A trusted privacy computing method, device, equipment and storage medium

By configuring a local authentication module in a distributed TEE node network for self-authentication and mutual authentication, the complexity of centralized authentication schemes is solved, enabling secure data flow and interconnection in heterogeneous environments, and improving the flexibility and data security of the authentication process.

CN116204914BActive Publication Date: 2026-04-21HANGZHOU DBAPPSECURITY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU DBAPPSECURITY CO LTD
Filing Date
2022-12-09
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, trusted authentication schemes for distributed TEE node networks typically rely on centralized auxiliary methods, resulting in high complexity of mutual verification engineering and difficulties in system maintenance. This makes it impossible to achieve self-authentication and mutual authentication of decentralized heterogeneous trusted execution environments.

Method used

By pre-configuring an authentication module in each node, local trusted authentication and distributed environment mutual authentication are achieved. Trusted credentials are generated using the local authentication module, and environmental information is broadcast and verified based on these credentials, thus realizing decentralized heterogeneous environment authentication and data flow.

Benefits of technology

It achieves decentralized heterogeneous environment authentication, supports interconnection between trusted execution environments from different vendors, ensures user data security, does not rely on remote verification agents, and improves the flexibility of the authentication process and the security of data flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116204914B_ABST
    Figure CN116204914B_ABST
Patent Text Reader

Abstract

This application discloses a trusted privacy computing method, apparatus, device, and storage medium, relating to the field of information security technology. The method includes: generating a privacy computing task and sending the privacy computing task to several external nodes to notify other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules; performing local trusted authentication operations on their own trusted execution environments using their pre-configured authentication modules; performing local distributed environment mutual authentication operations; and, after successful local distributed environment mutual authentication, performing data transfer operations between their own trusted execution environments and other external nodes whose local distributed environment mutual authentication operations have been successful, to execute corresponding distributed computing operations based on the privacy computing task. This application achieves remote authentication of the trusted execution environment through the node's own authentication module, realizing self-authentication and mutual authentication operations of decentralized heterogeneous trusted execution environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a trusted privacy computing method, apparatus, device, and storage medium. Background Technology

[0002] In the development of the digital society, various products and services derived from big data technology and data intelligence have extensively impacted business and daily life. With the iterative development of various algorithms, the requirements for data dimensions and volume are increasing daily. Individual organizations can no longer rely solely on data generated from their own operations to support the needs of these scenarios. Therefore, joint analysis and modeling using data from multiple parties has become an important trend. Since big data analysis inevitably involves enterprise user data and operational data, all parties involved in the joint data collaboration process hope that the privacy information in the raw input data can be fully protected, and that the final output only includes the analytical results or models obtained through algorithmic calculations that do not contain specific data—that is, achieving data that is "usable but not visible."

[0003] Currently, joint computation of data can be achieved through a distributed network of TEE nodes deployed across multiple institutions. However, current schemes for building distributed TEE node networks and for completing trusted authentication of distributed TEE nodes are generally centralized and auxiliary methods. Trusted authentication refers to the process where the initiating verification end sends a request to the remote task execution end, and the task execution end proves to the initiating verification end that it has not been modified compared to the target verification environment. The verified end is a trusted execution environment, and successful verification indicates the security of the computing environment and the integrity of the running code. Generally, a server from a remote vendor is required for auxiliary verification. Since mutual verification between different TEEs is required, different verification mechanisms of different TEEs are involved. If the system architecture is not modified, then each party's TEE module must integrate multiple sets of verification logic. On the one hand, this increases the engineering complexity of mutual verification; on the other hand, it is not conducive to the later maintenance of the system. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a trusted privacy computing method, apparatus, device, and storage medium, which can complete remote authentication of the trusted execution environment through the node's own authentication module, realizing self-authentication and mutual authentication operations of decentralized heterogeneous trusted execution environments. The specific solution is as follows:

[0005] Firstly, this application discloses a trusted privacy computation method, applied to a task initiation node, comprising:

[0006] A privacy computing task is generated and sent to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environment using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes;

[0007] It utilizes a pre-configured local authentication module to perform local trusted authentication operations on its own trusted execution environment;

[0008] Perform local distributed environment mutual authentication operation, and after the local distributed environment mutual authentication operation is successful, perform data transfer operation with other external nodes whose local distributed environment mutual authentication operations are successful through its own trusted execution environment, so as to perform corresponding distributed computing operations based on the privacy computing task.

[0009] The local trusted authentication operation of any participating node includes authenticating its own trusted execution environment and broadcasting the environment information of its trusted execution environment to other participating nodes after successful authentication; the local distributed environment mutual authentication operation of any participating node is to authenticate the trusted execution environments of other participating nodes using the environment information of its own trusted execution environment sent by other participating nodes.

[0010] Optionally, the step of performing local trusted authentication on its own trusted execution environment using a locally pre-configured authentication module includes:

[0011] The system uses a pre-configured local authentication module to search for the root certificate corresponding to the target trusted authentication request transmitted by its own trusted execution environment from a remote verification server; the remote verification server is a server deployed on the trusted execution environment provider's server.

[0012] The authentication module uses the root certificate to remotely verify the local environment report within its trusted execution environment.

[0013] After the remote verification operation is successful, a corresponding trusted credential is generated, and the corresponding environment information of its trusted execution environment is broadcast to the other external nodes through its own interconnection agent.

[0014] Optionally, the trusted privacy computation method further includes:

[0015] Create and start its own trusted execution environment, and use the automatic trusted execution environment to process the initial trusted authentication request initiated by its own host agent to generate the target trusted authentication request.

[0016] Optionally, after the authentication module performs remote verification of the local environment report within its trusted execution environment using the root certificate, the process further includes:

[0017] The authentication module returns the corresponding remote verification result to its own host agent, and the host agent synchronously sends the remote verification result to its own interconnect agent, so that the interconnect agent can determine whether the remote verification operation was successful based on the remote verification result.

[0018] Optionally, after the authentication module performs remote verification of the local environment report within its trusted execution environment using the root certificate, the process further includes:

[0019] If the remote verification operation fails, the system uses its own interconnection agent to generate corresponding verification error information based on the remote verification result and sends it to the local privacy computing platform; the privacy computing task is a task generated by the privacy computing platform.

[0020] Optionally, the step of authenticating the trusted execution environment of each of the other participating nodes using the environment information of their own trusted execution environment sent by the other participating nodes includes:

[0021] Using the environment information of their own trusted execution environment sent by the other participating nodes, a signature verification operation is performed on the trusted credentials corresponding to the trusted execution environments of the other participating nodes.

[0022] If the verification of trusted credentials for all other participating nodes is successful, then the current local distributed environment mutual authentication operation is considered successful.

[0023] Optionally, the data transfer operation performed by other external nodes that have successfully completed mutual authentication between their trusted execution environment and their respective local distributed environments, in order to execute corresponding distributed computing operations based on the privacy computing task, includes:

[0024] The external nodes that successfully perform mutual authentication operations with their own trusted execution environment and their respective local distributed environments synchronize the calculation parameters to perform data flow operations, so as to perform distributed joint ciphertext calculation based on the privacy calculation task in the trusted execution environment of the corresponding participating node of the calculation parameters.

[0025] Alternatively, it can perform data transfer operations with other external nodes that have successfully completed mutual authentication between its own trusted execution environment and its respective local distributed environment, in order to obtain the encrypted data to be computed returned by each external node, and then decrypt each of the encrypted data to be computed in its own trusted execution environment, and then perform distributed joint plaintext computation on each of the decrypted data to be computed.

[0026] Secondly, this application discloses a trusted privacy computing device, applied to a task initiation node, comprising:

[0027] A task generation module is used to generate privacy computing tasks and send the privacy computing tasks to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing tasks include the task initiating node and several external nodes.

[0028] The trusted authentication module is used to perform local trusted authentication operations on its own trusted execution environment using a locally pre-configured authentication module.

[0029] The environment mutual authentication module is used to perform local distributed environment mutual authentication operations;

[0030] The data computing module is used to perform data transfer operations with other external nodes that have successfully completed mutual authentication operations in their respective local distributed environments after the local distributed environment mutual authentication operation is successful, through its own trusted execution environment, so as to perform corresponding distributed computing operations based on the privacy computing task.

[0031] Thirdly, this application discloses an electronic device, including:

[0032] Memory, used to store computer programs;

[0033] A processor for executing the computer program to implement the aforementioned trusted privacy computing method.

[0034] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the aforementioned trusted privacy computing method.

[0035] As can be seen, this application first generates a privacy computing task and sends the privacy computing task to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules. The participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes. The node performs local trusted authentication operations on its own trusted execution environment using its pre-configured authentication module. It then performs local distributed environment mutual authentication operations, and after successful local distributed environment mutual authentication, it performs data flow operations with the other external nodes whose local distributed environment mutual authentication operations have been successfully completed, in order to execute corresponding distributed computing operations based on the privacy computing task. The local trusted authentication operation of any participating node includes authenticating its own trusted execution environment and broadcasting its environment information to the other participating nodes after successful authentication. The local distributed environment mutual authentication operation of any participating node is an operation that uses the environment information of its own trusted execution environment sent by the other participating nodes to authenticate the trusted execution environments of the other participating nodes. Therefore, this application performs local trusted authentication operations on its own trusted execution environment through its own authentication module, and performs mutual authentication operations on each external node based on the obtained environment information of each external node. In this way, the environment can be authenticated based on the authentication module of each node, realizing the authentication operation of decentralized heterogeneous environment. End-to-end encrypted data flow can be realized between the trusted execution environments of each participating node, ensuring that user data is not leaked. Furthermore, it does not restrict the type of trusted execution environment of the participating nodes, supports the interconnection and interoperability between trusted execution environments of various vendors, and makes practical applications more extensive and flexible. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0037] Figure 1 This is a flowchart of a trusted privacy computing method disclosed in this application;

[0038] Figure 2 This is a schematic diagram of the structure between several participating nodes disclosed in this application;

[0039] Figure 3 This application discloses a specific flowchart of a trusted privacy computing method.

[0040] Figure 4This application discloses a specific flowchart of a trusted privacy computing method.

[0041] Figure 5 This is a schematic diagram of the structure of a trusted privacy computing device disclosed in this application;

[0042] Figure 6 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0043] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0044] Currently, joint computation of data can be achieved through a distributed network of TEE nodes deployed across multiple institutions. However, current schemes for building distributed TEE node networks and for completing trusted authentication of distributed TEE nodes are generally centralized and auxiliary methods. Trusted authentication refers to the process where the initiating verification end sends a request to the remote task execution end, and the task execution end proves to the initiating verification end that it has not been modified compared to the target verification environment. The verified end is a trusted execution environment, and successful verification indicates the security of the computing environment and the integrity of the running code. Generally, a server from a remote vendor is required for auxiliary verification. Since mutual verification between different TEEs is required, different verification mechanisms of different TEEs are involved. If the system architecture is not modified, then each party's TEE module must integrate multiple sets of verification logic. On the one hand, this increases the engineering complexity of mutual verification; on the other hand, it is not conducive to the later maintenance of the system.

[0045] See Figure 1 As shown in the embodiment, this application discloses a trusted privacy computation method applied to a task initiation node, including:

[0046] Step S11: Generate a privacy computing task and send the privacy computing task to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environment using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes.

[0047] In this embodiment, a privacy computing task is generated based on the privacy computing platform in the task initiating node. This privacy computing task is then broadcast to other external nodes via the privacy computing platform, notifying them to execute the privacy computing task and begin performing local trusted authentication operations on their respective trusted execution environments using their pre-configured authentication modules. The privacy computing task includes all participating nodes in this task, including the task initiating node and several external nodes.

[0048] It should be noted that before generating and executing the privacy computing task, several participating nodes need to undergo corresponding initialization operations. These initialization operations include the initialization of some underlying cryptographic algorithms and security parameters. Furthermore, each trusted execution environment (TEE) is required to have a unique 256-bit ID, and key pairs are initialized internally when the TEE is created. See also... Figure 2 As shown, each participating node contains several components for trusted privacy computation, including but not limited to: a privacy computation platform, an interconnect agent (TEEC - Trusted Execution Environment Connect) agent, a host agent, a trusted execution environment, and an authentication module. The privacy computation platform is used for data scheduling and authorization, task scheduling, and business logic management among the participating nodes. The interconnect agent is responsible for distributing tasks to the interconnect agent. The interconnect agent is responsible for information synchronization between each node. The host agent is software deployed on a host with hardware TEE capabilities, assisting in task scheduling, execution, and result return. The trusted execution environment is a secure area constructed on the computing platform using hardware and software methods, ensuring the confidentiality and integrity of code and data loaded within the secure area, ensuring a task executes as expected, and guaranteeing the confidentiality and integrity of the initial and runtime states. The authentication module is responsible for initiating random challenges to the trusted execution environment, completing remote verification and environment mutual authentication operations, and the authentication module can communicate with remote authentication servers (RAs). The remote verification server communicates with the TEE vendor's remote verification server, which assists in remote verification operations for a specific TEE. It is understood that different TEE vendors have different remote verification servers, and the self-authentication modules of different participating nodes can communicate remotely with different TEE vendors. In addition, each node's trusted execution environment has a teec-net (TEE connection network), which is responsible for building a virtual network for communication between nodes, and the link encryption ensures the security of data flow.

[0049] It should be further noted that this solution can be adapted to TEE technologies from some mainstream manufacturers, such as those released by mainstream computing chip manufacturers like Hygon, Zhaoxin, Phytium, Kunpeng, Intel, AMD, and ARM. This allows for interconnection and joint computing between TEEs from different manufacturers, enabling the reuse of existing computing power. Furthermore, different manufacturers' TEE technology solutions can be flexibly selected according to the data flow scenario, leveraging the differentiated advantages of each solution.

[0050] Step S12: Use the pre-configured local authentication module to perform local trusted authentication on your own trusted execution environment.

[0051] In this embodiment, the task initiating node utilizes a pre-configured local authentication module to perform local trusted execution operations on its own Trusted Execution Environment (TEE). Specifically, the local trusted authentication operation of any participating node includes authenticating its own TEE and, upon successful authentication, broadcasting the environment information of its TEE to other participating nodes. It is understood that each participating node possesses its own authentication module, enabling local trusted authentication of its own TEE. Thus, by setting up an authentication module within the system, decentralized heterogeneous environment authentication operations can be achieved.

[0052] Step S13: Perform local distributed environment mutual authentication operation, and after the local distributed environment mutual authentication operation is successful, perform data transfer operation with other external nodes whose local distributed environment mutual authentication operations are successful through its own trusted execution environment, so as to perform corresponding distributed computing operations based on the privacy computing task.

[0053] In this embodiment, after the local trusted authentication operation (i.e., the self-authentication operation) is successfully executed, the task initiating node performs a local distributed environment mutual authentication operation. Following the successful local distributed environment mutual authentication, it then uses its own trusted execution environment to perform data transfer operations with other external nodes whose local distributed environment mutual authentication operations have also been successful, in order to execute corresponding distributed computing operations based on the privacy computing task. The local distributed environment mutual authentication operation of any participating node involves using the environment information of its own trusted execution environment sent by other participating nodes to authenticate the trusted execution environments of the other participating nodes. In this way, mutual authentication of the trusted execution environments of corresponding nodes can be performed using the environment information sent by each external node, ensuring the security of the trusted execution environments of the external nodes. This avoids relying on a separate remote verification proxy module to perform mutual verification of trusted execution environments from different vendors, making the environment authentication process more flexible.

[0054] In one specific embodiment, obtaining the data to be computed returned by each of the external nodes after successful mutual authentication in their respective local distributed environments, and computing the data to be computed in their own trusted execution environment, may include: synchronizing computation parameters with other external nodes that have successfully completed mutual authentication with their respective local distributed environments through their own trusted execution environment to perform data flow operations, so as to perform distributed joint encrypted computation based on the privacy computation task in the trusted execution environments of the corresponding participating nodes of the computation parameters. That is, after each of the external nodes successfully completes mutual authentication in its local distributed environment, an interconnection proxy assists in synchronizing several computation parameters required for the distributed joint encrypted computation between the trusted execution environments of several participating nodes to perform data flow operations. This allows distributed joint encrypted computation to be performed in the trusted execution environments of the several participating nodes corresponding to the several computation parameters. The distributed joint encrypted computation includes, but is not limited to, secure multi-party computation. In this way, initiating distributed joint encrypted computation can further improve the security of encrypted computation.

[0055] In another specific embodiment, obtaining the data to be computed returned by each of the external nodes after successful mutual authentication in their respective local distributed environments, and computing the data to be computed in its own trusted execution environment, may include: performing data transfer operations with other external nodes that have successfully completed mutual authentication in their respective local distributed environments through its own trusted execution environment to obtain encrypted data to be computed returned by each of the external nodes; decrypting the encrypted data to be computed in its own trusted execution environment; and then performing distributed joint plaintext computation on the decrypted data to be computed. That is, after each external node successfully completes its mutual authentication in its local distributed environment, it encrypts the node data corresponding to each external node using a randomly generated symmetric key, encrypts the symmetric key using the public key of the trusted execution environment of the task initiating node, and sends the encrypted symmetric key and the encrypted data to be computed to the task initiating node for data transfer operations. The process of decrypting, intersecting, and performing operations on the encrypted data to be computed within the trusted execution environment of the task initiating node is then performed to conduct the distributed joint plaintext computation, which can greatly improve computational efficiency. Understandably, after the computation is completed, the Trusted Execution Environment (TEE) only outputs the computation result to the outside world. The original data and the computation process data are destroyed on-site within the TEE. In this way, multi-party data joint modeling achieved through TEE technology can not only meet the business needs of multi-party data collaboration, but also fully protect the original data between parties as "usable but not visible". Moreover, compared with pure cryptographic computation schemes, TEE-based schemes have stronger performance and algorithm versatility. When TEE hardware is available, cryptographic strategies can choose better and more optimal methods to better balance performance and security, thereby achieving better results in scenarios with large-scale data or certain performance requirements.

[0056] As can be seen, this embodiment first generates a privacy computing task and sends the privacy computing task to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules. The participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes. The node performs local trusted authentication operations on its own trusted execution environment using its pre-configured authentication module. It then performs local distributed environment mutual authentication operations, and after successful local distributed environment mutual authentication, it performs data flow operations with the other external nodes whose local distributed environment mutual authentication operations have been successfully completed, in order to execute corresponding distributed computing operations based on the privacy computing task. The local trusted authentication operation of any participating node includes authenticating its own trusted execution environment and broadcasting its environment information to the other participating nodes after successful authentication. The local distributed environment mutual authentication operation of any participating node is an operation that uses the environment information of its own trusted execution environment sent by the other participating nodes to authenticate the trusted execution environments of the other participating nodes. Therefore, this embodiment performs local trusted authentication on its own trusted execution environment through its own authentication module, and performs mutual authentication on each external node based on the obtained environment information of each external node. In this way, the environment can be authenticated based on the authentication module of each node, realizing the authentication operation of decentralized heterogeneous environment. End-to-end encrypted data flow can be realized between the trusted execution environments of each participating node, ensuring that user data is not leaked. Furthermore, it does not restrict the type of trusted execution environment of the participating nodes, supports the interconnection and interoperability between trusted execution environments of various vendors, and makes practical applications more extensive and flexible.

[0057] As can be seen from the above embodiments, this application can perform self-authentication and mutual authentication operations on the trusted execution environment through its own authentication module. The self-authentication operation of each participating node will be described in detail below. See [link to documentation]. Figure 3 As shown in the figure, this application discloses a specific trusted privacy computation method applied to participating nodes, including:

[0058] Step S21: Create and start its own trusted execution environment, and use the automatic trusted execution environment to process the initial trusted authentication request initiated by its own host agent to generate the target trusted authentication request.

[0059] In this embodiment, after each participating node's own host agent obtains the privacy computing task from its own privacy computing platform through its own interconnect agent, it begins to execute the privacy computing task, that is, to create and start its own trusted execution environment. Upon receiving the privacy computing task, the trusted execution environment immediately pushes its own IP address (Internet Protocol Address) and MAC address (Media Access Control Address) to the host agent. The host agent stores the IP address of the trusted execution environment in the corresponding physical disk based on the MAC address. Then, the host agent sends an initial trusted authentication request carrying a TEEID (Trusted Execution Environment Serial Number) to the trusted execution environment. After receiving the initial trusted request, the trusted execution environment generates a target trusted authentication request based on the initial trusted request. The target trusted authentication request carries the trusted execution environment's local environment report, environment public key, and the TEEID. It is understandable that each participating node, whether it is the task initiating node or other external node, will perform the above operations after receiving the privacy computing task, laying the foundation for subsequent trusted authentication operations. Furthermore, each participating node has a different IP address, MAC address, TEEID, local environment report, and environment public key corresponding to its own trusted execution environment.

[0060] Step S22: Use the locally pre-configured authentication module to find the root certificate corresponding to the target trusted authentication request transmitted by its own trusted execution environment from the remote verification server; the remote verification server is a server deployed on the trusted execution environment provider's server.

[0061] In this embodiment, after the authentication module of each participating node obtains the target trusted authentication request sent by its own trusted execution environment, it sends a request to the remote verification server of the provider of its trusted execution environment to obtain the corresponding root certificate, so as to obtain the root certificate corresponding to the trusted execution environment.

[0062] Step S23: The authentication module uses the root certificate to remotely verify the local environment report within its trusted execution environment.

[0063] In this embodiment, the authentication module in the participating node uses the root certificate to verify the certificate chain and TEE metric value in the local environment report within its own trusted execution environment, so as to perform a remote verification operation to verify whether its own trusted execution environment is trustworthy.

[0064] Step S24: The authentication module returns the corresponding remote verification result to its own host agent, and the host agent synchronously sends the remote verification result to its own interconnect agent, so that its own interconnect agent can determine whether the remote verification operation is successful based on the remote verification result.

[0065] In this embodiment, the self-authentication module in the participating node returns the corresponding remote verification result to its own host agent. After receiving the remote verification result, the host agent synchronizes it to its own interconnect agent so that its own interconnect agent can determine whether the remote verification operation was successful based on the remote verification result.

[0066] In this embodiment, after the authentication module performs a remote verification operation on the local environment report within its trusted execution environment using the root certificate, it may further include: if the remote verification operation fails, the interconnect agent of the participating node uses the remote verification result to generate corresponding verification error information and sends it to the local privacy computing platform; the privacy computing task is a task generated by the privacy computing platform. That is, if the remote verification result indicates that the remote verification operation has failed, the interconnect agent of the participating node can use the remote verification result to generate corresponding verification error information and send it to the local privacy computing platform, wherein the verification error information includes, but is not limited to, "certificate chain verification failed" or "metric value verification failed".

[0067] Step S25: After the remote verification operation is successful, generate the corresponding trusted credentials and broadcast the corresponding environment information of its trusted execution environment to other participating nodes through its own interconnection agent.

[0068] In this embodiment, after the remote verification operation of the participating node's own trusted execution environment is successful, its own authentication module calculates the hash value of the environment public key and TEEID provided in the target trusted authentication request, and signs the hash value using the authentication module's private key. The resulting signature value is the trusted credential of its own trusted execution environment. The self-authentication module stores the trusted credential in the corresponding physical disk and associates it with the corresponding TEEID in the disk. After the above operations are completed, the self-interconnection proxy obtains the environment information of its own trusted execution environment through its own host proxy and broadcasts the environment information to other participating nodes to perform subsequent distributed environment mutual authentication operations. The environment information includes, but is not limited to, the environment public key, TEEID, trusted credential, and authentication module public key of the trusted execution environment.

[0069] Therefore, in this scheme, each participating node can remotely verify its own trusted execution environment based on its own authentication module and obtain the corresponding trusted credentials. This lays the foundation for subsequent distributed environment mutual authentication operations using trusted credentials. It can realize decentralized heterogeneous environment authentication and does not restrict the type of trusted execution environment among participating nodes. It supports the interconnection and interoperability between trusted execution environments from various vendors, making the trusted authentication process simpler and more convenient, and more widely and flexibly applicable in practical applications.

[0070] Based on the above facts, it is clear that each participating node can perform trusted authentication operations based on its own authentication module and obtain corresponding trusted credentials. The following section will describe in detail how trusted credentials are used to implement distributed environment mutual authentication operations between participating nodes. See also... Figure 4 As shown in the figure, this application discloses a specific trusted privacy computation method applied to participating nodes, including:

[0071] Step S31: Using the environment information of their own trusted execution environment sent by the other participating nodes, perform a signature verification operation on the trusted credentials corresponding to the trusted execution environments of the other participating nodes.

[0072] In this embodiment, after each participating node's interconnection proxy obtains the corresponding environment information of its trusted execution environment sent by other participating nodes, it first calculates the hash value of the TEEID and environment public key in the environment information. Then, it reads the content of the trusted credential in the environment information and uses the obtained authentication module public key to perform a signature verification operation on the trusted credential. The success of the signature verification operation is determined by judging whether the hash value calculated by itself is the same as the hash value corresponding to the trusted credential. If the signature verification operation of another participating node is successful, it indicates that the trusted execution environment in that participating node has completed the remote verification operation and that the trusted execution environment is trusted.

[0073] Step S32: If the verification operation of the trusted credentials of the other participating nodes is successful, then the current local distributed environment mutual authentication operation is successful.

[0074] In this embodiment, each participating node sequentially verifies the trusted credentials from several environmental information sets obtained through its interconnection. If the verification of trusted credentials for all other participating nodes is successful, the local distributed environment inter-authentication operation of that participating node is considered successful. It should be noted that while one participating node is performing local distributed environment inter-authentication, several other participating nodes are also performing their own local distributed environment inter-authentication operations. When all local distributed environment inter-authentication operations of each participating node are successfully executed, the inter-authentication operation between the distributed environments is completed.

[0075] As can be seen, in this scheme, each participating node can perform mutual authentication operations on the trusted execution environment of the corresponding node based on the received trusted credentials, without relying on an independent remote verification agent module to realize mutual authentication between trusted execution environments of different vendors. This achieves decentralized heterogeneous environment mutual authentication operations, ensuring that each trusted execution environment is trustworthy, and providing security for subsequent data flow and distributed joint computing processes.

[0076] refer to Figure 5 The present application also discloses a trusted privacy computing device, applied to a task initiation node, comprising:

[0077] The task generation module 11 is used to generate a privacy computing task and send the privacy computing task to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environment using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes.

[0078] Trusted authentication module 12 is used to perform local trusted authentication operations on its own trusted execution environment using a locally pre-configured authentication module;

[0079] Environment mutual authentication module 13 is used to perform local distributed environment mutual authentication operations;

[0080] Data computing module 14 is used to perform data transfer operations with other external nodes that have successfully completed mutual authentication operations in their respective local distributed environments through its own trusted execution environment, in order to perform corresponding distributed computing operations based on the privacy computing task.

[0081] As can be seen, this embodiment first generates a privacy computing task and sends the privacy computing task to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules. The participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes. The node performs local trusted authentication operations on its own trusted execution environment using its pre-configured authentication module. It then performs local distributed environment mutual authentication operations, and after successful local distributed environment mutual authentication, it performs data flow operations with the other external nodes whose local distributed environment mutual authentication operations have been successfully completed, in order to execute corresponding distributed computing operations based on the privacy computing task. The local trusted authentication operation of any participating node includes authenticating its own trusted execution environment and broadcasting its environment information to the other participating nodes after successful authentication. The local distributed environment mutual authentication operation of any participating node is an operation that uses the environment information of its own trusted execution environment sent by the other participating nodes to authenticate the trusted execution environments of the other participating nodes. Therefore, this embodiment performs local trusted authentication on its own trusted execution environment through its own authentication module, and performs mutual authentication on each external node based on the obtained environment information of each external node. In this way, the environment can be authenticated based on the authentication module of each node, realizing the authentication operation of decentralized heterogeneous environment. End-to-end encrypted data flow can be realized between the trusted execution environments of each participating node, ensuring that user data is not leaked. Furthermore, it does not restrict the type of trusted execution environment of the participating nodes, supports the interconnection and interoperability between trusted execution environments of various vendors, and makes practical applications more extensive and flexible.

[0082] In some specific embodiments, the trusted authentication module 12 may specifically include:

[0083] The root certificate acquisition unit is used to search for the root certificate corresponding to the target trusted authentication request transmitted by its own trusted execution environment from a remote verification server using a locally pre-configured authentication module; the remote verification server is a server deployed on the trusted execution environment provider's server.

[0084] The remote verification unit is used to perform remote verification of the local environment report within its own trusted execution environment using the root certificate through the authentication module.

[0085] The trusted credential generation unit is used to generate a corresponding trusted credential after the remote verification operation is successful, and to broadcast the corresponding environment information of its trusted execution environment to the other external nodes through its own interconnection agent.

[0086] In some specific embodiments, the trusted privacy computing device may further include:

[0087] The environment creation module is used to create and start its own trusted execution environment, and to use the automatic trusted execution environment to process the initial trusted authentication request initiated by its own host agent to generate the target trusted authentication request.

[0088] In some specific embodiments, the trusted privacy computing device may further include:

[0089] The result transmission module is used to return the corresponding remote verification result to its own host agent through the authentication module, and to synchronously send the remote verification result to its own interconnect agent through its own host agent, so that its own interconnect agent can determine whether the remote verification operation is successful based on the remote verification result.

[0090] In some specific embodiments, the trusted privacy computing device may further include:

[0091] An error message sending module is used to generate corresponding verification error information using the remote verification result through its own interconnection agent and send it to the local privacy computing platform if the remote verification operation fails; the privacy computing task is a task generated by the privacy computing platform.

[0092] In some specific embodiments, the environment inter-authentication module 13 may specifically include:

[0093] The credential verification unit is used to perform verification operations on the trusted credentials corresponding to the trusted execution environments of the other participating nodes by using the environment information of their own trusted execution environments sent by the other participating nodes.

[0094] The mutual authentication determination unit is used to determine that the current local distributed environment mutual authentication operation is successful if the signature verification operation for the trusted credentials of all other participating nodes is successful.

[0095] In some specific embodiments, the data calculation module 14 may specifically include:

[0096] The encrypted computation unit is used to synchronize computation parameters with other external nodes that have successfully completed mutual authentication operations between its own trusted execution environment and their respective local distributed environments, and to perform data flow operations, so as to perform distributed joint encrypted computation based on the privacy computation task in its own trusted execution environment in the corresponding participating nodes of the computation parameters.

[0097] The plaintext computation unit is used to perform data transfer operations on other external nodes that have successfully completed mutual authentication operations with their respective local distributed environments through its own trusted execution environment, in order to obtain the encrypted data to be computed returned by each external node, and to decrypt each of the encrypted data to be computed in its own trusted execution environment, and then perform distributed joint plaintext computation on each of the decrypted data to be computed.

[0098] Furthermore, embodiments of this application also disclose an electronic device, Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0099] Figure 6 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the trusted privacy computing method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0100] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0101] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0102] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including computer programs capable of performing the trusted privacy computing method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0103] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed trusted privacy computing method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0104] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0105] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0106] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0107] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0108] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A trusted privacy computation method, characterized in that, Applied to the task initiation node, including: A privacy computing task is generated and sent to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environment using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing task include the task initiating node and several external nodes; It utilizes a pre-configured local authentication module to perform local trusted authentication operations on its own trusted execution environment; Perform local distributed environment mutual authentication operation, and after the local distributed environment mutual authentication operation is successful, perform data transfer operation with other external nodes whose local distributed environment mutual authentication operations are successful through its own trusted execution environment, so as to perform corresponding distributed computing operations based on the privacy computing task. The local trusted authentication operation of any participating node includes authenticating its own trusted execution environment and broadcasting the environment information of its trusted execution environment to other participating nodes after successful authentication; the local distributed environment mutual authentication operation of any participating node is to authenticate the trusted execution environments of other participating nodes by using the environment information of its own trusted execution environment sent by other participating nodes. Specifically, the step of authenticating the trusted execution environments of other participating nodes using the environment information of their own trusted execution environments sent by the other participating nodes includes: using the environment information of their own trusted execution environments sent by the other participating nodes to perform a signature verification operation on the trusted credentials corresponding to the trusted execution environments of the other participating nodes; if the signature verification operation on the trusted credentials of the other participating nodes is successful, then the current local distributed environment mutual authentication operation is determined to be successful.

2. The trusted privacy computation method according to claim 1, characterized in that, The process of performing local trusted authentication on its own trusted execution environment using a pre-configured local authentication module includes: The system uses a pre-configured local authentication module to search for the root certificate corresponding to the target trusted authentication request transmitted by its own trusted execution environment from a remote verification server; the remote verification server is a server deployed on the trusted execution environment provider's server. The authentication module uses the root certificate to remotely verify the local environment report within its trusted execution environment. After the remote verification operation is successful, a corresponding trusted credential is generated, and the corresponding environment information of its trusted execution environment is broadcast to other external nodes through its own interconnection agent.

3. The trusted privacy computation method according to claim 2, characterized in that, Also includes: Create and start its own trusted execution environment, and use the automatic trusted execution environment to process the initial trusted authentication request initiated by its own host agent to generate the target trusted authentication request.

4. The trusted privacy computation method according to claim 2, characterized in that, After the authentication module performs remote verification of the local environment report within its trusted execution environment using the root certificate, the process further includes: The authentication module returns the corresponding remote verification result to its own host agent, and the host agent synchronously sends the remote verification result to its own interconnect agent, so that the interconnect agent can determine whether the remote verification operation was successful based on the remote verification result.

5. The trusted privacy computation method according to claim 4, characterized in that, After the authentication module performs remote verification of the local environment report within its trusted execution environment using the root certificate, the process further includes: If the remote verification operation fails, the system uses its own interconnection agent to generate corresponding verification error information based on the remote verification result and sends it to the local privacy computing platform; the privacy computing task is a task generated by the privacy computing platform.

6. The trusted privacy computation method according to any one of claims 1 to 5, characterized in that, The process of transferring data between other external nodes that have successfully completed mutual authentication between their trusted execution environment and their respective local distributed environments, in order to perform corresponding distributed computing operations based on the privacy computing task, includes: The external nodes that successfully perform mutual authentication operations with their own trusted execution environment and their respective local distributed environments synchronize the calculation parameters to perform data flow operations, so as to perform distributed joint ciphertext calculation based on the privacy calculation task in the trusted execution environment of the corresponding participating node of the calculation parameters. Alternatively, it can perform data transfer operations with other external nodes that have successfully completed mutual authentication between its own trusted execution environment and its respective local distributed environment, in order to obtain the encrypted data to be computed returned by each external node, and then decrypt each of the encrypted data to be computed in its own trusted execution environment, and then perform distributed joint plaintext computation on each of the decrypted data to be computed.

7. A trusted privacy computing device, characterized in that, Applied to the task initiation node, including: A task generation module is used to generate privacy computing tasks and send the privacy computing tasks to several external nodes to notify the other external nodes to perform local trusted authentication operations on their own trusted execution environments using their respective pre-configured authentication modules; the participating nodes corresponding to the privacy computing tasks include the task initiating node and several external nodes; The trusted authentication module is used to perform local trusted authentication operations on its own trusted execution environment using a locally pre-configured authentication module. The environment mutual authentication module is used to perform local distributed environment mutual authentication operations; The data computing module is used to perform data transfer operations with other external nodes that have successfully completed mutual authentication operations in their respective local distributed environments through its own trusted execution environment, in order to perform corresponding distributed computing operations based on the privacy computing task. Specifically, the environment mutual authentication module is used to use the environment information of its own trusted execution environment sent by the other participating nodes to perform signature verification operations on the trusted credentials corresponding to the trusted execution environments of the other participating nodes; if the signature verification operations on the trusted credentials of the other participating nodes are all successful, then the current local distributed environment mutual authentication operation is determined to be successful.

8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the trusted privacy computing method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the trusted privacy computing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Task scheduling method and system based on MapReduce mechanism

    CN102769615A

  • Cross-chain transaction verification method, relay chain node device and medium

    CN112532393A

  • Privacy computing system and method based on trusted execution environment

    CN115412275A