A secure computing method and device based on SGX technology

By performing identification interception and calculation in enclaves generated by SGX technology, the problem of insufficient security of multi-party computing in the prior art is solved, and higher security and data protection effects are achieved.

CN115396091BActive Publication Date: 2025-05-13太保科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211025393.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-25
Publication Date
2025-05-13
Estimated Expiration
2042-08-25

AI Technical Summary

Technical Problem

The prior art has problems of information leakage and poor security in multi-party computing, especially in a trusted execution environment built by virtualization technology. The detailed data of the calculation applicant is easily directly accessed by the computing party, resulting in insufficient security.

Method used

The security calculation method based on SGX technology is adopted to ensure that the data and calculation rules are processed in a completely isolated security environment by performing identification and interception in the enclaves generated by SGX technology, and interference from the operating system or privileged software is avoided.

Benefits of technology

It improves the security of multi-party computing, prevents information leakage and malicious attacks, and ensures the security of data and calculation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396091B_ABST
    Figure CN115396091B_ABST
Patent Text Reader

Abstract

The present application discloses a secure computing method and device based on SGX technology, the method comprising: receiving a computing request sent by a computing applicant including a computing rule provided by the computing applicant and a first identification set; using the received first identification set and the second identification set stored by itself to perform identification intersection in an enclave generated based on SGX technology; using the intersection result to find detailed data; using the detailed data and the computing rule to complete the computing in the enclave generated based on SGX technology; and returning the computing result to the computing applicant. The present application can use the identification set generated based on SGX technology to complete the identification intersection and computing process in the enclave generated based on SGX technology, making multi-party computing more secure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of secure computing technology, and in particular to a secure computing method and device based on SGX technology. Background Art

[0002] With the continuous development of science and technology, malware and network attacks emerge in an endless stream, and secure computing has become an important issue that needs to be solved. Secure computing, the full name of which is secure multi-party computing, refers to the implementation of multi-party computing under the premise of protecting data security. Multi-party computing refers to a computing method in which multiple participants put their respective data together, perform certain calculations on this large data set, and obtain the final calculation results. In order to ensure the security of multi-party computing, the existing technology uses virtualization technology to build a trusted execution environment, and the executable environment is generated by the privileged software hypervisor after allocating system resources. The calculation rules provided by the computing applicant and the data required for the calculation are sent to the trusted execution environment built by the computing party based on virtualization technology, and multi-party computing is performed in the trusted execution environment to ensure the security of multi-party computing. Secure computing performed in this way often leaks information and has poor security. Summary of the invention

[0003] Based on the above problems, the present application provides a secure computing method and device based on SGX technology to improve the security of multi-party computing.

[0004] This application discloses a secure computing method based on SGX technology:

[0005] Receiving a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant;

[0006] Performing an identification intersection using the received first identification set and the second identification set stored by itself, wherein the identification intersection is completed in an enclave generated based on the SGX technology;

[0007] Use the intersection result to find the detailed data;

[0008] The detailed data and the calculation rules are used to complete the calculation in the enclave generated based on the SGX technology.

[0009] Optionally, the first identifier set includes:

[0010] The identity identifier of the detailed data used in the calculation is generated by a hash algorithm and symmetric encryption based on the detailed data used in the calculation and a key generated based on the SGX technology.

[0011] Optionally, the second identifier set includes:

[0012] The identity identifier corresponding to the detailed data is generated by a hash algorithm and symmetric encryption based on the detailed data and a key generated based on the SGX technology.

[0013] Optionally, the secure computing method based on SGX technology further includes:

[0014] If the detailed data cannot be found using the intersection result, it proves that there is a database collision.

[0015] Optionally, the secure computing method based on SGX technology further includes:

[0016] Sending a detailed data verification request to the calculation applicant;

[0017] Receive the detailed data identity identifier returned by the computing applicant;

[0018] The detailed data identity is used to perform detailed data verification, and the data verification is completed in the enclave generated based on the SGX technology.

[0019] Optionally, the secure computing method based on SGX technology further includes:

[0020] Encrypting the calculation result in the enclave generated based on the SGX technology, wherein the encryption key used for encrypting the calculation result is obtained from the first identifier set;

[0021] The encrypted calculation result is returned to the calculation applicant.

[0022] The present application also provides a secure computing device based on SGX technology, the device comprising:

[0023] A receiving module, configured to receive a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant;

[0024] A set intersection module, used for performing an identification intersection between the received first identification set and the second identification set stored in the module;

[0025] A detailed data search module, used to search for detailed data, wherein the detailed data is found by using the result of the intersection of the identifiers;

[0026] A calculation module, used for calculating and obtaining a calculation result, wherein the calculation uses the found detailed data and the calculation rule;

[0027] The return module is used to return the calculation result.

[0028] Optionally, the secure computing device based on SGX technology also includes:

[0029] The detailed data identity generation module uses the key generated based on SGX technology to generate the identity of the detailed data used in the calculation through hash algorithm and symmetric encryption.

[0030] Optionally, the secure computing device based on SGX technology further includes:

[0031] The judgment module is used to determine whether the detailed data can be found using the intersection result. If not, it proves that there is a database collision.

[0032] Optionally, the secure computing device based on SGX technology further includes:

[0033] A verification information request module, used to send a detailed data verification request to the calculation applicant;

[0034] A verification information receiving module, used to receive the detailed data identity identifier returned by the computing applicant;

[0035] The verification module uses the detailed data identity identifier to verify the detailed data.

[0036] Optionally, the secure computing device based on SGX technology further includes:

[0037] The calculation result encryption module is used to encrypt the calculation result, and the calculation result is encrypted using the calculation result encryption key.

[0038] The present application also provides an electronic device, including a memory and a processor, wherein:

[0039] The memory is used to store the computer program;

[0040] The processor is used to execute the computer program to implement the above-mentioned secure computing method based on SGX technology.

[0041] The present application also provides a computer-readable storage medium for storing a computer program, wherein the computer program implements the above-mentioned secure computing method based on SGX technology when executed by a processor.

[0042] Compared with the prior art, this application has the following beneficial effects:

[0043] The present application performs secure computing based on SGX technology. The computing party receives the computing rules and the first identification set sent by the computing applicant, and uses the received first identification set and the second identification set stored by itself to perform identification intersection in the enclave generated by the SGX technology. The computing party uses the intersection result to find the detailed data pre-stored by the computing applicant. The computing party uses the detailed data required for the calculation and the computing rules provided by the computing applicant to complete the calculation in the enclave generated by the SGX technology, and returns the calculation result to the computing applicant after the calculation is completed. In the method provided in the present application, an enclave is generated based on the SGX technology. The enclave is a completely isolated security environment composed of hardware. During the generation of the enclave, it is necessary to determine whether the device is a real physical device, not a virtual device simulated by software. After the enclave is generated, even the operating system or privileged software cannot affect the code and data in the enclave. The data is stored in the enclave generated based on the SGX technology. The computing applicant sends the required operation rules and the identity of the required detailed data to the computing party. The computing party completes the identification intersection process in the enclave. After the computing party finds the detailed data according to the result of the identification intersection, it completes the multi-party computing in the enclave. Compared with the prior art of performing multi-party computing in a secure environment allocated by a software hypervisor, the present application improves the security of multi-party computing. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0045] Figure 1 A flowchart of a secure computing method based on SGX technology provided in this application;

[0046] Figure 2 A flowchart of another secure computing method based on SGX technology provided by this application;

[0047] Figure 3 Another flow chart of a secure computing method based on SGX technology provided by this application;

[0048] Figure 4 A schematic diagram of the structure of a secure computing device based on SGX technology provided in this application. DETAILED DESCRIPTION

[0049] As described above, current secure computing uses virtualization software to allocate system resources to the computing party and allocate a secure environment, in which the decryption and computing processes are completed. Since the secure environment is allocated using virtualization software, secure computing performed in this way often leaks information and has poor security.

[0050] The inventor has found through research that the virtualization software used in the prior art is privileged software, which can directly access the security environment. The virtualization software itself may have vulnerabilities and is more susceptible to malicious attacks, resulting in poor security. If secure computing is completed based on the security environment allocated by the virtualization software, the computing party and the computing applicant need to jointly negotiate the encryption key to achieve the identification intersection, which directly exposes the detailed data of the computing applicant to the computing party, resulting in poor security.

[0051] In order to solve the above problems, a secure computing method and device based on SGX technology is provided in an embodiment of the present application. The computing party receives a computing request sent by a computing applicant, uses the first identification set in the computing request and the second identification set stored by itself to complete the identification intersection in the enclave generated based on SGX technology, uses the identification intersection result to find the detailed data, and completes the calculation in the enclave generated based on SGX technology using the calculation rules in the first identification set. The present application generates detailed data identification based on SGX technology, and completes the identification intersection and calculation process in the enclave generated based on SGX technology. In this way, the security risks of identification intersection by jointly negotiating a key are avoided, privileged software does not exist, and the security of multi-party computing is improved.

[0052] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0053] Figure 1 A flowchart of a secure computing method based on SGX technology provided in this application, the method may include the following steps:

[0054] S101: receiving a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant.

[0055] The calculation applicant may be one or more than one party, and the calculation rules may be provided by one of the calculation applicants or by multiple calculation applicants, all of which fall within the scope of protection of this application.

[0056] Among them, the first identification set includes the identity identification of the detailed data used for calculation, and the identity identification of the detailed data used for calculation is generated by hashing the detailed data used for calculation and the key generated based on SGX technology through symmetric encryption.

[0057] When the computing applicant inputs the detailed data into the computing party enclave, the computing party system interface used to create the enclave can be called to store the detailed data through the system interface. After the storage is completed, the computing applicant can measure the data in the enclave through the enclave measurement interface provided by the SGX hardware device. The measurement can obtain the hash value in the computing party enclave memory and the key generated based on the SGX technology. The computing party applicant first uses the measured hash value and the key generated based on the SGX technology to perform hash calculation on the detailed data identifier used in the calculation, and then symmetric encryption is performed on the hashed data to obtain the identity set of the detailed data used in the calculation. The identity set of the detailed data used in the calculation is put together with other data to form a first identification set and sent to the computing party. The other data may include a calculation result encryption key for encrypting the calculation result, and may also include an identity used to verify the identity of the computing applicant, and may also include other data, all of which belong to the scope of protection of this application.

[0058] The calculation rules in the calculation request may be sent directly, or may be sent after being encrypted, or may be in other forms, all of which fall within the scope of protection of this application.

[0059] S102: Performing identifier intersection using the received first identifier set and the second identifier set stored in the system, wherein the identifier intersection is completed in an enclave generated based on the SGX technology.

[0060] Among them, the second identification set includes the identity identification corresponding to the detailed data, and the identity identification corresponding to the detailed data is generated through a hash algorithm and symmetric encryption based on the detailed data and a key generated based on the SGX technology.

[0061] As described in S101, if there are multiple computing applicants, the computing party needs to perform an identification intersection of the identification sets provided by the multiple computing applicants with the second identification set saved by itself, so as to obtain the detailed data identity identifications used by the multiple computing parties for multi-party computing.

[0062] Among them, the identity of the detailed data used in the calculation in the first identification set is generated by the hash value in the enclave memory of the calculation party and the key generated based on the SGX technology. The identity of the detailed data used in the calculation in the second identification set is also generated in this way. For the same detailed data on the calculation party and the calculation applicant, the detailed data uses the same hash value and the same key for hash calculation, and finally performs symmetric encryption. The same detailed data has the same identity on the calculation party and the calculation applicant.

[0063] S103: Find detailed data using the intersection result.

[0064] As described in S102, the same piece of detailed data has the same identity identifier in the computing party and the computing applicant, and the identifiers are intersected in the enclave generated by the SGX technology, and the same detailed data identities are intersected, and the corresponding detailed data is found using the detailed data identity identifier.

[0065] S104: Using the detailed data and the calculation rules, the calculation is completed in the enclave generated based on the SGX technology.

[0066] Among them, if the calculation rules are sent in encrypted form, the calculation rules need to be decrypted. The encryption and decryption can be the encryption and decryption methods in the prior art, or can be encryption and decryption based on the keys generated by SGX technology, or encryption and decryption may not be performed, all of which fall within the scope of protection of this application.

[0067] Among them, the calculation rules can be a complete calculation rule provided by a calculation applicant, or the same complete calculation rule provided by multiple calculation applicants, or a calculation rule composed of partial calculation rules provided by multiple calculation applicants, or other methods, all of which fall within the scope of protection of this application.

[0068] S105: Return the calculation result to the calculation requester.

[0069] After the calculation result is obtained in the enclave, the calculation result can be encrypted using the calculation result encryption key, or encrypted using the key generated based on the SGX technology, or not encrypted. The calculation result can be processed or not processed and then returned to the calculation applicant.

[0070] In summary, in the above-mentioned secure computing method based on SGX technology, the computing party receives the computing rules and the first identification set sent by the computing applicant, and uses the received first identification set and the second identification set stored by itself to perform identification intersection in the enclave generated by the SGX technology. The computing party uses the intersection result to find the detailed data pre-stored by the computing party. The computing party uses the detailed data required for the calculation and the computing rules provided by the computing applicant to complete the calculation in the enclave generated by the SGX technology, and returns the calculation result to the computing applicant after the calculation is completed. The present application can obtain a hash value and a key in an enclave generated based on SGX technology, and obtain a detailed data identity by symmetric encryption after hashing the detailed data using the hash value and the key, and perform identification intersection in the enclave generated based on SGX technology to obtain the detailed data. By obtaining the key in this way, possible database collision behavior and possible malicious attack threats of the computing party are avoided, and the security of data storage is improved. The detailed data and the calculation rules are used to complete the calculation in the enclave generated based on SGX technology. The data is stored in the enclave generated based on SGX technology, and the identification intersection and calculation process are completed in the enclave, which can improve the security of multi-party computing.

[0071] The calculation party can be one or more. Figure 2 This is another flow chart of a secure computing method based on SGX technology, and the method may include the following steps:

[0072] S201: Receive a first computing request and a second computing request sent by a first computing applicant and a second computing applicant.

[0073] The first calculation request includes a part of the calculation rules and a first identification set provided by the first calculation applicant, and the second calculation request includes a part of the calculation rules and a second identification set provided by the second calculation applicant.

[0074] The first identification set includes the identity identification of the detailed data used by the first calculation applicant for calculation, and the second identification set includes the identity identification of the detailed data used by the second calculation applicant for calculation.

[0075] The first calculation request and some calculation rules in the first calculation request may be sent directly, or may be sent after being encrypted, or may be in other forms, all of which fall within the scope of protection of this application.

[0076] S202: Performing identity intersection on the first identity set and the third identity set stored by itself, wherein the identity intersection is completed in an enclave generated based on the SGX technology.

[0077] Among them, the third identification set includes the identity identification corresponding to the detailed data provided by the first computing applicant, and the identity identification corresponding to the detailed data provided by the first computing applicant is generated through a hash algorithm and symmetric encryption based on the detailed data and the key generated based on SGX technology.

[0078] S203: Performing identity intersection on the second identity set and the fourth identity set stored by itself, wherein the identity intersection is completed in an enclave generated based on the SGX technology.

[0079] Among them, the fourth identification set includes the identity identifier corresponding to the detailed data provided by the second computing applicant, and the identity identifier corresponding to the detailed data provided by the second computing applicant is generated through a hash algorithm and symmetric encryption based on the detailed data and the key generated based on SGX technology.

[0080] The two steps S202 and S203 may be performed simultaneously, or S202 may be performed before S203, or S203 may be performed before S202, all of which fall within the scope of protection of this application.

[0081] S204: Use the intersection result to find the detailed data.

[0082] Among them, the intersection result of the first identification set and the third identification set is used to find the detailed data used by the first calculation applicant; the intersection result of the second identification set and the fourth identification set is used to find the detailed data used by the second calculation applicant.

[0083] S205: Integrate the partial calculation rules provided by the first calculation applicant and the second calculation applicant into a complete calculation rule.

[0084] Among them, S205 can be completed between any two steps after S201 and before S206, or it can be completed simultaneously with any step between S202 to S204, all of which fall within the scope of protection of this application.

[0085] S206: Use the found detailed data and complete calculation rules to complete the calculation in the enclave generated based on the SGX technology.

[0086] S207: Return the calculation results to the first calculation applicant and the second calculation applicant.

[0087] After the calculation result is obtained in the enclave, the calculation result can be encrypted using the calculation result encryption key, or can be encrypted using a key generated based on the SGX technology, or can be unencrypted. The calculation result can be processed or returned to the first calculation applicant and the second calculation applicant without processing.

[0088] In summary, in the above-mentioned secure computing method based on SGX technology, the computing rules and identification sets provided by multiple computing applicants can be adapted to more complex computing scenarios. In the same multi-party secure computing process, different computing applicants can provide different types of detailed data to make the division of labor of each computing applicant clearer; they can also provide the same type of detailed data to make the results of multi-party secure computing more accurate.

[0089] In addition, this application proposes another method in combination with actual use needs. Figure 3 A flowchart of another secure computing method based on SGX technology provided in this application.

[0090] S301: Calculate the identity of the detailed data that the applicant needs to prepare.

[0091] The computing applicant processes the detailed data needed for the calculation to generate an identity identifier of the detailed data needed, and then performs a hash algorithm and symmetric encryption to generate an identity identifier of the detailed data needed.

[0092] The computing applicant measures the data in the enclave through the enclave measurement interface provided by the computing party SGX hardware device. The measurement can obtain the hash value in the computing party enclave memory and the key generated based on the SGX technology, and obtain the identity of the detailed data required for the calculation through the hash algorithm and symmetric encryption.

[0093] S302: The calculation applicant generates a first identification set.

[0094] The calculation applicant combines the identity identifier of the detailed data required for the calculation, the verification identifier for verifying the identity of the calculation applicant, and the calculation result encryption key to generate a first identifier set.

[0095] Among them, the first identification set may also include other identifications such as the return result time identification, all of which fall within the scope of protection of this application.

[0096] S303: The computing party receives the computing request sent by the computing applicant.

[0097] The calculation request includes a calculation rule and a first identification set provided by the calculation applicant.

[0098] S304: The computing party verifies the identity of the computing applicant using the verification identifier.

[0099] Among them, the verification process can be completed in the enclave of the computing party, or it can be completed outside the enclave, and both fall within the scope of protection of this application.

[0100] S305: The computing party performs identification intersection in the enclave.

[0101] The received first identification set is used to perform identification intersection with the second identification set stored by itself, and the identification intersection is completed in an enclave generated based on the SGX technology.

[0102] S306: The computing party judges the intersection result in the enclave. If there is an intersection result, S307 is executed; if there is no intersection result, S310 is executed to send return data to the computing applicant. After receiving the return data indicating that there is no intersection result, the computing applicant suspects that the computing party has a database collision.

[0103] S307: The calculation party uses the intersection result to find the detailed data.

[0104] S308: The computing party completes the computing in the enclave.

[0105] Among them, detailed data and calculation rules are used to complete the calculation in the enclave generated based on SGX technology.

[0106] S309: The computing party encrypts the computing result.

[0107] The calculation result is encrypted using the calculation result encryption key in the first identification set, and the encryption can be completed in the enclave.

[0108] S310: The computing direction sends return data to the computing requester.

[0109] In summary, the specific process of the secure computing method based on SGX technology provided above includes the verification of the identity of the computing applicant, clarifies the identity of the computing applicant, encrypts the computing results in the enclave generated based on SGX technology, and returns the computing results after encryption, making multi-party computing safer.

[0110] In addition, this application also provides Figure 4 A structural schematic diagram of a secure computing device based on SGX technology is shown.

[0111] A secure computing device 100 based on SGX technology, comprising:

[0112] The receiving module 101 is used to receive a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant.

[0113] The set intersection module 102 is used to perform identifier intersection on the received first identifier set and the second identifier set stored in itself.

[0114] The detailed data search module 103 is used to search for detailed data, and the detailed data is found by using the result of the intersection of the identifiers.

[0115] The calculation module 104 is used to calculate and obtain a calculation result, wherein the calculation uses the found detailed data and the calculation rule.

[0116] The return module 105 is used to return the calculation result.

[0117] The device may also include the following modules:

[0118] The detailed data identity generation module uses the key generated based on SGX technology to generate the identity of the detailed data used in the calculation through hash algorithm and symmetric encryption.

[0119] The judgment module is used to determine whether the detailed data can be found using the intersection result. If not, it proves that there is a database collision.

[0120] A verification information request module, used to send a detailed data verification request to the calculation applicant;

[0121] A verification information receiving module, used to receive the detailed data identity identifier returned by the computing applicant;

[0122] The verification module uses the detailed data identity identifier to verify the detailed data.

[0123] The calculation result encryption module is used to encrypt the calculation result, and the calculation result is encrypted using the calculation result encryption key.

[0124] The return module 105 is specifically used for:

[0125] The encrypted calculation result is returned to the calculation applicant.

[0126] The secure computing device based on SGX technology provided above can perform multi-party computing more securely.

[0127] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned secure computing method based on SGX technology are implemented.

[0128] The computer-readable storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes, all of which fall within the scope of protection of this application.

[0129] It should be noted that each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is merely schematic, in which the unit described as a separate component may or may not be physically separated, and the component prompted as a unit may or may not be a physical unit, that is, it may be located in one place, or it may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative work.

[0130] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A secure computing method based on SGX technology, characterized in that: include: Receiving a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant; Performing an identification intersection using the received first identification set and the second identification set stored by itself, wherein the identification intersection is completed in an enclave generated based on the SGX technology; Use the intersection result to find the detailed data; Using the detailed data and the calculation rules to complete the calculation in the enclave generated based on the SGX technology; Return the calculation result to the calculation applicant; The computing applicant includes: a first computing applicant and a second computing applicant, the first computing applicant sends a first computing request, and the second computing applicant sends a second computing request; the method further includes: receiving the first computing request and the second computing request sent by the first computing applicant and the second computing applicant; Performing an identification intersection on the first identification set and the third identification set stored by itself, wherein the identification intersection is completed in an enclave generated based on the SGX technology; Performing an identifier intersection of the second identifier set and the fourth identifier set stored in the system, wherein the identifier intersection is performed in an enclave generated based on the SGX technology; Use the intersection result to find the detailed data; Integrate partial calculation rules provided by the first calculation applicant and the second calculation applicant into a complete calculation rule; The calculation is completed in the enclave generated based on the SGX technology using the found detailed data and complete calculation rules.

2. The method according to claim 1, characterized in that The first identification set includes: The identity identifier of the detailed data used in the calculation is generated by a hash algorithm and symmetric encryption based on the detailed data used in the calculation and a key generated based on the SGX technology.

3. The method according to claim 1, characterized in that: The second identification set includes: The identity identifier corresponding to the detailed data is generated by a hash algorithm and symmetric encryption based on the detailed data and a key generated based on the SGX technology.

4. The method according to any one of claims 1 to 3, characterized in that: The method further includes: if the detailed data cannot be found using the intersection result, it proves that there is a database collision behavior.

5. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Sending a detailed data verification request to the calculation applicant; Receive the detailed data identity identifier returned by the computing applicant; The detailed data identity is used to perform detailed data verification, and the data verification is completed in the enclave generated based on the SGX technology.

6. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Encrypting the calculation result in the enclave generated based on the SGX technology, wherein the encryption key used for encrypting the calculation result is obtained from the first identifier set; The step of returning the calculation result to the calculation requesting party includes: The encrypted calculation result is returned to the calculation applicant.

7. A secure computing device based on SGX technology, characterized in that: include: A receiving module, configured to receive a calculation request sent by a calculation applicant, wherein the calculation request includes a calculation rule and a first identification set provided by the calculation applicant; A set intersection module, used for performing an identification intersection between the received first identification set and the second identification set stored in the module; A detailed data search module, used to search for detailed data, wherein the detailed data is found by using the result of the intersection of the identifiers; A calculation module, used for calculating and obtaining a calculation result, wherein the calculation uses the found detailed data and the calculation rule; A return module, used to return the calculation result; The computing applicant includes: a first computing applicant and a second computing applicant, the first computing applicant sends a first computing request, and the second computing applicant sends a second computing request; the device is also used for: receiving the first computing request and the second computing request sent by the first computing applicant and the second computing applicant; Performing an identification intersection on the first identification set and the third identification set stored by itself, wherein the identification intersection is completed in an enclave generated based on the SGX technology; Performing an identifier intersection of the second identifier set and the fourth identifier set stored in the system, wherein the identifier intersection is performed in an enclave generated based on the SGX technology; Use the intersection result to find the detailed data; Integrate partial calculation rules provided by the first calculation applicant and the second calculation applicant into a complete calculation rule; The calculation is completed in the enclave generated based on the SGX technology using the found detailed data and complete calculation rules.

8. The device according to claim 7, characterized in that The device further comprises: The calculation result encryption module is used to encrypt the calculation result.

9. An electronic device, characterized in that: comprising a memory and a processor, wherein: The memory is used to store the computer program; The processor is used to execute the computer program to implement the secure computing method based on SGX technology as described in any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the secure computing method based on the SGX technology as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Multi-party computing method and device based on blockchain, equipment and medium

    CN111222165A

  • Multi-party safe intersection solving method and device, storage medium and equipment

    CN113901425A