for the present invention to achieve the above object are as follows:

[0008] (1) The user sends a plaintext query statement to the client, and the client rewrites it into a ciphertext SQL statement and then sends it to the server; the server parses the ciphertext SQL statement and adaptively distributes the queries involving user-defined functions (UDFs) to software or hardware for execution according to the static software-hardware collaborative mechanism, and obtains the ciphertext query result; the static software-hardware collaborative mechanism is: when the server performs a range query on an encrypted column, all operations related to the order-preserving encryption (ORE) encrypted column are replaced with the use of trusted hardware to complete, and the column to be range-queryed is converted into an encrypted column encrypted by the block cipher algorithm AES and passed into the trusted hardware enclave. The trusted hardware decrypts the AES encrypted ciphertext, returns the corresponding execution result and records it;

[0009] (2) Use a data statistic to record the query execution time of the UDF and update the statistical information related to the UDF, that is, the average time ST of running in the software execution mode and the average time HT of running in the hardware execution mode, and obtain the UDF execution time data statistical result;

[0010] (3) Design different detection tasks for different trusted hardware to determine whether the current trusted hardware state can provide conditions superior to software execution for UDF calculation, construct an enclave page cache detector for detecting the page replacement situation of the secure memory space SGX, and use the detection result as part of the decision basis for the decision maker;

[0011] (4) Use the UDF execution time data, the enclave page cache detector, and the decision maker to construct a dynamic software-hardware collaborative mechanism on the basis of the static software-hardware collaborative mechanism; the implementation is as follows:

[0012] (4.1) Design a UDF distribution function and create a user-defined function (UDF) description report for this execution according to the parameter information;

[0013] (4.2) Use the decision maker to receive the UDF description report, make a decision in combination with the current trusted hardware state, and obtain the current optimal execution path. If the decision path is hardware execution, call the trusted hardware enclave to execute the UDF and obtain the result; otherwise, use software to execute the UDF to obtain the result; the specific steps are as follows:

[0014] (4.2.1) Read the current hardware configuration state. If the current state is not using the secure memory space SGX, return that the UDF execution mode is hardware execution and go to step (4.2.6); otherwise, continue with step (4.2.2);

[0015] (4.2.2) Determine whether the current UDF is configured for trusted hardware execution mode. If so, proceed to step (4.2.3); otherwise, return that the UDF execution mode is software execution and go to step (4.2.6).

[0016] (4.2.3) Determine whether the current software-hardware cooperation mode is a static mechanism. If so, execute according to the UDF calculation method determined by the static mechanism and go to step (4.2.6); otherwise, proceed to step (4.2.4).

[0017] (4.2.4) Detect whether the enclave page cache replacement flag EPCPaing is true. If so, return that the UDF calculation method is software execution and go to step (4.2.6); otherwise, proceed to step (4.2.5).

[0018] (4.2.5) Judge the hardware execution cost C TEE of the UDF soft whether it is less than the software execution cost C

[0019] (4.2.6) Report the current execution situation of the UDF. The data statistics recorder records the execution time corresponding to its execution mode and updates the UDF statistical information.

[0020] (4.3) According to the dynamic software-hardware cooperation mechanism, adaptively allocate the query involving the user-defined function UDF to software or hardware for execution to obtain the ciphertext query result.

[0021] (5) The server returns the ciphertext query result to the client, and the client decrypts it to obtain the plaintext query result.

[0022] (6) The client conveys the plaintext query result to the user to complete the encrypted database query task.

[0023] The present invention has the following advantages compared with the prior art:

[0024] Aiming at the efficiency problem existing in data encryption and operation in the fully encrypted database, the present invention combines trusted hardware and the encrypted database system. The proposed software-hardware dynamic decision method can dynamically determine the execution mode of the UDF according to the current state of the trusted hardware, realizing efficient query execution of encrypted data.

[0025] First, since the present invention designs and introduces a detector for approximately dynamically detecting the remaining margin function of the secure memory space SGX, it can support dynamic scheduling decisions during UDF calculation.

[0026] Second, since the present invention establishes a cost estimation model for software and hardware execution paths, the decision-making effect is more accurate, significantly improving the overall calculation and query efficiency of the encrypted database system.

[0027] Thirdly, the method of the present invention has strong portability and can be applied to current mainstream database systems and trusted hardware. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 It is a schematic diagram of the static software-hardware collaborative mechanism architecture in the present invention;

[0029] Figure 2 It is a schematic diagram of the dynamic software-hardware collaborative mechanism architecture in the present invention;

[0030] Figure 3 It is a schematic diagram of query execution interaction based on microbenchmarking in the present invention;

[0031] Figure 4 It is a flowchart of the implementation of the data statistic in the present invention;

[0032] Figure 5 It is a flowchart of the implementation of the enclave page cache detector in the present invention;

[0033] Figure 6 It is a flowchart of the implementation of dynamic software-hardware collaborative decision-making in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] The present invention will be further described below with reference to the accompanying drawings.

[0035] Embodiment 1: Referring to the attached Figure 1-6 , the software-hardware adaptive collaborative query execution method based on the encrypted database proposed by the present invention establishes a sensitive enclave page cache capacity detection mechanism through the combined use of a decision maker, a detector, and a data statistic, and uses the detection result for the decision of the execution path of the user-defined function UDF task, establishing a software-hardware adaptive dynamic decision mechanism for the UDF execution method; the specific implementation process is as follows:

[0036] Step 1. The user sends a plaintext query statement to the client, and the client rewrites it into an encrypted SQL statement and sends it to the server; the server parses the encrypted SQL statement and adaptively distributes the query involving the user-defined function UDF to software or hardware for execution according to the static software-hardware collaborative mechanism, and obtains the encrypted query result; the static software-hardware collaborative mechanism is: when the server performs a range query on the encrypted column, all operations related to the order-preserving encryption algorithm ORE encrypted column are replaced with the use of trusted hardware to complete, and the column to be subjected to the range query is converted into an encrypted column encrypted by the block symmetric encryption algorithm AES and passed into the trusted hardware enclave, and the trusted hardware decrypts the AES encrypted ciphertext, returns the corresponding execution result and records it;

[0037] Step 2. Use a data statistic to record the query execution time of the UDF and update the statistical information related to the UDF, that is, the average time ST of running in the software execution mode and the average time HT of running in the hardware execution mode, and obtain the data statistical result of the UDF execution time. The steps are as follows:

[0038] (2.1) Read the average time ST of software execution and the average time HT of hardware execution in the current record of the data statistic;

[0039] (2.2) Determine whether the execution mode of the current UDF is hardware or software. If it is hardware, continue to step (2.3); otherwise, go to step (2.6).

[0040] (2.3) Determine whether the current hardware execution time is greater than the average time HT of hardware operation. If it is, continue to step (2.4); otherwise, go to step (2.5).

[0041] (2.4) Set the EPCPaing flag to indicate that page replacement occurs in the EPC.

[0042] (2.5) Increment the hardware execution count of the current UDF by one, update the average hardware operation time HT, and execute step (2.7);

[0043] (2.6) Increment the software execution count of the current UDF by one and update the average software operation time ST;

[0044] (2.7) Obtain the data statistical result of the UDF execution time.

[0045] Here, in steps (2.5)-(2.6), the updated running time T' is obtained in the following manner:

[0046] T' = αT + (1 - α)t,

[0047] where T is the cumulative running time before this execution of the adopted execution mode, α is the update rate, and t is the execution time.

[0048] Step 3. Design different detection tasks for different trusted hardware to determine whether the current trusted hardware status can provide conditions superior to software execution for UDF calculation. Build an enclave page cache detector for detecting the page replacement situation of the secure memory space SGX, and use the detection result as part of the decision basis of the decision maker. The decision maker obtains the current running state of SGX in real time by calling the enclave page cache status detector, estimates the probability of page replacement occurring in the next UDF calculation, and the severity of the page replacement. The construction method of the enclave page cache detector is as follows:

[0049] (3.1) Denote the running times of the benchmark test when no page replacement occurs and when page replacement occurs as T1 and T2 respectively, and T1 ≤ T2; the execution time of the current benchmark test is t0, and t0 is distributed centered around T1 or T2; let α1 and α2 denote the first weight and the second weight respectively, and α1 < α2; in this embodiment, the first weight here is much smaller than the second weight.

[0050] (3.2) Determine whether t0 belongs to the T1 center or the T2 center. If it belongs to the T1 center, continue to step (3.3); otherwise, go to step (3.4).

[0051] (3.3) Cancel the global identifier EPCPaging for EPC page replacement and calculate the dynamic load with the first weight α1; go to step (3.5);

[0052] (3.4) Set the global identifier EPCPaging and calculate the dynamic load with the second weight α2;

[0053] (3.5) Update T1 and T2;

[0054] The updated running time T' is obtained in the following way:

[0055] T' = αT + (1 - α)t,

[0056] where T is the cumulative running time before this execution of the adopted execution method, α is the update rate, and t is the execution time.

[0057] Step 4. Use the UDF execution time data, enclave page cache detector, and decision maker to construct a dynamic software-hardware collaboration mechanism on the basis of the static software-hardware collaboration mechanism; the implementation is as follows:

[0058] (4.1) Design a UDF distribution function and create a user-defined function UDF description report for this execution according to the parameter information; the UDF distribution function is specifically expressed as follows:

[0059] UDF dispatch (UDFType, Ci he1 , Ci he2 , Ci aes1 , Ci aes2 , e),

[0060] where UDFType represents the type of UDF, and Ci he1 、Ci he2 are ciphertext 1 and ciphertext 2 of homomorphic encryption, which are used for encrypted state calculation in the soft execution mode, and Ci aes1 、Ci aes2For symmetric encryption ciphertext 1 and ciphertext 2, which are used for calculation in a hardware - executed manner, e represents the expected encrypted form of the calculation result.

[0061] (4.2) Use the decision - maker to receive the UDF description report, make a decision in combination with the current trusted hardware status to obtain the current optimal execution path. If the decision path is hardware execution, call the trusted hardware enclave Enclave to execute the UDF and obtain the result; otherwise, use software to execute the UDF to obtain the result. The specific steps are as follows:

[0062] (4.2.1) Read the current hardware configuration status. If the current status is not using the secure memory space SGX, return that the UDF execution method is hardware execution and go to step (4.2.6); otherwise, continue with step (4.2.2);

[0063] (4.2.2) Determine whether the current UDF is configured for the trusted hardware execution mode. If so, continue with step (4.2.3); otherwise, return that the UDF execution method is software execution and go to step (4.2.6)

[0064] (4.2.3) Determine whether the current software - hardware cooperation mode is a static mechanism. If so, execute according to the UDF calculation method determined by the static mechanism and go to step (4.2.6); otherwise, continue with step (4.2.4)

[0065] (4.2.4) Detect whether the enclave page cache replacement flag EPCPaing is true. If so, return that the UDF calculation method is software execution and go to step (4.2.6); otherwise, continue with step (4.2.5);

[0066] (4.2.5) Judge the hardware execution cost C TEE of the UDF whether it is less than the software execution cost C soft . If so, return that the UDF calculation method is hardware execution; otherwise, it is software execution;

[0067] Here, the hardware execution cost C TEE and the software execution cost C soft of the UDF are calculated as follows:

[0068] C soft = C calc-software + C decide ,

[0069] C TEE = C fixed + C calc-TEE + C runtime + C decide ,

[0070] Among them, C calc-softwareThe computing cost C when the UDF adopts the software execution mode calc-TEE The computing cost C when the UDF adopts the trusted hardware execution mode decide The overhead caused by the decision-making itself when the decision-maker makes a decision, C fixed The startup cost C of the trusted execution environment runtime Is the additional load overhead of the trusted hardware during operation

[0071] (4.2.6) Report the current execution situation of the UDF. The data statistician records the execution time corresponding to its execution mode and updates the UDF statistical information

[0072] (4.3) According to the dynamic software-hardware cooperation mechanism, the queries involving the user-defined function UDF are adaptively assigned to software or hardware for execution to obtain the ciphertext query result

[0073] Step 5. The server returns the ciphertext query result to the client, and the client decrypts it to obtain the plaintext query result

[0074] Step 6. The client conveys the plaintext query result to the user to complete the encrypted database query task

[0075] Embodiment 2: Refer to the appendix Figure 1 , the overall implementation steps of this embodiment are the same as those of Embodiment 1, and only the static cooperation mechanism of Step 1 is further described as follows

[0076] The user sends a plaintext SQL statement, the client rewrites it into a ciphertext SQL statement and sends it to the server. The server parses the ciphertext SQL statement, adaptively assigns the queries involving the user-defined function to software or hardware for execution, returns the ciphertext query result, and the client decrypts it and returns the plaintext query result to the user

[0077] Currently, most of the UDFs in the encrypted database design are memory-consuming calculations. The encrypted UDF calculation has too much overhead compared with the plaintext. For a database that contains multiple encryption algorithms at the same time, the present invention replaces the user-defined function operations of the encryption scheme with relatively large time or space overheads with the use of trusted hardware. That is, before the UDF is executed, a corresponding calculation method, software execution or hardware execution, is configured for each encryption operation. When processing a query, when a certain specific UDF function is encountered, it is transferred to the corresponding calculation library for solution. Specifically, when the execution mode of the UDF involving a certain encrypted column is specified as hardware execution, the AES encrypted ciphertext of the corresponding data can be passed into the trusted hardware and decrypted in the trusted hardware to implement confidential operations. The static software-hardware cooperative encrypted database system is as Figure 1As shown in the figure, the data encryption part introduces four encryption algorithms: AES, ORE, SMHE, and SAHE, and the trusted hardware is SGX. Specifically, it includes the following steps:

[0078] 1) Staticly allocate specific execution methods for all UDFs in the database, either software execution or hardware execution. For example, when performing a range query on an encrypted column, considering that the ORE encrypted column has a greater overhead in terms of space and time than other encrypted columns, all operations related to the ORE column are replaced with the use of trusted hardware to solve, reducing the ORE encrypted column. The column that needs to perform a range query is converted into an AES encrypted column and passed into the trusted hardware. For example, the default calculation method of ore_le (AES encrypted ciphertext 1, AES encrypted ciphertext 2, calculation result) is set to hardware execution.

[0079] 2) After the server receives the encrypted SQL statement, it judges the calculation method of the UDF function involved therein. For example, when receiving a user-defined function involving the ORE column, such as size relationship comparison, finding the maximum value, etc., it judges that its calculation method is hardware execution, and passes the UDF and parameters into the Enclave for solution. For example, ore_le (AES encrypted ciphertext 1, AES encrypted ciphertext 2, calculation result), decrypt the AES encrypted ciphertext in the Enclave, judge whether the AES decrypted ciphertext 1 is less than or equal to the AES decrypted ciphertext 2, and return the corresponding result;

[0080] 3) After the server calls the UDF, it obtains the execution result, returns the encrypted query result, and the client decrypts it and feeds back the final plaintext query result to the user.

[0081] The above-mentioned solution of statically transmitting a certain encrypted column to the trusted hardware for solution is a static cooperation mechanism. In implementation, it is determined by pre-configured options whether a certain encrypted column or UDF is executed in SGX. This simple way of replacing a certain encrypted column to reduce the space-time overhead can solve the problem of low computing efficiency in the original pure software system while ensuring security, and improve the overall performance of the encrypted database system.

[0082] Example 3: The overall implementation steps of this example are the same as those of Example 1. The data statistics unit, enclave page cache status detector, and decision unit involved therein are further described in detail as follows:

[0083] The execution modes of all UDFs in the database can all be set to the hardware execution mode. Depending on the different internal states of the trusted hardware, that is, the occupancy rate of the secure memory area of SGX, the execution efficiency of UDFs will have different performances. In the trusted hardware SGX, when the data in the secure memory area is full, new memory requirements will cause page replacement, thus affecting the efficiency. As the occupancy of the secure area memory increases, the time taken for the same operation executed in the trusted hardware will gradually increase, while the operations executed externally remain stable. When the secure area memory is exhausted, the overhead of continuing to perform ciphertext calculations using the trusted hardware will be higher than that without using the trusted hardware. In this case, using the trusted hardware or having all calculations done by SGX will reduce the query efficiency.

[0084] Based on the above-mentioned software-hardware collaborative computing query execution scheme designed for the encrypted database in the present invention, a dynamic software-hardware collaborative mechanism is constructed, and its architecture is as Figure 2 shown. A data statistic, an EPC detector, and a dynamic decision maker are introduced to implement the software-hardware adaptive collaborative computing scheme in the encrypted database query.

[0085] 1. Data statistic

[0086] The data statistic records the execution time of UDFs and updates the statistical information related to UDFs, namely the average hardware execution time and the average software execution time. The specific steps are as follows:

[0087] 1.1) Read the average time AvgSoftwareTime and AvgHardwareTime of software and hardware running in the current record;

[0088] 1.2) Determine whether the execution mode of the current UDF is hardware or software. If it is hardware, go to step 1.3); otherwise, go to step 1.6)

[0089] 1.3) Determine whether the current hardware execution time is greater than the average hardware execution time AvgHardwareTime. If it is, go to step 1.4); otherwise, go to step 1.5)

[0090] 1.4) Set the EPCPaing page replacement flag to indicate that EPC is undergoing page replacement

[0091] 1.5) Increment the hardware execution count of the current UDF and update the average hardware execution time AvgHardwareTime,

[0092] 1.6) Increment the software execution count of the current UDF and update the average software execution time AvgSoftwareTime,

[0093] Among them, the update method of the average execution time T of software and hardware is: T = αT + (1 - α)t, where T is the cumulative running time, α is the update rate, and t is the execution time of this UDF. According to this update mode, the sensitivity of the final cumulative time T to the execution time of a single UDF is affected by α, and α is adjusted to control the update rate.

[0094] 2. Enclave Page Cache Status Detector

[0095] Considering that page replacement will occur when the remaining capacity of the secure memory is insufficient, which will affect the execution efficiency of the calculation, the running time of the calculation tasks executed in the current SGX can indirectly reflect the status of the remaining capacity of the current EPC. The present invention deploys a periodically running microbenchmark to approximately detect the SGX page replacement situation, and then provides specific decision-making basis for the decision maker based on this. Specifically, a timer is started with the system startup in a new thread and a task is triggered once at a certain determined time. This task is executed in the trusted hardware enclave, and the execution time of this task is recorded.

[0096] The detection task of trusted hardware is to provide accurate runtime overhead of trusted hardware for the cost estimation model. Different detection tasks will be designed for different trusted hardware to determine whether the current trusted hardware state can provide conditions superior to software execution for UDF calculation. For example, for SGX, its main computing limitation comes from insufficient secure memory space. When this computing resource is exhausted, page replacement will occur in subsequent calculations in secure memory, and page replacement will cause serious additional computing overhead, thus reducing the overall system performance. Since the computing limitation condition of SGX is the size of secure memory, the main objective of the detection task of the present invention for SGX is to be able to accurately and timely reflect the remaining capacity of secure memory, so as to estimate the probability of page replacement occurring in the next UDF calculation and the severity of page replacement. For a single UDF calculation task, even when the secure memory is insufficient, there is a certain probability that each instruction accessing data will cause page replacement, but this probability is greater than in the normal state. Whether the severity of page replacement can be accurately predicted when the secure memory is insufficient is also an important reference basis for the dynamic decision-making effect. For the selection of benchmark test tasks, users can fill in different test tasks according to the different performances of the SGX platform to obtain better detection effects. A main requirement for benchmark test tasks is that the data access in the task test should be random enough to resist the caching effect of the page replacement algorithm, so that the task test can cause enough page faults, and thus show obvious discrimination in running time. Generally speaking, the present invention hopes that in the best case, each instruction accessing data in the benchmark test task can cause a page fault interrupt. However, in fact, if the data access in the test task is not random enough and there are more local accesses, the page fault interrupts will be fewer, and thus it cannot accurately reflect whether page replacement is currently occurring. After many experiments, the present invention adopts the method of performing quicksort and then binary search in secure memory as the benchmark test task.

[0097] Among them, the selection of the benchmark test task needs to ensure that the memory access is random enough, or try to ensure that each memory access is not on the same page, so as to ensure the sensitivity of the test to page replacement. For the selection of benchmark test tasks, users can fill in different test tasks according to the different performances of the SGX platform, such as quicksort, binary search, etc., to provide relatively accurate real-time state information of secure memory for the decision-making mechanism. Design the size of the secure memory page to be applied for the benchmark test according to the size of the UDF task volume. After determining the benchmark test task, assume that n * 4KB of memory is applied, and after m random accesses, record the execution time of this task. After multiple rounds of execution, a series of execution time records will be obtained.

[0098] The specific steps of the enclave page cache status detector are as follows:

[0099] 2.1) Assume that the execution time of the benchmark task is t0. When there is no page replacement, the running time of this task is recorded as T1. When page replacement occurs, the task running time is recorded as T2, and it always holds that T1 ≤ T2. The distribution of t0 is centered around T1 and T2;

[0100] 2.2) Trigger the benchmark task in the trusted hardware at regular intervals. For the execution time t of each benchmark, determine whether t belongs to the center of T1 or T2. If t belongs to the center of T1, go to step 3; otherwise, go to step 2.4);

[0101] 2.3) Cancel the global identifier EPCPaging for EPC page replacement, and calculate the dynamic load cost with a lower weight;

[0102] 2.4) Set EPCPaging, and calculate the dynamic load cost with a higher weight;

[0103] 2.5) Update T1 and T2 in the same way as the average execution time T of software and hardware.

[0104] Among them, EPCPaging is mainly used to indicate that the actual execution effect of the UDF in the trusted hardware is not ideal. Setting this identifier can notify other UDF tasks that there is page replacement in the current trusted hardware, and continue to use the hardware execution method to reduce efficiency.

[0105] 3. Decider

[0106] The decider calls the enclave page cache status detector to obtain the current running state of SGX in real time, that is, it can obtain the remaining capacity of the memory safe area in real time to support the operation of the decision-making mechanism.

[0107] 3.1) Design the UDF distribution function UDF dispatch (UDFType, Ci he1 , Ci he2 , Ci aes1 , Ci aes2 , e), where UDFType is the type of UDF, and Ci he1 , Ci he2 are the ciphertext 1 and ciphertext 2 of homomorphic encryption, which are used for encrypted state calculation in the soft execution mode. Ci aes1 , Ci aes2 are the ciphertext 1 and ciphertext 2 of symmetric encryption, which are used for calculation in the hardware execution mode. e is the expected encryption form of the calculation result. The UDF distribution function creates a UDF description report for this execution according to the parameter information;

[0108] 3.2) Receive the query request, create a description report of the UDF according to the ciphertext operations involved in the query, and the decision maker receives the UDF description report;

[0109] 3.3) Read the current hardware configuration status. If the current status is not using SGX, return that the UDF execution mode is hardware execution, and go to step 3.8);

[0110] 3.4) Determine whether the current software-hardware cooperation mode is a static mechanism. If so, determine whether the current UDF is configured for a trusted hardware execution mode, and go to step 3.5); otherwise, go to step 3.6);

[0111] 3.5) Determine whether the current UDF is configured for a trusted hardware execution mode. If so, return that the UDF execution mode is hardware execution; otherwise, return that the UDF execution mode is software execution, and go to step 3.8);

[0112] 3.6) Detect whether the EPCPaing flag is true. If so, return that the UDF calculation mode is software execution, and go to step 3.9);

[0113] 3.7) Determine whether the hardware execution cost of the UDF is less than the software execution cost. If so, return that the UDF calculation mode is hardware execution; otherwise, it is software execution;

[0114] 3.8) Report the current execution situation of the UDF. The data statistician records the execution time corresponding to its execution mode and updates the UDF statistical information;

[0115] Among them, the calculation methods of the software and hardware execution costs in step 3.8) are as follows:

[0116] Software execution cost: C soft = C calc-software + C decide

[0117] Hardware execution cost: C TEE = C fixed + C calc-TEE + C runtime + C decide

[0118] C calc-software is the calculation cost when the UDF adopts the software execution mode, C calc-TEE is the calculation cost when the UDF adopts the trusted hardware execution mode, C decide is the overhead brought by the decision itself when the decision maker makes a decision, C fixed is the startup cost of the trusted execution environment, C runtimeIt is the additional load overhead of trusted hardware during runtime, which mainly manifests as the additional computational cost during page replacement in SGX. Its value changes continuously with the severity of page replacement and is positively correlated with the time t obtained from the benchmark test.

[0119] The parts not detailed in the present invention belong to the common general knowledge of those skilled in the art.

[0120] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Obviously, for professionals in the field, after understanding the content and principle of the present invention, various modifications and changes in form and details may be made without departing from the principle and structure of the present invention. However, these modifications and changes based on the idea of the present invention are still within the scope of protection of the claims of the present invention.

Claims

1. A method for executing a soft-hard adaptive collaborative query based on an encrypted database, characterized in that A sensitive enclave page cache capacity detection mechanism is established by the combined use of a decision maker, a detector, and a data statistician, and the detection results are used for the decision-making of the execution path of the user-defined function UDF task, establishing a software-hardware adaptive dynamic decision-making mechanism for the UDF execution method; specifically including the following steps: (1) The user sends a plaintext query statement to the client, and the client rewrites it into a ciphertext SQL statement and sends it to the server; the server parses the ciphertext SQL statement and adaptively distributes the query involving the user-defined function UDF to software or hardware for execution according to the static software-hardware collaborative mechanism, and obtains the ciphertext query result; the static software-hardware collaborative mechanism is: when the server performs a range query on the encrypted column, all operations related to the order-preserving encryption algorithm ORE encrypted column are replaced with the use of trusted hardware to complete, and the column that needs to perform a range query is converted into an encrypted column encrypted by the block cipher algorithm AES and passed into the trusted hardware enclave, and the trusted hardware decrypts the AES encrypted ciphertext, returns the corresponding execution result and records it; (2) Use the data statistician to record the query execution time of the UDF and update the statistical information related to the UDF, that is, the average time ST of the software execution method and the average time HT of the hardware execution method, and obtain the data statistical result of the UDF execution time; (3) Design different detection tasks for different trusted hardware to determine whether the current trusted hardware state can provide conditions superior to software execution for UDF calculation, construct an enclave page cache detector for detecting the page replacement situation of the secure memory space SGX, and use the detection result as part of the decision-making basis for the decision maker; (4) Use the UDF execution time data, the enclave page cache detector, and the decision maker to construct a dynamic software-hardware collaborative mechanism on the basis of the static software-hardware collaborative mechanism; the implementation is as follows: (4.1) Design a UDF distribution function and create a user-defined function UDF description report for this execution according to the parameter information; (4.2) Use the decision maker to receive the UDF description report, make a decision in combination with the current trusted hardware state, and obtain the current optimal execution path. If the decision path is hardware execution, call the trusted hardware enclave to execute the UDF and obtain the result, otherwise use software to execute the UDF to obtain the result; the specific steps are as follows: (4.2.1) Read the current hardware configuration state. If the current state is not using the secure memory space SGX, return that the UDF execution method is hardware execution, and go to step (4.2.6); otherwise continue with step (4.2.2); (4.2.2) Judge whether the current UDF is configured as the trusted hardware execution method. If so, continue with step (4.2.3), otherwise return that the UDF execution method is software execution and go to step (4.2.6); (4.2.3) Judge whether the current software-hardware collaborative method is a static mechanism. If so, execute according to the UDF calculation method determined by the static mechanism, and go to step (4.2.6); otherwise continue with step (4.2.4); (4.2.4) Check whether the enclave page cache replacement flag EPCPaing is true. If it is true, return that the UDF calculation method is software execution and go to step (4.2.6); otherwise, continue with step (4.2.5). (4.2.5) Determine whether the hardware execution cost C of the UDF TEE is less than the software execution cost C soft , if so, return that the UDF calculation method is hardware execution, otherwise it is software execution; (4.2.6) Report the current execution status of the UDF. The data statistician records the execution time corresponding to its execution method and updates the UDF statistical information. (4.3) According to the dynamic software-hardware cooperation mechanism, adaptively allocate the query involving the user-defined function UDF to software or hardware for execution, and obtain the ciphertext query result. (5) The server returns the ciphertext query result to the client, and the client decrypts it to obtain the plaintext query result. (6) The client conveys the plaintext query result to the user to complete the encrypted database query task.

2. The method according to claim 1, characterized in that: The UDF execution time data statistic result in step (2) is obtained according to the following steps: (2.1) Read the average time ST of software execution and the average time HT of hardware execution in the current record of the data statistician. (2.2) Determine whether the execution method of the current UDF is hardware or software. If it is hardware, continue with step (2.3); otherwise, go to step (2.6). (2.3) Determine whether the current hardware execution time is greater than the average time HT of hardware operation. If it is, continue with step (2.4); otherwise, go to step (2.5). (2.4) Set the EPCPaing flag to indicate that EPC is undergoing page replacement. (2.5) Increment the hardware execution count of the current UDF by one, update the average hardware operation time HT, and execute step (2.7). (2.6) Increment the software execution count of the current UDF by one and update the average software operation time ST. (2.7) Obtain the UDF execution time data statistic result.

3. The method according to claim 1, wherein: The enclave page cache detector in step (3) is constructed as follows: (3.1) Denote the running times of the benchmark test when there is no page replacement and when there is page replacement as T1 and T2 respectively, and T1 ≤ T2; the execution time of the current benchmark test is t0, and t0 is centered around T1 or T2; let α1 and α2 represent the first weight and the second weight respectively, and α1 < α2. (3.2) Determine whether t0 belongs to the center of T1 or T2. If it belongs to the center of T1, continue with step (3.3); otherwise, go to step (3.4). (3.3) Cancel the global identifier EPCPaging for EPC page replacement and calculate the dynamic load with the first weight α1. Go to step (3.5). (3.4) Set the global identifier EPCPaging and calculate the dynamic load with the second weight α2. (3.5) Update T1 and T2.

4. The method according to claim 2 or 3, characterized in that: The above updates are all obtained in the following way to get the updated running time T': T' = αT + (1 - α)t, where T is the cumulative running time before this execution of the adopted execution method, α is the update rate, and t is the execution time.

5. The method according to claim 1, characterized in that: The decision maker in step (3) obtains the current running status of the current SGX in real time by calling the enclave page cache status detector, estimates the probability of page replacement occurring in the next UDF calculation, and the severity of the page replacement.

6. The method according to claim 1, wherein: Design the UDF distribution function in step (4.1) as follows: UDF dispatch (UDFType,Ci he1 ,Ci he2 ,Ci aes1 ,Ci aes2 ,e) Among them, UDFType represents the type of UDF, Ci he1 and Ci he2 are ciphertext 1 and ciphertext 2 of homomorphic encryption, which are used for encrypted computing in the soft execution mode. Ci aes1 and Ci aes2 are ciphertext 1 and ciphertext 2 of symmetric encryption, which are used for computing in the hardware execution mode. e represents the expected encryption form of the computing result.

7. The method according to claim 1, characterized in that: The hardware execution cost C of the UDF in step (4.2.5) TEE and the software execution cost C soft are calculated as follows: C soft = C calc-software + C decide , C TEE = C fixed + C calc-TEE + C runtime + C decide , Among them, C calc-software is the computational cost when the UDF is executed in software, and C calc-TEE is the computational cost when the UDF is executed in trusted hardware. C decide is the overhead incurred by the decision itself when the decision maker makes a decision, and C fixed is the startup cost of the trusted execution environment. C runtime is the additional load overhead of the trusted hardware during runtime.

Citation Information

Patent Citations

  • TEE encrypted database interface attack-oriented defense method and system

    CN113609492A

  • Ciphertext query calculation method for encrypted database

    CN113742362A