Trusted environment construction method, data transmission method and data processing system
By setting up a hardware trusted execution environment and management unit in the host and programmable hardware, the security problem on the programmable hardware side of the core processor-programmable hardware heterogeneous architecture is solved, and the secure transmission of data on the untrusted communication link and the secure startup of the trusted environment is achieved.
Patent Information
- Application Number
- CN202310252210.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-10
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2043-03-10
AI Technical Summary
In the prior art, in the core processor-programmable hardware heterogeneous architecture, the operating environment on the host side can only be guaranteed, the security on the programmable hardware side cannot be guaranteed, and the communication security between the host and the programmable hardware is insufficient, resulting in the trusted environment of the cloud service platform being unable to effectively protect user data.
Set up a hardware trusted execution environment in the host, obtain the encrypted hardware trusted management logic, and send it to programmable hardware, build a hardware trusted management unit and processing unit, and securely transmit data on an untrusted communication link through encryption logic, ensuring data security between the host and programmable hardware.
It realizes the security of a trusted environment without affecting the flexible and programmable characteristics of the cloud service platform, and ensures that the trusted environment is safely started and operated under the control of the trusted cloud, and safely transmits data on untrusted communication links.
Smart Images

Figure CN116361863B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and in particular to a method for establishing a trusted environment. One or more embodiments of this specification also relate to a data transmission method, a data processing system, a computing device, and a computer-readable storage medium. Background Art
[0002] With the continuous development of computer technology, the amount of data generated by enterprises and individual users has exploded, and the demand for computing power has also increased accordingly. Enterprises and individual users hand over the generated data to cloud service platforms for storage, computing, and other processing. Therefore, security is a key performance indicator of cloud platforms.
[0003] Currently, a cloud-based heterogeneous architecture with host-programmable hardware can be used to improve computing performance. However, this architecture only guarantees the security of the host-side operating environment. User data may be tampered with by untrusted attackers on other ends, thereby destroying the trusted environment of the cloud service platform and failing to guarantee the security of user data. Therefore, a highly secure trusted environment is urgently needed. Summary of the Invention
[0004] In view of this, embodiments of this specification provide a method for establishing a trusted environment. One or more embodiments of this specification also relate to a data transmission method, a data processing system, a computing device, a computer-readable storage medium, and a computer program to address technical deficiencies in the prior art.
[0005] According to the first aspect of the embodiments of this specification, a method for constructing a trusted environment is provided, including: setting a hardware trusted execution environment in a host; obtaining encrypted hardware trusted management logic from the hardware trusted execution environment; sending the encrypted hardware trusted management logic to programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to construct a hardware trusted management unit in the programmable hardware; sending hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware.
[0006] According to the second aspect of the embodiments of this specification, a trusted environment construction method is provided, which is applied to a hardware trusted execution environment, including: obtaining a hardware key corresponding to programmable hardware connected to a host; encrypting the hardware trusted management logic according to the hardware key to obtain encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware; sending the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware.
[0007] According to a third aspect of the embodiments of this specification, a data transmission method is provided, which is applied to a hardware trusted processing unit. The hardware trusted processing unit is constructed on programmable hardware using the method provided in the first or second aspect above. The data transmission method includes: obtaining encrypted data to be processed from a user trusted execution environment; using a pre-stored data transmission key to decrypt the encrypted data to be processed to obtain plaintext of the data to be processed; and processing the plaintext of the data to be processed.
[0008] According to the fourth aspect of the embodiments of this specification, a data processing system is provided, comprising: programmable hardware and a host, the programmable hardware comprising a hardware trusted management unit deployed using the method provided in the first or second aspect above and a hardware trusted processing unit deployed using the method provided in the first or second aspect above, the host comprising a hardware trusted execution environment as provided in the second aspect above.
[0009] According to the fifth aspect of the embodiments of this specification, a trusted environment construction device is provided, including: a first setting module, configured to set a hardware trusted execution environment in a host; a first acquisition module, configured to obtain encrypted hardware trusted management logic from the hardware trusted execution environment; a first sending module, configured to send the encrypted hardware trusted management logic to programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to construct a hardware trusted management unit in the programmable hardware; a second sending module, configured to send the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware.
[0010] According to the sixth aspect of the embodiments of this specification, a trusted environment construction device is provided, which is applied to a hardware trusted execution environment, including: a second acquisition module, configured to obtain a hardware key corresponding to the programmable hardware connected to the host; an encryption module, configured to encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware; a third sending module, configured to send the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware.
[0011] According to the seventh aspect of the embodiments of this specification, a data transmission device is provided, which is applied to a hardware trusted processing unit. The hardware trusted processing unit is constructed on programmable hardware using the method provided in the first or second aspect above. The data transmission device includes: a third acquisition module, configured to obtain encrypted data to be processed from a user trusted execution environment; a decryption module, configured to use a pre-stored data transmission key to decrypt the encrypted data to be processed to obtain the plaintext of the data to be processed; and a processing module, configured to process the plaintext of the data to be processed.
[0012] According to an eighth aspect of the embodiments of this specification, a computing device is provided, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method provided in the first aspect, the second aspect, or the third aspect above.
[0013] According to the ninth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions. When the instructions are executed by a processor, the steps of the method provided in the first aspect, the second aspect, or the third aspect are implemented.
[0014] According to a tenth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the method provided in the first aspect, the second aspect, or the third aspect above.
[0015] One embodiment of this specification provides a method for constructing a trusted environment, which includes setting a hardware trusted execution environment in a host; obtaining encrypted hardware trusted management logic from the hardware trusted execution environment; sending the encrypted hardware trusted management logic to programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to construct a hardware trusted management unit in the programmable hardware; and sending the hardware processing logic to the hardware trusted management unit via the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware. By setting the hardware trusted execution environment in the host and setting the hardware trusted management unit and hardware trusted processing unit in the programmable hardware, user logic and trusted startup-related logic are decoupled in the host and programmable hardware, which can efficiently extend the trusted environment from the host to the programmable hardware. At the same time, since both the host and the programmable hardware include trusted units, the trusted environment can be securely started and operated even when not under the control of the trusted cloud. In addition, encrypting the hardware trusted management logic allows data between the host and the programmable hardware to be securely transmitted over an untrusted communication link, thereby improving the security of the trusted environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is an architectural diagram of a data processing system provided by one embodiment of this specification;
[0017] Figure 2 This is a flow chart of a method for building a trusted environment provided by an embodiment of this specification;
[0018] Figure 3 This is a flowchart of another trusted environment construction method provided by an embodiment of this specification;
[0019] Figure 4 This is a flow chart of a data transmission method provided by one embodiment of this specification;
[0020] Figure 5 is a flowchart of another data transmission method provided by an embodiment of this specification;
[0021] Figure 6 This is a deployment flow chart of a trusted platform provided by an embodiment of this specification;
[0022] Figure 7 This is a deployment flow chart of another trusted platform provided by an embodiment of this specification;
[0023] Figure 8 This is a schematic diagram of the structure of a trusted environment construction device provided by an embodiment of this specification;
[0024] Figure 9 This is a schematic diagram of the structure of another trusted environment construction device provided by an embodiment of this specification;
[0025] Figure 10 This is a structural diagram of a data transmission device provided by an embodiment of this specification;
[0026] Figure 11 This is a structural block diagram of a computing device provided by one embodiment of this specification. DETAILED DESCRIPTION
[0027] The following description sets forth many specific details to facilitate a thorough understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0028] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a," "the," and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0029] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0030] First, the terms involved in one or more embodiments of this specification are explained.
[0031] Programmable hardware: Programmable hardware, also known as programmable logic devices, is the hardware carrier that implements the established functions and technical specifications of electronic application systems through electronic design automation (EDA). It features rich wiring resources, reprogrammability, and high integration. Programmable hardware includes but is not limited to field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), digital signal processors (DSPs), ARM (Advanced RICS) processors, programmable logic controllers (PLCs), and single-chip microcomputers.
[0032] Bitstream: A programming file that describes the hardware logic to be implemented on programmable hardware.
[0033] Encrypted Bitstream: A symmetric key is pre-burned into the programmable hardware. The Bitstream is encrypted with this key and can be written directly to the programmable hardware. The programmable hardware then uses the key to decrypt the ciphertext Bitstream and load it into the programmable hardware. The key and decryption process are transparent and cannot be tampered with.
[0034] Trusted Execution Environment: A Trusted Execution Environment (TEE) typically protects the code and data within it from being leaked or maliciously tampered with by providing a secure execution environment isolated from the outside world.
[0035] Dynamic reconfiguration: Dynamic Partial Reconfiguration (DPR) logically divides a piece of programmable hardware into several areas, each of which can independently reload the hardware logic without affecting other areas.
[0036] Remote Attestation: Remote attestation (RA) is also known as remote authentication or remote verification. The verifier initiates a request to verify that the remote application is running correctly on the secure platform. The prover generates an attestation report and sends it to the verifier for verification.
[0037] Local Attestation: Local Attestation (LA) is also known as local authentication or local verification. The prover proves to the verifier that it is running on the same secure platform as the verifier, such as two trusted execution environments authenticating that each other is running on the same core processor (CPU).
[0038] Programmable hardware DNA (Deoxyribonucleic acid), also known as programmable hardware identification (ID, Identity Document): It is used for programmable hardware identity identification. It is unique and is written into the programmable hardware chip by the programmable hardware server (such as the programmable hardware manufacturer) before leaving the factory. It cannot be modified by users.
[0039] Replay attacks, also known as replay attacks or playback attacks, occur when an attacker sends a packet that has already been received by the destination host in order to deceive the system. These attacks are primarily used during the authentication process to undermine authentication validity. Replay attacks can be carried out by the initiator or by an attacker who intercepts and retransmits the data.
[0040] As computing power demands increase, more and more services are adopting heterogeneous core processor-programmable hardware (such as CPU-FPGA) architectures to achieve improved computing performance, and users' demands for data security are also gradually increasing. Specifically, in a heterogeneous core processor-programmable hardware architecture, after a user applies for heterogeneous acceleration services, the cloud server deploys the corresponding application image to the host and simultaneously deploys the required programmable hardware logic to the programmable hardware.
[0041] However, the trusted execution environment for the core processor can only guarantee the security of the operating environment on the host side, and cannot guarantee the security and trustworthiness of the programmable hardware side. In addition, the security of the core processor-programmable hardware communication makes it impossible to extend the trusted boundary of the system from the core processor to the entire core processor-programmable hardware heterogeneous architecture. In the above-mentioned trusted execution environment, untrusted cloud service users or attackers can load malicious hardware logic into the programmable hardware, and the communication between the host and the programmable hardware may also be stolen or tampered with by attackers. On the other hand, since the resources on the cloud service side need to meet the characteristics of flexible programmability, allowing developers or programmable hardware kernel developers to deploy applications or hardware kernels on heterogeneous platforms, malicious attacks may occur in the cloud service side.
[0042] In order to solve the above problems, the embodiments of this specification provide a solution for building a trusted environment, which increases the security and trustworthiness without affecting the functions of the cloud core processor-programmable hardware heterogeneous architecture. Specifically, a hardware trusted execution environment is set in the host; encrypted hardware trusted management logic is obtained from the hardware trusted execution environment; the encrypted hardware trusted management logic is sent to the programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware; the hardware processing logic is sent to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware. By setting up a hardware trusted execution environment in the host and setting up a hardware trusted management unit and a hardware trusted processing unit in the programmable hardware, the user logic and trusted startup related logic are decoupled in the host and the programmable hardware, and the trusted environment can be efficiently extended from the host to the programmable hardware. At the same time, since both the host and the programmable hardware include trusted units, it is ensured that the trusted environment can still be safely started and run without being controlled by the trusted cloud. In addition, the hardware trusted management logic is encrypted, so that data between the host and programmable hardware can also be securely transmitted over an untrusted communication link. Through a secure and trusted cloud service heterogeneous platform, the security of the trusted environment is improved without sacrificing the flexible and programmable features of the cloud service platform.
[0043] In this specification, a method for building a trusted environment is provided. This specification also involves a data transmission method, a data processing system, a computing device, and a computer-readable storage medium, which are described in detail one by one in the following embodiments.
[0044] See also Figure 1 , Figure 1The following figure shows an architecture diagram of a data processing system provided by one embodiment of the present specification. The data processing system includes programmable hardware and a host (Host). The programmable hardware includes a hardware trusted management unit (SM, Secure Manager) and a hardware trusted processing unit (CL, Custom Logic). The host includes a hardware trusted execution environment.
[0045] A hardware trusted execution environment is used to obtain a hardware key corresponding to programmable hardware connected to a host; encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware; and send the hardware processing logic to the hardware trusted management unit;
[0046] A hardware trusted management unit is used to build a hardware trusted processing unit in programmable hardware using hardware processing logic.
[0047] The hardware trusted processing unit is used to obtain encrypted data to be processed from the user trusted execution environment; use the pre-stored data transmission key to decrypt the encrypted data to be processed to obtain the plaintext of the data to be processed; and process the plaintext of the data to be processed.
[0048] Furthermore, the data processing system may also include a user trusted execution environment, which is used to verify whether the hardware trusted execution environment is trustworthy.
[0049] It should be noted that if Figure 1 As shown in the figure, the programmable hardware includes three independent logic areas divided by dynamic reconfiguration. These three independent logic areas are the hardware trusted management unit, the hardware trusted processing unit and the hardware encapsulation unit (Shell). Among them, the hardware trusted management unit is responsible for key management, secure and trusted startup of programmable hardware, and remote authentication. Generally, the hardware trusted management unit is developed by the programmable hardware server. The hardware encapsulation unit is responsible for encapsulating the periphery of the programmable hardware. Generally, the hardware encapsulation unit is developed by the cloud service provider (CSP, Cloud Service Providers). The hardware trusted processing unit contains specific data processing logic, which is generally developed by developers. It is ensured that users can verify it through open source, or the certificate is disclosed to users through third-party certification. In actual applications, the role of the hardware trusted processing unit developer can also be assumed by the user. When the user develops, the hardware trusted processing unit does not need to be open source.
[0050] The user trusted execution environment in the host runs the user-oriented project logic code, which is developed by the developer and provides security assurance to the user through open source or third-party certification. The hardware trusted execution environment in the host is responsible for the secure and trusted startup of the programmable hardware. It can also remotely authenticate the hardware trusted management unit, hardware packaging unit and user trusted processing unit. It is generally developed by the programmable hardware server. In particular, in one or more schemes provided in the embodiments of this specification, for the core processor-programmable hardware heterogeneous system, the core processor and programmable hardware are considered to belong to two different hardware platforms, so the mutual authentication between the core processor and programmable hardware in the same system is classified as remote authentication.
[0051] By applying the solutions of the embodiments of this specification, the trusted boot logic and user logic are separated on the host side and the programmable hardware side, respectively, thereby decoupling the functions and ensuring the independent portability of trusted boot-related components, reducing the user's migration costs and enabling end-to-end migration of the trusted execution environment with minimal modifications. For the cloud server, only minimal modifications are required to the user logic to port the functions of the existing trusted execution environment for the core processor to the core processor-programmable hardware heterogeneous trusted execution environment, thereby leveraging the hardware acceleration capabilities of the programmable hardware on a secure and trustworthy basis.
[0052] See also Figure 2 , Figure 2 A flow chart of a method for establishing a trusted environment provided by an embodiment of this specification is shown, which specifically includes the following steps:
[0053] Step 202: Set up a hardware trusted execution environment in the host.
[0054] In one or more embodiments of this specification, in order to decouple user logic and trusted boot logic, a hardware trusted execution environment can be set in the host.
[0055] Specifically, the hardware trusted execution environment can be responsible for the secure and trusted startup of programmable hardware, and can also remotely authenticate the hardware trusted management unit, hardware packaging unit, and user trusted processing unit.
[0056] It should be noted that Figure 2 The trusted environment construction method shown can be executed by the cloud server or by other users, depending on the actual situation. The embodiment of this specification does not impose any limitation on this. The embodiment of this specification takes the cloud server as an example.
[0057] Step 204: Obtain the encrypted hardware trusted management logic from the hardware trusted execution environment.
[0058] In one or more embodiments of the present specification, after a hardware trusted execution environment is set in a host, an encrypted hardware trusted management environment may be further obtained from the hardware trusted execution environment.
[0059] Specifically, the hardware trusted management logic (SM bitstream) refers to the programming file used to start the hardware trusted management unit and ensure the trustworthiness of the hardware trusted management unit. The hardware trusted management logic can be a public programming file or a private programming file, depending on the actual situation. This specification does not impose any restrictions on this. The encrypted hardware trusted management logic (ciphertext bitstream) refers to the programming file obtained by encrypting the hardware trusted management logic using a hardware key (keydevice) in the hardware trusted execution environment.
[0060] Step 206: Send the encrypted hardware trusted management logic to the programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware.
[0061] In one or more embodiments of this specification, a hardware trusted execution environment is set in the host, and after obtaining the encrypted hardware trusted management logic from the hardware trusted execution environment, the encrypted hardware trusted management logic can be further sent to the programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware.
[0062] Specifically, the programmable hardware and the host can be connected via a communication link, thereby achieving data transmission between the core processor and the programmable hardware.
[0063] It should be noted that there are many ways to build a hardware trusted management unit in programmable hardware using encrypted hardware trusted management logic. The specific selection should be made according to the actual situation. The embodiments of this specification do not impose any restrictions on this.
[0064] In one possible implementation of this specification, a hardware trusted management unit can be built using an ARM hard core. The firmware code in this ARM hard core is securely protected. Specifically, the cloud server initializes the ARM core, reads the hardware trusted management unit core based on the firmware code, and deploys it on programmable hardware.
[0065] In another possible implementation of this specification, the key management hardware circuit in the programmable hardware can be used to construct the hardware trusted management unit. Specifically, the cloud service end transmits the encrypted hardware trusted management logic to the programmable hardware through the specific interface of the programmable hardware. Inside the programmable hardware, the programmable hardware decryption unit decrypts the encrypted hardware trusted management logic and deploys the decrypted hardware trusted management logic to the hardware trusted management area, completing the construction of the hardware trusted management unit. The decryption process is not visible to the outside world.
[0066] Step 208: Send the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0067] In one or more embodiments of the present specification, a hardware trusted execution environment is set in the host, and encrypted hardware trusted management logic is obtained from the hardware trusted execution environment. After the encrypted hardware trusted management logic is sent to the programmable hardware connected to the host, the hardware processing logic can be further sent to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0068] Specifically, the hardware processing logic (CLbitstream) refers to the user-defined programming file used to deploy the hardware processing unit. When the cloud server sends the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, the hardware processing logic can be unencrypted. If the hardware processing logic is tampered with during transmission, the report generated by the hardware management unit based on the hardware processing logic will be different from the report file corresponding to the hardware processing logic on the user side.
[0069] It should be noted that after the cloud service sends the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, the hardware trusted management unit can calculate a summary of the hardware processing logic and store it in the hardware execution report. Furthermore, the hardware trusted management unit deploys the hardware processing logic to the hardware trusted processing area through the dynamic configuration interface (DRP, Dynamic Reconfiguration Port) interface to complete the construction of the hardware trusted processing unit.
[0070] By applying the solution of the embodiments of this specification, a hardware trusted execution environment is set in the host; encrypted hardware trusted management logic is obtained from the hardware trusted execution environment; the encrypted hardware trusted management logic is sent to the programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware; the hardware processing logic is sent to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware. By setting up the hardware trusted execution environment in the host and setting up the hardware trusted management unit and hardware trusted processing unit in the programmable hardware, the user logic and trusted startup-related logic in the host and programmable hardware are decoupled, and the trusted environment can be efficiently extended from the host to the programmable hardware, achieving end-to-end migration of the trusted execution environment. At the same time, since both the host and the programmable hardware include trusted units, the trusted environment can be securely started and run even when not under the control of the trusted cloud. In addition, the hardware trusted management logic is encrypted, so that data between the host and the programmable hardware can also be securely transmitted over an untrusted communication link, thereby improving the security of the trusted environment.
[0071] In an optional embodiment of the present specification, since the hardware trusted execution environment needs to use a hardware key to encrypt the hardware trusted management logic, the hardware trusted execution environment needs to obtain the hardware key. That is, before setting the hardware trusted execution environment in the host, the following steps may also be included:
[0072] Get the hardware identification of the programmable hardware connected to the host;
[0073] The hardware identification is sent to the host, so that the hardware trusted execution environment obtains the hardware key according to the hardware identification.
[0074] Specifically, hardware identifiers such as FPGA DNA (FPGA Deoxyribonucleic acid) are used for programmable hardware identity identification and are unique.
[0075] It should be noted that there are multiple ways to obtain the hardware identification of the programmable hardware connected to the host, and the specific selection should be made according to the actual situation. The embodiments of this specification do not impose any limitation on this.
[0076] In a possible implementation of this specification, the hardware identification sent by the trusted user can be directly received.
[0077] In another possible implementation of this specification, the hardware identification can be read through the identification reading interface of the programmable hardware, that is, the identification reading interface of the programmable hardware is found, the host and the programmable hardware are connected through the identification reading interface, and the hardware identification of the programmable hardware is viewed in the host.
[0078] In practice, before programmable hardware leaves the factory, the programmable hardware server generates a symmetric hardware key for each piece of programmable hardware. The hardware key is then embedded in the programmable hardware, and the programmable hardware server maintains a mapping table between hardware identifiers and hardware keys. Therefore, when the hardware trusted execution environment obtains the hardware key based on the hardware identifier, it can send the hardware identifier to the programmable hardware server, which then searches the mapping table for the hardware key corresponding to the hardware identifier.
[0079] By applying the solution of the embodiments of this specification, the hardware identification of the programmable hardware connected to the host is obtained; the hardware identification is sent to the host, so that the hardware trusted execution environment obtains the hardware key based on the hardware identification, and further enables the hardware trusted execution environment to encrypt the hardware trusted management logic based on the hardware key, thereby preventing the hardware trusted management logic from being attacked and tampered with, and ensuring the security of the hardware trusted management logic.
[0080] In an optional embodiment of this specification, the above-mentioned trusted environment construction method may further include the following steps:
[0081] A user trusted execution environment is set in the host, so that the user trusted execution environment verifies whether the hardware trusted execution environment is trustworthy.
[0082] Specifically, the user can send a remote authentication request to the user trusted execution environment to verify whether the user trusted execution environment is trustworthy, thereby ensuring that the user programming files have not been tampered with or attacked. If the user trusted execution environment is trustworthy, the user trusted execution environment can further verify whether the hardware trusted execution environment is trustworthy, while also ensuring the security of the host environment.
[0083] It should be noted that trusted execution environments running on different core processors use different keys and cannot authenticate each other. Therefore, the user trusted execution environment can determine whether the user trusted execution environment and the hardware trusted execution environment are running on a core processor with a trusted execution environment through local verification. If they are running on the same core processor, the data will not be leaked and the hardware trusted execution environment is trustworthy. If they are not running on the same core processor, the hardware trusted execution environment is untrustworthy. The specific verification method is determined by the trusted execution environment technology of each programmable hardware server.
[0084] By applying the solution of the embodiments of this specification, a user trusted execution environment is set in the host, so that the user trusted execution environment verifies whether the hardware trusted execution environment is trustworthy, thereby ensuring the security and credibility of the host side.
[0085] In an optional embodiment of this specification, the above-mentioned trusted environment construction method may further include the following steps:
[0086] The hardware encapsulation logic is sent to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware encapsulation logic to build a hardware encapsulation unit in the programmable hardware.
[0087] Specifically, the hardware encapsulation logic (Shellbitstream) is a plaintext programming file used to deploy the hardware encapsulation unit. Since the peripherals of programmable hardware (such as external memory and external network ports) need to interact with other devices, to ensure the security of programmable hardware, the hardware encapsulation unit can encapsulate the peripherals of the programmable hardware to prevent malicious hardware processing units from physically damaging the programmable hardware. At the same time, the hardware encapsulation unit can abstract the interfaces of the peripheral devices for use by the hardware trusted processing unit.
[0088] By applying the solution of the embodiments of this specification, the hardware encapsulation logic is sent to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware encapsulation logic to build a hardware encapsulation unit in the programmable hardware, thereby ensuring the security of the programmable hardware.
[0089] See also Figure 3 , Figure 3 A flowchart of another trusted environment construction method provided by an embodiment of this specification is shown. The trusted environment construction method is applied to a hardware trusted execution environment and specifically includes the following steps:
[0090] Step 302: Obtain a hardware key corresponding to the programmable hardware connected to the host.
[0091] In one or more embodiments of this specification, to build a highly secure trusted environment, user logic and trusted boot logic in programmable hardware can be decoupled, and a hardware trusted management unit and a hardware trusted processing unit can be built within the programmable hardware. Because the hardware trusted management unit can be built based on the hardware trusted management logic, to ensure the security and trustworthiness of the hardware trusted management unit, the hardware trusted execution environment can obtain a hardware key corresponding to the programmable hardware connected to the host and use the hardware key to encrypt the hardware trusted management logic.
[0092] In actual applications, there are many ways to obtain the hardware key corresponding to the programmable hardware connected to the host. The specific method is selected according to the actual situation. The embodiments of this specification do not impose any restrictions on this. In one possible implementation of this specification, a pre-stored hardware key can be read from the host according to the hardware identifier. In another possible implementation of this specification, the hardware identifier can be sent to the programmable hardware server, and the programmable hardware server can search the hardware key corresponding to the hardware identifier in the mapping table.
[0093] Step 304: Encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware.
[0094] In one or more embodiments of this specification, after the hardware trusted execution environment obtains the hardware key corresponding to the programmable hardware connected to the host, it can further encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic.
[0095] It should be noted that the hardware trusted execution environment encrypts the hardware trusted management logic. After obtaining the encrypted hardware trusted management logic, the cloud service end can obtain the encrypted hardware trusted management logic and send the encrypted hardware trusted management logic to the programmable hardware connected to the host, so that the programmable hardware can use the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware.
[0096] Step 306: Send the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0097] In one or more embodiments of the present specification, the hardware trusted execution environment obtains a hardware key corresponding to the programmable hardware connected to the host to encrypt the hardware trusted management logic according to the hardware key. After obtaining the encrypted hardware trusted management logic, the hardware processing logic can be sent to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0098] In actual applications, the hardware trusted management unit can calculate a summary of the hardware processing logic and store it in the hardware execution report. Furthermore, the hardware trusted management unit deploys the hardware processing logic to the hardware trusted processing area through the dynamic configuration interface to complete the construction of the hardware trusted processing unit.
[0099] Apply the solution of the embodiment of this specification to obtain the hardware key corresponding to the programmable hardware connected to the host; encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to build a hardware trusted management unit in the programmable hardware; send the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware. By setting the hardware trusted management unit and the hardware trusted processing unit in the programmable hardware, the user logic and the trusted startup related logic are decoupled in the programmable hardware. At the same time, since both the host and the programmable hardware include trusted units, it is ensured that the trusted environment can still be safely started and run without the control of the trusted cloud. In addition, the hardware trusted management logic is encrypted so that data can be securely transmitted on an untrusted communication link, thereby improving the security of the trusted environment.
[0100] In an optional embodiment of the present specification, in order to ensure that the hardware key is not leaked and is accurately sent to the hardware trusted execution environment, the programmable hardware end can remotely authenticate the trusted execution environment. That is, the above-mentioned acquisition of the hardware key corresponding to the programmable hardware connected to the host may include the following steps:
[0101] Sending the hardware identification of the programmable hardware to the programmable hardware end, so that the programmable hardware end remotely authenticates the hardware trusted execution environment;
[0102] When the remote authentication is successful, a hardware key is obtained from the programmable hardware end, wherein the hardware key is obtained by the programmable hardware end by querying a preset mapping table according to the hardware identifier, and the preset mapping table includes a correspondence between the hardware identifier and the hardware key.
[0103] For example, assuming that the preset mapping table includes mapping identifiers 001, 002, and 003, the hardware key corresponding to mapping identifier 001 is 111, the hardware key corresponding to mapping identifier 002 is 222, and the hardware key corresponding to mapping identifier 003 is 333. After the programmable hardware end obtains the hardware identifier 002, it searches the preset mapping table for the hardware key corresponding to the hardware identifier 002 and finds the hardware key 222, and sends the hardware key 222 to the hardware trusted execution environment.
[0104] Using the solutions of the embodiments of this specification, the hardware identification of the programmable hardware is sent to the programmable hardware terminal, allowing the programmable hardware terminal to remotely authenticate the hardware trusted execution environment. If remote authentication is successful, the programmable hardware terminal obtains a hardware key. The hardware key is obtained by the programmable hardware terminal by querying a preset mapping table based on the hardware identification. The preset mapping table includes the correspondence between hardware identifications and hardware keys. By remotely authenticating the hardware trusted execution environment, the security of the hardware key is guaranteed, further ensuring the security of the encrypted hardware trusted management logic.
[0105] In an optional embodiment of the present specification, in order to ensure that the hardware trusted management unit is loaded normally and thus accurately construct the hardware trusted processing unit, after encrypting the hardware trusted management logic according to the hardware key and obtaining the encrypted hardware trusted management logic, the following steps may also be included:
[0106] When the hardware trusted management unit is built, remote authentication of the hardware trusted management unit is performed;
[0107] When the remote authentication is successful, the symmetric key is negotiated with the hardware trusted management unit, so that the hardware trusted management unit generates an encrypted hardware execution report using the symmetric key.
[0108] It should be noted that there are many ways of remote authentication, which can be selected based on actual conditions, and the embodiments of this specification do not impose any restrictions on this. In one possible implementation of this specification, remote authentication can be performed through the summary returned by the trusted execution environment. Since the hardware trusted processing unit and the hardware trusted management unit are both in programmable hardware, the hardware trusted management unit will encrypt the implanted information to be authenticated and return it to the hardware trusted execution environment. Only the hardware trusted execution environment knows the authentication information and key, and the hardware trusted execution environment only needs to decrypt it with its own key, and then verify the authentication information. Specifically, after starting the hardware trusted execution environment, the ARM firmware code can calculate the summary of the hardware trusted management unit and return it to the host to detect the correctness of the summary. In another possible implementation of this specification, remote authentication can be performed using unclonable function (PUF, Physical Unclonable Function) technology.
[0109] Furthermore, when remote authentication is successful, the hardware trusted execution environment and the hardware trusted management unit can negotiate a symmetric key (keyattest) through a secure channel. The hardware trusted management unit can use the symmetric key to encrypt the hardware execution report it generates, and the hardware trusted execution environment can use the symmetric key to decrypt the encrypted hardware execution report, so that the hardware execution report is only visible to the hardware trusted management unit and the hardware trusted execution environment, thereby ensuring the security of the hardware execution report.
[0110] Using the solution of the embodiments of this specification, after the hardware trusted management unit is constructed, the hardware trusted management unit is remotely authenticated. If remote authentication is successful, a symmetric key is negotiated with the hardware trusted management unit, and the hardware trusted management unit uses the symmetric key to generate an encrypted hardware execution report. This ensures that the hardware trusted management unit loads properly, thereby accurately constructing the hardware trusted processing unit and ensuring the security of the hardware execution report.
[0111] In an optional embodiment of the present specification, after the trusted environment is constructed, a trusted environment construction report may be generated and fed back to the user, allowing the user to determine the trustworthiness of the trusted environment based on the trusted environment construction report. That is, after the hardware processing logic is sent to the hardware trusted management unit, the following steps may also be included:
[0112] When the hardware trusted processing unit is built, an encrypted hardware execution report is obtained from the hardware trusted management unit;
[0113] decrypting the encrypted hardware execution report using the symmetric key to generate a programmable hardware report;
[0114] The hardware environment report and the programmable hardware report of the hardware trusted execution environment are sent to the user trusted execution environment, so that the user trusted execution environment generates a trusted environment construction report by using the hardware environment report and the programmable hardware report.
[0115] In actual applications, the hardware trusted management unit generates a hardware execution report and encrypts it before returning it to the hardware trusted execution environment. After the hardware trusted execution environment decrypts and verifies the encrypted hardware execution report, it generates a hardware environment report containing the hardware trusted execution environment itself and the programmable hardware report of the programmable hardware side, and returns the hardware environment report and the programmable hardware report to the user trusted execution environment. The user trusted execution environment integrates the received hardware environment report, programmable hardware report, and the user environment report of the user trusted execution environment itself, and returns it to the user. In summary, the report received on the user side includes the user trusted execution environment, the hardware trusted execution environment, the hardware trusted management unit, and the hardware trusted processing unit.
[0116] It should be noted that since the hardware packaging unit is developed by the cloud server and is unreliable, the report does not include the hardware packaging unit.
[0117] Furthermore, the user can compare the trusted environment construction report with a pre-stored report to determine whether the hardware trusted processing unit is trustworthy. If it is not trustworthy, the user can return to rebuild the trusted environment.
[0118] Applying the solution of the embodiments of this specification, after the hardware trusted processing unit is constructed, an encrypted hardware execution report is obtained from the hardware trusted management unit; the encrypted hardware execution report is decrypted using a symmetric key to generate a programmable hardware report; the hardware environment report and programmable hardware report of the hardware trusted execution environment are sent to the user trusted execution environment, which then uses the hardware environment report and programmable hardware report to generate a trusted environment construction report. Through the trusted environment construction report, the entire deployment and remote authentication process of the trusted environment are transparent to the user, and secure trusted startup requires minimal code modifications to the user trusted execution environment and the hardware trusted processing unit. The user can then determine the trustworthiness of the trusted environment based on the trusted environment construction report.
[0119] In the embodiments of this specification, since the core processor-programmable hardware trusted heterogeneous platform is running, data transmission needs to be communicated via a high-speed serial computer expansion bus (PCIe, Peripheral Component Interconnect Express) that is not managed by a trusted operating system. Therefore, in order to ensure end-to-end trust during platform operation, it is necessary to ensure that the core processor-programmable hardware data transmission is encrypted, tamper-proof, and anti-replay attack. Figure 4 , Figure 4 A flowchart of a data transmission method provided by an embodiment of this specification is shown, which is applied to a hardware trusted processing unit and specifically includes the following steps:
[0120] Step 402: Obtain encrypted data to be processed from the user trusted execution environment.
[0121] Step 404: Decrypt the encrypted data to be processed using the pre-stored data transmission key to obtain the plain text of the data to be processed.
[0122] Step 406: Process the plaintext data to be processed.
[0123] In one or more embodiments of this specification, after the user trusted execution environment and the hardware trusted processing unit are trustedly deployed, the user trusted execution environment and the hardware trusted processing unit can negotiate a data transmission key through a key negotiation mechanism and store the data transmission key and a verification value in their respective memories. After obtaining the data to be processed, the user trusted execution environment can use the data transmission key to encrypt the data to be processed. After the hardware trusted processing unit obtains the encrypted data to be processed from the user trusted execution environment, it can use the pre-stored data transmission key to decrypt the encrypted data to be processed, obtain the plaintext of the data to be processed, and further process the plaintext of the data to be processed.
[0124] It should be noted that, since the hardware trusted processing unit is trusted, the key agreement mechanism used by the user trusted execution environment and the hardware trusted processing unit can be immune to attacks from other attackers.
[0125] Using the solutions of the embodiments of this specification, encrypted data to be processed is obtained from a user trusted execution environment; the encrypted data to be processed is decrypted using a pre-stored data transmission key to obtain the plaintext data to be processed; and the plaintext data to be processed is processed. Because data transmission between the core processor and the programmable hardware during runtime requires communication via a high-speed serial computer expansion bus that is not managed by the trusted operating system, in order to ensure end-to-end trust during the trusted platform runtime, secure communication between the user trusted execution environment and the hardware trusted processing unit is used to ensure that data transmission between the core processor and the programmable hardware is encrypted, tamper-proof, and protected against replay attacks.
[0126] In the embodiments of the present specification, since the encrypted data to be processed may be tampered with when transmitted in an untrusted high-speed serial computer expansion bus communication, in the embodiments of the present specification, when the user trusted execution environment and the hardware trusted processing unit negotiate the data transmission key through the key negotiation mechanism, they can also negotiate a verification value, which can be a random number (counter). After the data transmission key and the verification value are obtained through negotiation, the user trusted execution environment and the hardware trusted processing unit can store the data transmission key and the verification value in the memory respectively.
[0127] Furthermore, after obtaining the data to be processed, the user trusted execution environment can concatenate the data to be processed and the check value to obtain updated data to be processed, encrypt the updated data to be processed using the data transmission key, and transmit the updated data to the hardware trusted processing unit via the untrusted high-speed serial computer expansion bus. At the same time, the user trusted execution environment automatically increments the stored check value by a preset value. The hardware trusted processing unit can use the check value to determine whether the data transmission is secure. That is, before processing the plaintext of the data to be processed, the following steps can also be included:
[0128] Extracting a plaintext check value from the plaintext of the data to be processed;
[0129] When the difference between the plaintext check value and the pre-stored check value is equal to a preset value, the data transmission is determined to be secure;
[0130] If the difference between the plain text check value and the pre-stored check value is not equal to a preset value, determining that the data transmission is abnormal;
[0131] Process the plain text of the data to be processed, including:
[0132] Under the condition of data transmission security, run the plain text of the data to be processed;
[0133] In the case of abnormal data transmission, it is determined that the plain text of the data to be processed is erroneous.
[0134] Specifically, the plaintext check value is the check value stored in the user's trusted execution environment, and the pre-stored check value is the check value stored in the hardware trusted processing unit. The hardware trusted processing unit compares the plaintext check value with the pre-stored check value stored in itself to determine whether the difference between the plaintext check value and the pre-stored check value is equal to a preset value. If it is not equal to the preset value, it indicates that the data transmission is abnormal and is a replay attack. The hardware trusted processing unit reports the detection of the attack. If it is equal to the preset value, it indicates that the data transmission is secure. The hardware trusted processing unit receives the plaintext data to be processed and increments the check value stored in the hardware trusted processing unit by the preset value.
[0135] It should be noted that Figure 4 The process of securely transmitting data from the user trusted execution environment to the hardware trusted processing unit is shown. Figure 4 The reverse process shown is the same.
[0136] Using the solution of the embodiments of this specification, a plaintext check value is extracted from the plaintext data to be processed. If the difference between the plaintext check value and the pre-stored check value is equal to a preset value, the data transmission is determined to be secure and the plaintext data to be processed is executed. If the difference between the plaintext check value and the pre-stored check value is not equal to the preset value, the data transmission is determined to be abnormal and the plaintext data to be processed is determined to be erroneous. This ensures that data transmission between the core processor and the programmable hardware is encrypted, preventing tampering and replay attacks.
[0137] See also Figure 5 , Figure 5 FIG. 1 shows a flow chart of another data transmission method provided by an embodiment of this specification. Figure 5As shown, after the user trusted execution environment and the hardware trusted processing unit are trustedly deployed, they first negotiate a key and a check value through a specified key agreement mechanism. These keys are then stored in memory. The user trusted execution environment concatenates the data (data) and the check value (counterMem) using a processing function (Concat) and encrypts (Encrypt) them with the key (keyMem) to obtain the data to be processed. The processed data is then transmitted to the hardware trusted processing unit in the programmable hardware via the high-speed serial computer expansion bus controller (PCIe controller) in the untrusted operating system (UntrustedOS). Simultaneously, the user trusted execution environment increments the stored check value. The hardware trusted processing unit decrypts the ciphertext using the key (Decrypt) and compares the plaintext check value with its own stored check value. The difference between the plaintext check value and the currently stored check value is determined. If the difference is not 1, the transmission is a replay attack, and the hardware trusted processing unit reports the detection of the attack. If it is 1, the transmission is secure, and the hardware trusted processing unit receives the plaintext and increments the stored check value.
[0138] By applying the solution of the embodiments of this specification, a secure communication mechanism is designed in combination with a trusted startup process to address the vulnerability of the channel between the core processor and the programmable hardware to attacks, thereby ensuring that the core processor and the programmable hardware can securely transmit data on a communication link controlled by an untrusted cloud server.
[0139] See also Figure 6 , Figure 6 FIG1 shows a deployment flow chart of a trusted platform provided by an embodiment of this specification. Figure 6 As shown, the programmable hardware includes a hardware trusted management unit, a hardware trusted processing unit and a hardware encapsulation unit. The host includes a hardware trusted execution environment and a user trusted execution environment. The user can perform two-way data exchange with the user trusted execution environment. The user trusted execution environment can perform two-way data exchange with the hardware trusted execution environment. The hardware trusted execution environment and the hardware trusted management unit can perform two-way data exchange. The hardware trusted management unit can send data to the hardware encapsulation unit and the hardware trusted processing unit. The hardware trusted execution environment can perform data exchange with the programmable hardware server, and the programmable hardware server can embed the hardware identifier into the programmable hardware. The cloud server (cloud service provider) can deploy the user trusted execution environment developed by the developer and the hardware trusted execution environment developed by the programmable hardware server to the host. The cloud server can perform two-way data exchange with the hardware trusted execution environment, and can also send data to the programmable hardware and the hardware trusted management unit.
[0140] See also Figure 7 , Figure 7The following is a flow chart showing another trusted platform deployment process provided by an embodiment of this specification. Specifically, it includes the following steps:
[0141] Step 702: Before the programmable hardware leaves the factory, the programmable hardware server generates a hardware key for each piece of programmable hardware, embeds the hardware key into the programmable hardware, and maintains a mapping table between the hardware identifier and the hardware key.
[0142] Step 704: After the cloud core processor-programmable hardware heterogeneous trusted environment instance (trusted platform) is started, the cloud server reads the hardware identification through the identification reading interface.
[0143] Step 706: The cloud server transmits the hardware identifier to the host side; and sets the user trusted execution environment and the hardware trusted execution environment in the host.
[0144] Step 708: The user initiates a remote authentication request to the user trusted execution environment.
[0145] Step 710: The user trusted execution environment confirms through local verification whether the hardware trusted execution environment and the user trusted execution environment are running on the same core processor.
[0146] Step 712: The hardware trusted execution environment sends the hardware identification to the programmable hardware server and requests the hardware key corresponding to the hardware identification.
[0147] Step 714: After remotely verifying the hardware trusted execution environment, the programmable hardware server queries the hardware key.
[0148] Step 716: The programmable hardware server sends the hardware key to the hardware trusted execution environment.
[0149] Step 718: After obtaining the public hardware trusted management logic, the hardware trusted execution environment encrypts the hardware trusted management logic using the hardware key to obtain the encrypted hardware trusted management logic.
[0150] Step 720: The cloud service end obtains the encrypted hardware trusted management logic from the hardware trusted execution environment.
[0151] Step 722: The cloud service sends the encrypted hardware trusted management logic to the programmable hardware connected to the host.
[0152] Step 724: The programmable hardware utilizes the encrypted hardware trusted management logic to construct a hardware trusted management unit in the programmable hardware.
[0153] Step 726: The hardware trusted execution environment remotely authenticates the hardware trusted management unit to ensure that the hardware trusted management unit is correctly loaded.
[0154] Step 728: The cloud server sends the hardware encapsulation logic to the hardware trusted management unit through the hardware trusted execution environment.
[0155] Step 730: The hardware trusted management unit uses the hardware encapsulation logic to construct a hardware encapsulation unit in the programmable hardware.
[0156] Step 732: The cloud server sends the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment.
[0157] Step 734: The hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0158] Step 736: The hardware trusted management unit generates and encrypts a hardware execution report.
[0159] Step 738: The hardware trusted management unit returns the encrypted hardware execution report to the hardware trusted execution environment.
[0160] Step 740: The hardware trusted execution environment decrypts and verifies the encrypted hardware execution report to generate a programmable hardware report.
[0161] Step 742: The hardware trusted execution environment sends the hardware environment report and the programmable hardware report of the hardware trusted execution environment to the user trusted execution environment.
[0162] Step 744: The user trusted execution environment integrates the received hardware environment report, programmable hardware report, and its own user environment report to generate a trusted environment construction report.
[0163] Step 746: The user trusted execution environment returns the trusted environment construction report to the user.
[0164] By applying the solution of the embodiments of this specification, the four roles of cloud service end, developer, user, and programmable hardware service end jointly build a core processor-programmable hardware end-to-end heterogeneous trusted execution environment, which is compatible with all programmable hardware architectures and core processor architectures, that is, it is compatible with whether the programmable hardware side contains an ARM hard core, what kind of core processor trusted execution environment technology the host uses on the server side, and is also compatible with various core processors and programmable hardware trusted startup and remote verification methods. By decoupling the secure and trusted startup mechanism and user logic on the host side and the programmable hardware side respectively, the trusted startup mechanism is made independent and portable, with little intrusion on user logic, and only a small amount of logic modification is required. While ensuring security and trustworthiness, it can still meet the flexible and programmable characteristics of cloud-based heterogeneous platforms. Both the host side and the programmable hardware side can be open to developers, further ensuring that data transmission at runtime is secure and reliable end-to-end, and can prevent theft, tampering, and replay attacks.
[0165] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0166] Corresponding to the above method embodiment, this specification also provides a trusted environment construction device embodiment, Figure 8 FIG1 shows a schematic diagram of a structure of a trusted environment construction device provided by an embodiment of this specification. Figure 8 As shown, the device includes:
[0167] A first setting module 802 is configured to set a hardware trusted execution environment in the host;
[0168] A first acquisition module 804 is configured to obtain the encrypted hardware trusted management logic from the hardware trusted execution environment;
[0169] A first sending module 806 is configured to send the encrypted hardware trusted management logic to the programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware;
[0170] The second sending module 808 is configured to send the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware.
[0171] Optionally, the device further includes: a fourth acquisition module configured to acquire a hardware identification of programmable hardware connected to the host; and send the hardware identification to the host, so that the hardware trusted execution environment acquires a hardware key according to the hardware identification.
[0172] Optionally, the apparatus further includes: a second setting module configured to set a user trusted execution environment in the host, so that the user trusted execution environment verifies whether the hardware trusted execution environment is trustworthy.
[0173] Optionally, the device further includes: a fourth sending module configured to send the hardware encapsulation logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware encapsulation logic to construct a hardware encapsulation unit in the programmable hardware.
[0174] Using the solutions of the embodiments of this specification, a hardware trusted execution environment is set up in the host; encrypted hardware trusted management logic is obtained from the hardware trusted execution environment; the encrypted hardware trusted management logic is sent to programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware; the hardware processing logic is sent to the hardware trusted management unit via the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware. By setting up the hardware trusted execution environment in the host, end-to-end migration of the trusted execution environment is achieved. The hardware trusted management unit and the hardware trusted processing unit are set up in the programmable hardware to decouple user logic and trusted startup-related logic in the host and programmable hardware, which can efficiently extend the trusted environment from the host to the programmable hardware. At the same time, because both the host and the programmable hardware include trusted units, the trusted environment can still be securely started and operated even when not under the control of the trusted cloud. In addition, the hardware trusted management logic is encrypted, so that data between the host and the programmable hardware can also be securely transmitted over an untrusted communication link, thereby improving the security of the trusted environment.
[0175] The above is a schematic diagram of a trusted environment construction device according to this embodiment. It should be noted that the technical solution of the trusted environment construction device and the technical solution of the trusted environment construction method described above are based on the same concept. For details not described in detail in the technical solution of the trusted environment construction device, please refer to the description of the technical solution of the trusted environment construction method described above.
[0176] Corresponding to the above method embodiment, this specification also provides a trusted environment construction device embodiment, Figure 9 FIG. 1 shows a schematic diagram of another trusted environment construction device provided by an embodiment of this specification. Figure 9 As shown, the device includes:
[0177] A second acquisition module 902 is configured to acquire a hardware key corresponding to the programmable hardware connected to the host;
[0178] an encryption module 904 configured to encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware;
[0179] The third sending module 906 is configured to send the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware.
[0180] Optionally, the second acquisition module 902 is further configured to send the hardware identification of the programmable hardware to the programmable hardware end, so that the programmable hardware end remotely authenticates the hardware trusted execution environment; if the remote authentication is successful, the hardware key is obtained from the programmable hardware end, wherein the hardware key is obtained by the programmable hardware end by querying the preset mapping table according to the hardware identification, and the preset mapping table includes the correspondence between the hardware identification and the hardware key.
[0181] Optionally, the device also includes: a first authentication module, configured to remotely authenticate the hardware trusted management unit when the hardware trusted management unit is constructed; if the remote authentication is successful, negotiate a symmetric key with the hardware trusted management unit so that the hardware trusted management unit uses the symmetric key to generate an encrypted hardware execution report.
[0182] Optionally, the device also includes: a generation module, configured to obtain an encrypted hardware execution report from the hardware trusted management unit when the hardware trusted processing unit is constructed; decrypt the encrypted hardware execution report using a symmetric key to generate a programmable hardware report; and send the hardware environment report and the programmable hardware report of the hardware trusted execution environment to the user trusted execution environment, so that the user trusted execution environment uses the hardware environment report and the programmable hardware report to generate a trusted environment construction report.
[0183] Apply the solution of the embodiment of this specification to obtain the hardware key corresponding to the programmable hardware connected to the host; encrypt the hardware trusted management logic according to the hardware key to obtain the encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to build a hardware trusted management unit in the programmable hardware; send the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to build a hardware trusted processing unit in the programmable hardware. By setting the hardware trusted management unit and the hardware trusted processing unit in the programmable hardware, the user logic and the trusted startup related logic are decoupled in the programmable hardware. At the same time, since both the host and the programmable hardware include trusted units, it is ensured that the trusted environment can still be safely started and run without the control of the trusted cloud. In addition, the hardware trusted management logic is encrypted so that data can be securely transmitted on an untrusted communication link, thereby improving the security of the trusted environment.
[0184] The above is a schematic diagram of a trusted environment construction device according to this embodiment. It should be noted that the technical solution of the trusted environment construction device and the technical solution of the trusted environment construction method described above are based on the same concept. For details not described in detail in the technical solution of the trusted environment construction device, please refer to the description of the technical solution of the trusted environment construction method described above.
[0185] Corresponding to the above method embodiment, this specification also provides a data transmission device embodiment, Figure 10 FIG1 shows a schematic diagram of the structure of a data transmission device provided by an embodiment of this specification. Figure 10 As shown, the device includes:
[0186] A third acquisition module 1002 is configured to obtain encrypted data to be processed from the user trusted execution environment;
[0187] The decryption module 1004 is configured to decrypt the encrypted data to be processed using a pre-stored data transmission key to obtain the plaintext of the data to be processed;
[0188] The processing module 1006 is configured to process the plaintext data to be processed.
[0189] Optionally, the apparatus further comprises: an extraction module configured to extract a plaintext check value from the plaintext of the data to be processed; if the difference between the plaintext check value and the pre-stored check value is equal to a preset value, determine that the data transmission is secure; if the difference between the plaintext check value and the pre-stored check value is not equal to the preset value, determine that the data transmission is abnormal;
[0190] Optionally, the processing module 1006 is further configured to run the plaintext of the data to be processed when data transmission is secure; and determine that the plaintext of the data to be processed is wrong when data transmission is abnormal.
[0191] Using the solutions of the embodiments of this specification, encrypted data to be processed is obtained from a user trusted execution environment; the encrypted data to be processed is decrypted using a pre-stored data transmission key to obtain the plaintext data to be processed; and the plaintext data to be processed is processed. Because data transmission during CPU-FPGA operation requires communication via a high-speed serial computer expansion bus (PCIe, Peripheral Component Interconnect Express) that is not managed by a trusted operating system, in order to ensure end-to-end trust during trusted platform operation, secure communication between the user trusted execution environment and the hardware trusted processing unit is used to ensure CPU-FPGA data transmission encryption, tamper resistance, and protection against replay attacks.
[0192] The above is a schematic scheme of a data transmission device of this embodiment. It should be noted that the technical scheme of the data transmission device and the technical scheme of the above-mentioned data transmission method are of the same concept. For details not described in detail in the technical scheme of the data transmission device, please refer to the description of the technical scheme of the above-mentioned data transmission method.
[0193] Figure 1111 is a block diagram of a computing device according to an embodiment of the present disclosure. Components of the computing device 1100 include, but are not limited to, a memory 1110 and a processor 1120. The processor 1120 is connected to the memory 1110 via a bus 1130, and a database 1150 is used to store data.
[0194] The computing device 1100 also includes an access device 1140 that enables the computing device 1100 to communicate via one or more networks 1160. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 1140 may include one or more of any type of network interface (e.g., a network interface card (NIC)) whether wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a world interoperability for microwave access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC) interface, and the like.
[0195] In one embodiment of the present specification, the above components of the computing device 1100 and Figure 11 Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 11 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0196] Computing device 1100 may be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook computer, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). Computing device 1100 may also be a mobile or stationary server.
[0197] The processor 1120 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-mentioned trusted environment construction method or data transmission method.
[0198] The above is a schematic diagram of a computing device according to this embodiment. It should be noted that the technical solution of this computing device is based on the same concept as the technical solutions of the above-mentioned trusted environment establishment method and data transmission method. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solutions of the above-mentioned trusted environment establishment method or data transmission method.
[0199] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned trusted environment construction method or data transmission method.
[0200] The above is a schematic diagram of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium is based on the same concept as the technical solutions of the above-mentioned trusted environment establishment method and data transmission method. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solutions of the above-mentioned trusted environment establishment method or data transmission method.
[0201] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned trusted environment construction method or data transmission method.
[0202] The above is an illustrative solution of a computer program according to this embodiment. It should be noted that the technical solution of this computer program is based on the same concept as the technical solutions of the above-mentioned trusted environment establishment method and data transmission method. For details not described in detail in the technical solution of the computer program, please refer to the description of the technical solution of the above-mentioned trusted environment establishment method or data transmission method.
[0203] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0204] The computer instructions include computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunications signal, and a software distribution medium.
[0205] It should be noted that for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0206] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0207] The preferred embodiments disclosed above are intended only to help illustrate this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made based on the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A method for establishing a trusted environment, comprising: Set up a hardware trusted execution environment in the host; Obtaining encrypted hardware trusted management logic from the hardware trusted execution environment; Sending the encrypted hardware trusted management logic to programmable hardware connected to the host, so that the programmable hardware uses the encrypted hardware trusted management logic to build a hardware trusted management unit in the programmable hardware; Remotely authenticate the hardware trusted management unit through the hardware trusted execution environment to ensure that the hardware trusted management unit is correctly loaded; Sending the hardware processing logic to the hardware trusted management unit through the hardware trusted execution environment, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware and uses the hardware encapsulation logic to construct a hardware encapsulation unit in the programmable hardware; The hardware trusted management unit calculates a summary of the hardware processing logic and stores it in a hardware execution report, and deploys the hardware processing logic to a hardware trusted processing area through a dynamic configuration interface to construct a hardware trusted processing unit; It also includes: decoupling the user logic and trusted startup logic in the programmable hardware, building a hardware trusted management unit and a hardware trusted processing unit in the programmable hardware, the hardware trusted execution environment obtaining the hardware key corresponding to the programmable hardware connected to the host, using the hardware key to encrypt the hardware trusted management logic, and obtaining the encrypted hardware trusted management logic, so that the cloud service end obtains the encrypted hardware trusted management logic.
2. The method according to claim 1, before setting the hardware trusted execution environment in the host, further comprising: Obtaining a hardware identifier of programmable hardware connected to the host; The hardware identification is sent to the host, so that the hardware trusted execution environment obtains the hardware key according to the hardware identification.
3. The method according to claim 1, further comprising: A user trusted execution environment is set in the host, and the user trusted execution environment is used to verify whether the hardware trusted execution environment is trustworthy.
4. A trusted environment construction method, applied to a hardware trusted execution environment, comprising: Obtaining a hardware key corresponding to the programmable hardware connected to the host; Encrypting the hardware trusted management logic according to the hardware key to obtain encrypted hardware trusted management logic, wherein the encrypted hardware trusted management logic is used to construct a hardware trusted management unit in the programmable hardware; Remotely authenticate the hardware trusted management unit to ensure that the hardware trusted management unit is loaded correctly; Sending the hardware processing logic to the hardware trusted management unit, so that the hardware trusted management unit uses the hardware processing logic to construct a hardware trusted processing unit in the programmable hardware and uses the hardware encapsulation logic to construct a hardware encapsulation unit in the programmable hardware; wherein the hardware trusted management unit calculates a summary of the hardware processing logic and stores it in a hardware execution report, and deploys the hardware processing logic to a hardware trusted processing area through a dynamic configuration interface to construct the hardware trusted processing unit; It also includes: decoupling the user logic and trusted startup logic in the programmable hardware, building a hardware trusted management unit and a hardware trusted processing unit in the programmable hardware, the hardware trusted execution environment obtaining the hardware key corresponding to the programmable hardware connected to the host, using the hardware key to encrypt the hardware trusted management logic, and obtaining the encrypted hardware trusted management logic, so that the cloud service end obtains the encrypted hardware trusted management logic.
5. The method according to claim 4, wherein obtaining a hardware key corresponding to programmable hardware connected to the host comprises: Sending the hardware identification of the programmable hardware to the programmable hardware terminal, so that the programmable hardware terminal remotely authenticates the hardware trusted execution environment; When the remote authentication is successful, a hardware key is obtained from the programmable hardware end, wherein the hardware key is obtained by the programmable hardware end by querying a preset mapping table according to the hardware identifier, and the preset mapping table includes a correspondence between the hardware identifier and the hardware key.
6. The method according to claim 4, further comprising: When the remote authentication of the hardware trusted management unit is successful, a symmetric key is negotiated with the hardware trusted management unit, so that the hardware trusted management unit generates an encrypted hardware execution report using the symmetric key.
7. The method according to claim 4 or 6, further comprising: after sending the hardware processing logic to the hardware trusted management unit: When the hardware trusted processing unit is constructed, obtaining an encrypted hardware execution report from the hardware trusted management unit; decrypting the encrypted hardware execution report using a symmetric key to generate a programmable hardware report; The hardware environment report of the hardware trusted execution environment and the programmable hardware report are sent to the user trusted execution environment, so that the user trusted execution environment generates a trusted environment construction report by using the hardware environment report and the programmable hardware report.
8. A data transmission method, applied to a hardware trusted processing unit, wherein the hardware trusted processing unit is constructed on programmable hardware using the method according to any one of claims 1 to 7, the method comprising: Obtaining encrypted data to be processed from the user's trusted execution environment; Decrypting the encrypted data to be processed using a pre-stored data transmission key to obtain the plaintext of the data to be processed; The plaintext of the data to be processed is processed.
9. The method according to claim 8, before processing the plaintext data to be processed, further comprising: Extracting a plaintext check value from the plaintext of the data to be processed; If the difference between the plaintext check value and the pre-stored check value is equal to a preset value, determining that the data transmission is secure; If the difference between the plaintext check value and the pre-stored check value is not equal to the preset value, determining that the data transmission is abnormal; The processing of the plaintext of the data to be processed includes: Under the condition that the data transmission is secure, executing the plaintext of the data to be processed; In the case where the data transmission is abnormal, it is determined that the plaintext of the data to be processed is erroneous.
10. A data processing system comprising: Programmable hardware and a host, the programmable hardware including a hardware trusted management unit deployed by the method described in any one of claims 1 to 7 and a hardware trusted processing unit deployed by the method described in any one of claims 1 to 7, and the host including a hardware trusted execution environment described in any one of claims 4 to 7.
11. The data processing system according to claim 10, further comprising: A user trusted execution environment is used to verify whether the hardware trusted execution environment is trustworthy.
12. A computing device comprising: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the method described in any one of claims 1 to 3 or any one of claims 4 to 7 or any one of claims 8 to 9 are implemented.
13. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method described in any one of claims 1 to 3, any one of claims 4 to 7, or any one of claims 8 to 9.
Citation Information
Patent Citations
Task processing method and device based on trusted execution environment, equipment and medium
CN111460429A
Privacy protection multi-party computing method and system based on trusted execution environment
CN111563261A