A Controllable Data Sharing Method Based on SGX and Smart Contracts

By introducing SGX trusted execution environment and smart contracts into the data sharing platform, the problems of data ownership and privacy protection are solved, and the controlled use and security of data in an isolated environment are realized, the risk of data theft is reduced, and the accountability mechanism is provided, and the performance overhead is small.

CN115473678BActive Publication Date: 2025-07-29PEKING UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210950101.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-03-16
Filing Date
2022-08-09
Publication Date
2025-07-29
Estimated Expiration
2042-08-09

AI Technical Summary

Technical Problem

In the prior art, it is difficult for users to ensure data ownership and privacy protection in the data sharing mode, data providers lack control over data, and there are problems of data leakage and accountability.

Method used

Using a trusted execution environment and smart contract based on SGX, we use smart contracts to generate and put them on the link to build a trusted computing environment, limiting data calculations in an isolated environment, and using the computing audit module to record the data usage process, ensuring that data is used under the contract control and preventing data theft and leakage.

Benefits of technology

It realizes controllability of data ownership, ensures security and privacy protection of data during use, reduces the risk of data theft, and provides a accountability mechanism after data leakage, with less performance overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115473678B_ABST
    Figure CN115473678B_ABST
Patent Text Reader

Abstract

The present invention discloses a controllable data sharing method based on SGX and smart contracts. The method is as follows: 1) Generate a smart contract based on the data usage requirements of the data user and the code review results of the data provider for using the data, and upload it to the blockchain; 2) The data user constructs a trusted computing environment required for data calculation based on SGX; the data provider performs security verification on the trusted computing environment, and after the verification passes, transmits the encrypted sensitive data to the trusted computing environment; 3) The data user uses the sensitive data under the control of the smart contract. The present invention can not only ensure that data cannot be stolen through direct copying and covert channels during the program operation, thereby ensuring data security, but also ensure the accountability issue after data leakage, thereby ensuring the trustworthy traceability during the data usage process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data exchange and sharing, and particularly to a controllable data sharing method based on SGX and smart contracts. Background Art

[0002] In the context of the big data era, with the deployment of communications such as 5G, users can enjoy faster and better network services. At the same time, the privacy protection and data security of mobile users also face more threats. Various enterprises have collected a large amount of user data, which can be used to improve their own businesses, provide more personalized and high-quality services for users, or be shared with other enterprises to obtain benefits. Due to issues such as the sensitivity of social data, corporate interests, and legal risks, user data sharing faces many difficulties. Among them, the ownership and privacy issues of shared data have become increasingly important. How to ensure the ownership of data and the privacy of users has become the primary problem in data sharing.

[0003] In the traditional data sharing mode, mobile users often have to accept the privacy and data agreements of enterprises, agree to enterprises collecting their data, and lack effective control over privacy and data. That is, users share their data completely and permanently once and for all with data users. The user data collected by enterprises is often traded to other enterprises once, and also lacks effective control over data ownership. It is difficult for both users and enterprises to ensure the controllability of data use, and they face the security and legal risks of user data privacy leakage. Therefore, it is necessary to propose a new sensitive data sharing mode and study data ownership management solutions such as secure exchange, isolated computing framework, and deterministic data deletion in the new data sharing mode, so that data providers (including mobile users and information collection enterprises) can safely exchange security-sensitive data with data consumers for computing, and ensure the ownership of data by data providers and the controllability of the number of data uses, and be able to verify that sensitive data is not copied and held by data consumers.

[0004] This article will focus on studying a framework for constructing sensitive data exchange and computing based on the SGX secure isolation environment. This framework should support the credibility verification of the computing environment, computing process, output results, and deletion after computing. Through a hardware-based trusted execution platform (such as SGX), a secure computing environment can be provided for sensitive data. However, the urgent problem to be solved is the issue of data control rights and ownership, that is, an effective remote attestation technology is needed to prove to data providers that their sensitive data has indeed entered a specified isolated computing environment on the data consumer side and is determined to be deleted after the deadline (no available copies).

[0005] The trusted isolation computing framework for sensitive data based on SGX focuses on hardware-based trusted execution technology, and studies to provide an effective secure exchange and trusted isolation computing environment in the scenario of mobile user data sharing and usage, ensuring that the sensitive data of data providers is not permanently held after the usage period. First, analyze the security threats faced in the process of secure data exchange and isolation computing. 1) We will analyze the possible security threats and difficulties in the process of isolation computing from the perspectives of the business requirements of data exchange and the security verification of the isolation computing environment. Since the computing code is provided by the data user, and the data is computed in the computing environment constructed by the data provider, the data consumer may use attack means such as directly or indirectly saving copies, covert channels, and access pattern attacks to store sensitive data locally or transmit it out; 2) After the computing is completed, the sensitive data (or keys) stored locally needs to be destroyed in a timely manner, otherwise it may lead to the problem of malicious holding of sensitive data. Second, based on the analysis of various security threats, design a framework for secure data exchange and trusted isolation computing of sensitive data.

[0006] Intel SGX (Software Guard Extension) is a new extension of the Intel architecture, which adds a new set of instruction sets and memory access mechanisms to the original architecture. These extensions allow applications to implement a container called an enclave, which divides a protected area in the address space of the application, providing confidentiality and integrity protection for the code and data within the container, and protecting them from being damaged by malicious software with special permissions.

[0007] An enclave is a protected content container used to store sensitive data and code of an application. SGX allows applications to specify the parts of code and data that need to be protected. Before creating an enclave, these code and data do not have to be checked or analyzed, but the code and data loaded into the enclave must be measured. When the parts of the application that need to be protected are loaded into the enclave, SGX protects them from being accessed by external software. An enclave can prove its identity to a remote authenticator and provide the necessary functional structures for securely providing keys. Users can also request unique keys, which are made unique by combining the enclave identity and the platform identity, and can be used to protect keys or data stored outside the enclave.

[0008] Blockchain and Smart Contracts: Smart contracts based on blockchain are programs executed by a network of participants who agree on the program state. Existing smart contract systems replicate data and computations across all nodes in the system so that each node can verify the correct execution of the contract. Full replication across all nodes provides a high level of fault tolerance and availability. Smart contract systems such as Ethereum have demonstrated their utility in various applications. However, some key limitations hinder the widespread adoption of current smart contract systems. First, the on-chain computations of fully replicated smart contracts are inherently expensive. For example, in August 2017, the cost of adding two numbers together one million times in an Ethereum smart contract was $26.55, which is approximately 8 orders of magnitude higher than the cost of AWS EC2. Additionally, current systems do not provide privacy guarantees. Users are identified by pseudonyms. Many studies have shown that pseudonyms only provide weak privacy protection. Moreover, the contract state and user inputs must be made public so that miners can verify the correct computations. The lack of privacy fundamentally limits the scope of applications of smart contracts.

[0009] Disadvantages and limitations of several existing methods

[0010] Traditional data sharing is that the data provider directly shares the data with other users all at once. To reduce the leakage of sensitive data, the data often needs to be processed for privacy, which will result in a certain loss of data accuracy. In addition, there is a serious defect in the traditional data sharing model: the data owner inevitably loses control of the data and cannot guarantee the ownership and controllability of the data in the platform, which also brings the problem of difficult accountability.

[0011] The cloud user data controlled usage model proposed by the present invention belongs to the research category of privacy computing. Privacy computing is one of the important methods for sharing sensitive data. The key technologies often adopted in privacy computing include multi-party secure computing, federated learning, data desensitization, differential privacy, homomorphic encryption, blockchain and other key technologies.

[0012] Privacy computing solutions based on isolated computing spaces. The trusted execution environment can converge data from all parties into a secure area for computing and isolate and protect the data through hardware technology. For example, Olga et al. proposed privacy-preserving machine learning algorithms based on the SGX trusted execution environment for some common machine learning algorithms such as SVM, k-means, decision trees, and neural networks. There are also distributed computing systems such as VC3, Ryoan, and Haven. The data sandbox technology can build a trusted computing environment and allow external programs to directly use sensitive data in the sandbox for computing such as model training, but the data users cannot enter the data sandbox to directly obtain the data, thus achieving the purpose of protecting data privacy. Manufacturers such as UCloud have launched relevant data sandbox solutions. The privacy computing solution based on TEE can use TEE to resist external attacks, but it cannot restrict the malicious behaviors of internal code, including the data sandbox technology. There is a need for a data-controlled usage solution that can ensure that data is shared for use by other cloud user applications and can ensure the confidentiality and ownership of sensitive data.

[0013] Data sharing solutions based on blockchain. Privacy computing technology needs to be combined with multiple technologies such as cloud computing, blockchain, and artificial intelligence to truly meet the data usage needs of data users. Currently, users increasingly adopt the method of integrating multiple technologies. Due to the advantages of blockchain such as decentralized control, fault tolerance, and execution of smart contracts, many data sharing solutions use blockchain to build sensitive data sharing solutions, such as the data management platform of GDPR, the secure and privacy-protected data sharing framework PrivySharing based on blockchain, etc. Currently, related work on ensuring the confidentiality of smart contracts based on the SGX trusted execution environment, such as FastKitten and Ekiden, mainly uses the TEE provided by SGX to ensure the confidentiality of blockchain or smart contracts, which is different from the goal of this paper. The data sharing solutions built based on blockchain can create a trusted data sharing platform and channel for cloud users, but they cannot solve the problem of data ownership loss. However, the difficulties in combining SGX and blockchain can be learned from. Summary of the Invention

[0014] In the initial data sharing and exchange platform, the main considerations were security and privacy issues, and the issue of data ownership was not considered. With the increasingly wide application of big data, the issue of data ownership is as important as the issues of data security and privacy protection.

[0015] The present invention focuses on and addresses the issues of data ownership and data leakage during the data sharing process. The current industry solutions mainly focus on static data security and access security, but ignore the security and isolation during task execution. Once some nodes are controlled by malicious users, or the tasks of some jobs run on the same node as the tasks of malicious users, there is a risk of information leakage.

[0016] The object of the present invention is to provide a controllable data sharing method based on SGX and smart contracts. The general idea of the present invention is: introducing the idea of isolated computing into the data sharing process of the data sharing platform, by restricting the data of users to be calculated only in a trusted isolation environment to achieve the purpose of ensuring data ownership, and using smart contracts to control and store the data usage process to reduce the risk of data being stolen. The main idea of this method is that the data user first develops code based on the data usage requirements and uploads the code and code fingerprint to the blockchain; then the data user constructs an isolated computing environment in the computing platform, and the data provider verifies the isolated computing environment. After successful verification, the data provider sends encrypted data to the isolated computing environment; during the data calculation process, the behavior of the program using the data is controlled and recorded according to the record and inspection of the calculation process of the code, so that it can not only ensure that the program cannot steal data through direct replication and covert channels during operation, as Figure 1 shown, thus ensuring the security of the data, but also ensuring the accountability issue after data leakage.

[0017] The technical solution of the present invention is as follows:

[0018] A controllable data sharing method based on SGX and smart contracts, the steps of which are:

[0019] 1) Generate a smart contract based on the data usage requirements of the data user and the code review results of the data provider for using the data, and upload it to the blockchain;

[0020] 2) The data user constructs a trusted computing environment required for data calculation based on SGX; the data provider conducts a security verification on the trusted computing environment, and after passing the verification, transmits the encrypted sensitive data to the trusted computing environment;

[0021] 3) The data user uses the sensitive data under the control of the smart contract.

[0022] Further, the method for generating the smart contract is as follows: According to the data usage contract negotiated between the data user and the data provider, the data provider provides a software development kit to the data user; the data user needs to develop an SGX application program according to the usage requirements in the data usage contract and the software development kit, and send the developed SGX application program to the data provider; the data provider conducts a code review on the SGX application program and verifies whether the computing audit module is inserted as required; then the data provider creates the smart contract according to the SGX application program and the data usage contract.

[0023] Further, the data usage contract includes the dataset to be used, the number of uses or the usage period.

[0024] Further, the data provider's code review of the SGX application program includes whether the relevant measurement code is inserted during the development and compilation of the SGX application program by the data user.

[0025] Further, in step 3), the smart contract uses the computing audit module to verify the usage permissions of the data user and uses the program measurement method to record the data usage records of the data user.

[0026] Further, in step 2), the data user constructs a trusted computing environment based on SGX technology; the data provider verifies the trusted computing environment through the remote attestation mechanism of SGX.

[0027] Further, in step 2), under the control of the smart contract, the data provider encrypts the sensitive data using the public key provided by the trusted computing environment and transmits it to the trusted computing environment. The trusted computing environment decrypts the encrypted sensitive data using its own private key and then verifies the data integrity.

[0028] Further, after the data user finishes using the sensitive data, the trusted computing environment clears the sensitive data and keys stored locally.

[0029] Further, the trusted computing environment includes a key generation and management module and a data integrity verification module; the key generation and management module is responsible for the generation and management of keys; the data integrity verification module is responsible for verifying data integrity.

[0030] Further, the trusted computing environment also includes a computing control module, which is used to communicate with the smart contract, control the data usage process of the data user in the trusted computing environment, and perform data cleaning after the computing task is completed or after the data usage period expires.

[0031] The main steps of the present invention are: code and contract generation stage, computing initialization stage, data transmission stage, data computing stage, and data cleaning stage. The process of controlled data use is as shown in the appendix Figure 1 as follows.

[0032] 1) Code and contract generation. The data user and the data provider need to agree on a data use contract (including data sets, number of uses or cycle, etc.). The data provider provides a software development kit, etc. for the data user. The data user needs to develop an SGX application program according to the usage requirements in the data use contract (such as the number of uses or cycle) (it cannot be directly or indirectly copied, and differential access information cannot be exposed; through sensitive data flow detection, behaviors such as direct data leakage are avoided, and restrictions are imposed on the data structures and access behaviors used to avoid the leakage of differential information), and send the developed SGX application program to the data provider. The data provider conducts relevant code reviews through code detection, etc. (mainly reviewing whether the code is developed according to the data use requirements and verifying whether there is malicious code in the code to steal data), and verifying whether modules such as a computing audit module are inserted as required. Finally, the data provider creates a smart contract based on the SGX application program and the corresponding data use contract and uploads the smart contract to the blockchain.

[0033] 2) Computing environment initialization. When computing starts, first, the data user needs to build a trusted computing environment based on SGX technology and have it verified by the data provider. Only after verifying the computing environment will the data provider send encrypted sensitive data to the trusted computing environment for computing. Specifically, the data user creates a trusted computing environment (loading the developed SGX application program), and the smart contract remotely verifies whether the SGX trusted computing environment is correctly loaded through the remote attestation mechanism of SGX.

[0034] 3) Encrypted data transmission. After verifying the trusted computing environment, under the control of the smart contract, the data provider uses a symmetric encryption algorithm to send data to the data user. The data transmission process includes: the data provider uses the public key PK TEE provided by the trusted computing environment (TEE) to encrypt the data and sign the data, and transmits the encrypted data to the verified trusted computing environment through the network. In the trusted computing environment, the encrypted sensitive data is decrypted using its own private key, and then the data integrity is verified. The data provider and the trusted computing environment can negotiate a symmetric key k after establishing a secure channel to improve efficiency.

[0035] 4) Data isolation calculation. During the data calculation process, the calculation audit module verifies the usage rights of the data and records the detailed process of data usage using program measurement methods. By inserting measurement nodes into the program to record and verify the execution process of the program, the measurement method can collect information with a sufficiently fine granularity. Based on this information, corresponding data usage records can be constructed, and then it can be determined whether there are malicious behaviors in the application programs of the data users.

[0036] 5) Data and key cleaning. After the data calculation is completed, the trusted computing environment needs to clean the sensitive data and keys stored locally to avoid the leakage of sensitive data. The data cleaning operations include: cleaning the sensitive data on the disk and in the memory, and destroying the SGX trusted computing environment and keys.

[0037] Advantages of the present invention

[0038] With the popularization of big data applications, more and more users are using data exchange and sharing platforms, and the issues of data ownership and data security have become particularly important. By combining SGX technology and blockchain smart contracts, the present invention realizes the controlled use of sensitive data on the data user platform or the third-party platform (only the SGX hardware is trusted), ensuring the requirements of the data provider for the ownership and confidentiality protection of its data. Based on the confidentiality protection and remote verification functions provided by SGX technology, the present invention constructs a trusted and verifiable isolated computing environment. Sensitive data will only be decrypted and used in the isolated computing environment, ensuring that the data will not be directly and permanently held by the data user. In addition to ensuring controllable data ownership, considering the privacy protection requirements, the data provider needs to conduct a security review of the code using the data to ensure that the data will not be stolen during the usage process. The C-Sharing model controls and records the data usage process through smart contracts, ensuring the trusted traceability of the data usage process.

[0039] The present invention proposes a secure data sharing strategy based on isolated computing and smart contracts, filling the gap in the controlled sharing and usage of sensitive data for data exchange platforms at home and abroad. It can effectively promote the sharing of sensitive data, while ensuring data ownership and security, and the method is simple to implement and deploy. At the same time, this method incurs a small performance overhead, enabling the security measurement of the data usage process. In the best case, it only increases the performance overhead by 10.36% - 25%, effectively preventing the risk of sensitive data being stolen. Brief description of the drawings

[0040] Figure 1 It is a schematic diagram of the process for the controlled use of sensitive data of the present invention.

[0041] Figure 2 It is a schematic diagram of the internal components of the prototype system of the present invention.

[0042] Figure 3 This is a schematic diagram of the insertion point for recording the program execution flow of the present invention. Detailed implementation manners

[0043] The present invention will be further described in detail below with reference to the accompanying drawings. The working process of the prototype system is as Figure 1 shown, and the prototype structure of the present invention is as Figure 3 shown.

[0044] When data is calculated in the isolated computing environment provided by SGX, threats from the system and internal code need to be resisted. Therefore, corresponding modules need to be added to the application program to control access to resources and audit data usage behaviors. The trusted measurement component in the computing environment records the execution process of the code and the data usage process, and generates fine-grained program execution logs and data usage logs. These two types of logs can be used by data users and data providers to detect data theft behaviors and define responsibilities. Figure 2 Shows the internal components added by the present invention. The following are the definitions and specific descriptions of the relevant modules in the internal components. It mainly includes:

[0045] 1) The key generation and management module runs in the SGX trusted space and is responsible for key generation and management, such as operations for randomly generating prime numbers and generating asymmetric keys, and is also responsible for operations such as data encryption and decryption.

[0046] 2) The data integrity verification module is mainly responsible for verifying data integrity. In the scenario of controlled data usage, data users lack trust in the data integrity sent by data providers and need to verify the data. After the data user negotiates with the data provider on the dataset to be used, the data user needs to generate data integrity verification information and upload it to the blockchain smart contract. Before the data user's program uses the data, it completes the verification with the smart contract.

[0047] 3) Responsible for recording the data usage process, data calculation process, and data cleaning process. Specifically, it uses the method of recording data streams and program execution flows for tracking, and generates corresponding data usage logs and program execution logs. These logs can be used for responsibility tracking after the data is stolen.

[0048] 4) The calculation control module mainly communicates with the smart contract that controls the calculation process, is responsible for controlling the data usage process in the trusted execution space, and needs to perform data cleaning operations after the calculation task is completed or after the data usage period expires.

[0049] 5) Data stream and program execution flow tracing mainly rely on the measurement codes inserted into the computing program. This requires the data users to insert relevant measurement codes during the program development and compilation processes, and the data providers need to conduct inspections during the code auditing process.

[0050] Embodiment:

[0051] Take the SGX technology and Hyperledger Fabric smart contract as examples.

[0052] The implementation of the prototype of the present invention mainly includes three parts: the implementation of the data security exchange protocol, the development of the control module and the insertion of measurement instructions, and the implementation of the smart contract. The detailed implementation details of the three parts will be introduced in this section.

[0053] 1) Implementation of the sensitive data exchange protocol. The above data-controlled usage process section introduced processes such as data encrypted transmission. The specific implementation of the data-controlled usage protocol is as follows: The SGX trusted space calls the key generation module to encapsulate the generated TEE private key SK TEE into the memory, and broadcasts the TEE public key PK TEE to the data provider (this process does not need to be confidential, and the MD5 hash value is used to ensure the integrity of the public key). Before the data provider transmits the data to the computing platform for processing, it first encrypts the data with the SGX public key PKTEE, and then directly transmits it to the computing platform party through the network. After being sent to the computing platform, it is directly transmitted from the computing platform host memory to the enclave secure memory through the data copy interface. The trusted space can decrypt the data using the SGX private key SKTEE to decrypt the sensitive data in the SGX trusted space and perform calculations. After the calculation is completed, it is encrypted with the public key PK DC of the data user and then transmitted back to the data user from the secure memory and the network.

[0054] In the specific implementation, the RSA key system is selected and implemented as the asymmetric key system, and the processes of generating random numbers, prime number verification, and public and private key generation of the complete RSA are implemented in the SGX trusted space and run independently of external conditions. In the key steps of generating random numbers, the method of reading the clock is used to generate pseudo-random numbers. Prime number verification needs to ensure that the prime numbers randomly generated are verified for primality at a time complexity far lower than brute-force factorization. Users can also use other asymmetric key systems such as the ECC key system to implement.

[0055] 2) Implementation of the computing control module. The implementation of the computing control module is based on the extension of the LLVM framework and integrated with the SGX SDK. The LLVM Pass is used to selectively insert measurement code, and the Clang compiler is used to compile the application source code. Clang is the front-end of LLVM, which compiles the Go code into LLVM IR. According to the measurement code insertion algorithm, the static analysis tool is implemented as an LLVM IR optimization pass, which can insert measurement code into selected basic blocks. These instructions call the audit module in the enclave to measure the data usage process and the program execution process, such as Figure 3 shown

[0056] 3) Implementation of the smart contract function. The C-Sharing model prototype is implemented using the Hyperledger Fabric open-source blockchain. It mainly includes two organizations (i.e., the data provider and the data user). In the smart contract, the basic information mainly includes the dataset information agreed upon by both parties (including integrity verification information), the code information for using the dataset, and the data usage period agreed upon by both parties (this period is the deadline for the data user to use the data). In addition to the basic information, the smart contract is involved in verifying the trusted execution environment, verifying the integrity of the dataset, controlling the data usage cycle, and finally cleaning up the data and uploading the data usage log to the blockchain, etc.

Claims

1. A controllable data sharing method based on SGX and smart contracts, the steps of which are as follows: 1) Generate a smart contract based on the data usage requirements of the data user and the code review results of the data provider for using the data, and upload it to the blockchain. The method for generating the smart contract is as follows: According to the data usage contract negotiated between the data user and the data provider, the data provider provides a software development kit for the data user. The data user needs to develop an SGX application program according to the data usage requirements and the software development kit in the data usage contract, and send the developed SGX application program to the data provider. The data provider conducts a code review on the SGX application program and verifies whether a computing audit module is inserted as required. Then, the data provider creates the smart contract according to the SGX application program and the data usage contract. The data usage contract includes the data set used, the number of uses or the period. The code review of the SGX application program by the data provider includes whether the data user inserts relevant measurement codes during the development and compilation of the SGX application program. 2) The data user constructs a trusted computing environment required for data calculation based on SGX. The data provider conducts a security verification on the trusted computing environment, and after the verification passes, transmits the encrypted sensitive data to the trusted computing environment. 3) The data user uses the sensitive data under the control of the smart contract. The smart contract uses the computing audit module to verify the usage permissions of the data user and uses the program measurement method to record the data usage records of the data user. A computing control module is further included in the trusted computing environment, and the computing control module is used to communicate with the smart contract to control the data usage process of the data user in the trusted computing environment. And perform data cleaning after the computing task is completed or after the data usage period expires.

2. The method according to claim 1, characterized in that, In step 2), the data user constructs a trusted computing environment based on SGX technology. The data provider verifies the trusted computing environment through the remote attestation mechanism of SGX.

3. The method according to claim 1, characterized in that In step 2), under the control of the smart contract, the data provider encrypts the sensitive data using the public key provided by the trusted computing environment and transmits it to the trusted computing environment. The trusted computing environment decrypts the encrypted sensitive data using its own private key, and then verifies the data integrity.

4. The method according to claim 1, characterized in that After the data user finishes using the sensitive data, the trusted computing environment clears the sensitive data and keys stored locally.

5. The method according to claim 1, wherein The trusted computing environment includes a key generation and management module and a data integrity verification module. The key generation and management module is responsible for the generation and management of keys. The data integrity verification module is responsible for verifying data integrity.

Citation Information

Patent Citations

  • Data circulation method based on block chain and enclave

    CN109660358A