A trusted cloud computing system

By integrating a trusted cloud computing module into the cloud computing system, secure and reliable measurement and encryption of devices and data can be achieved, solving the problem of users' uncertainty about the security of cloud computing systems and improving system security and user trust.

CN117176390BActive Publication Date: 2026-03-31WUHAN TRUSTED CLOUD TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-28
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

The security of current cloud computing systems is unclear, and users cannot be sure of the security of computing resources and data, leading to a lack of trust.

Method used

By introducing a trusted cloud computing system, integrating trusted computing modules, trusted cloud network security computing modules, trusted cloud confidentiality computing modules, and trusted cloud measurement computing modules, the security and trustworthiness level of devices and data is determined through security and trustworthiness measurement, encryption processing, and unified quantitative calculation.

Benefits of technology

It improves users' ability to verify the security and trustworthiness of computing resources and data, enhances the overall security of cloud computing systems, enables users to clearly understand the security level of the resources and data they use, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117176390B_ABST
    Figure CN117176390B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a trusted cloud computing system; the trusted cloud computing system integrates a trusted cloud mechanism module in all devices in the trusted cloud computing system; the trusted cloud mechanism module at least comprises a trusted cloud measurement calculation module, which is used for performing unified evaluation, calculation and hierarchical processing on each device according to a trusted firmware measurement result of each device in the trusted cloud computing system, and obtaining a security and trust verification level of each device. In the scheme provided by the present application, the security and trust measurement of all devices in the trusted cloud computing system is uniformly managed by the trusted cloud mechanism module, the user clearly knows the security and trust verification level of the computing resources, cloud services and data used by the user, so that the security level of various resources in the trusted cloud computing system can be perceived by the user, and the use experience of the user is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud computing technology, and more specifically to a trusted cloud computing system. Background Technology

[0002] Cloud computing is a service-oriented model based on the Internet that provides users with a wealth of shared services through on-demand service and metered pricing.

[0003] However, because current cloud computing systems provide services based on shared computing resources, users cannot be certain whether the computing resources they use, the cloud services they receive, and their own data are secure, resulting in a lack of information about cloud computing systems.

[0004] In other words, current cloud computing systems have technical issues with unclear security. Summary of the Invention

[0005] To alleviate the technical problem of unclear security in current cloud computing systems, embodiments of the present invention provide a trusted cloud computing system.

[0006] This invention provides a trusted cloud computing system, which includes a trusted cloud mechanism module integrated into all devices within the system; the trusted cloud mechanism module includes:

[0007] The trusted computing module is used to perform security and trust measurement processing on the device and obtain the trust measurement results of the device.

[0008] The Trusted Cloud Security Computing Module is used to perform secure and trusted encryption processing on the transmission protocols of all end-to-end connections.

[0009] The Trusted Cloud Confidential Computing Module is used to perform encrypted, secure, and trusted processing of all data input and output.

[0010] The Trusted Cloud Measurement Calculation Module is used to determine the security and trustworthiness verification level of each device based on the trustworthiness measurement results of each device.

[0011] In some embodiments, the trusted cloud metric calculation module is further configured to: subdivide the trusted cloud computing system into multiple multi-layer trusted cloud units according to the device functions of each device.

[0012] In some embodiments, the Trusted Cloud Measurement Calculation Module is specifically used to: perform unified quantitative calculation and classification of the security and trust fuzzy concepts of all multi-layered Trusted Cloud Units.

[0013] In some embodiments, the trusted cloud measurement and calculation module is specifically used to: determine the device security and trust level of the device according to a preset device security and trust level standard; and determine the data security level of the data according to the data privacy standard.

[0014] In some embodiments, the Trusted Cloud Measurement Calculation Module is used to: sort the device security and trust levels of all devices in each multi-layer Trusted Cloud Unit, and determine the device security and trust level of the device with the lowest device security and trust level as the security and trust verification level of the corresponding Trusted Multi-layer Trusted Cloud Unit.

[0015] In some embodiments, the multi-layer trusted cloud unit includes a device component unit, a security isolation unit, and a cloud infrastructure integration unit; the trusted cloud metric calculation module is further configured to determine the link security and trust verification level of the data link based on the security and trust verification levels of the device component unit, security isolation unit, and cloud infrastructure integration unit between end-to-end in the data link.

[0016] In some embodiments, the trusted cloud metric calculation module is used to determine the lowest security and trusted verification level among the device component units, security isolation units, and cloud facility integration units between end-to-end in the data link as the end-to-end link security and trusted verification level in the data link.

[0017] In some embodiments, the trusted cloud metric calculation module is further configured to: determine the link of the data link and the data security level of the target data according to the data request, and determine whether the link security trusted verification level is within the range of the data security level; if so, allow the cloud server to respond to the service operation corresponding to the data request; if not, refuse the cloud server to respond to the service operation corresponding to the data request.

[0018] In some embodiments, each device is equipped with a security and trust metric level certificate provided by a trusted cloud device vendor. The trusted cloud mechanism module also includes a certificate management module for unified management of the access certificates of the interfaces of each device.

[0019] In some embodiments, the trusted cloud mechanism module further includes a request management module, which controls the cloud server to respond to the zero-trust access request based on the security control level of the zero-trust access request and the security and trust verification level of the cloud service entry point.

[0020] Compared with the prior art, one or more embodiments of the present invention can bring at least the following beneficial effects:

[0021] This invention provides a trusted cloud computing system. The trusted cloud mechanism module within this system includes: a trusted computing module for performing security and trust measurement processing on devices to obtain the device's trust measurement results; a trusted cloud network security computing module for performing encrypted security and trust processing on the transmission protocols of all end-to-end connections in the trusted cloud computing system; a trusted cloud confidentiality computing module for performing encrypted security and trust processing on the input and output of all data in the trusted cloud computing system; and a trusted cloud measurement computing module for performing unified evaluation, calculation, and classification processing on each device based on the trusted software measurement results of each device in the trusted cloud computing system to obtain the security and trust verification level of each device. In the solution provided by this invention, the trusted cloud mechanism module performs unified management of security and trust measurement on all devices within the trusted cloud computing system. This allows users to clearly understand the security and trust verification levels of the computing resources, cloud services, and data they use, making the security levels of various resources in the trusted cloud computing system perceptible to users and improving the user experience. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a network diagram of a trusted cloud computing system provided in an embodiment of the present invention;

[0024] Figure 2 This is another network diagram of the trusted cloud computing system provided in the embodiments of the present invention. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0026] The technical principles involved in this invention will now be explained.

[0027] This invention provides a cloud computing system that supports a new trusted cloud security computing mechanism (hereinafter referred to as a trusted cloud computing system to distinguish it from current cloud computing systems), aiming to solve the security and trust issues of cloud computing. This invention provides a unified, complete, feasible, standard, open, and hard-integrated general roadmap for trusted cloud security computing technology, aiming to improve the overall security and trust verification level of cloud computing systems, protect the shared isolation security and trust of higher security level data, and solidify the foundation for the industrialization of cloud computing security.

[0028] The technical solution provided by this invention comprehensively considers the key issues of cloud computing security and trustworthiness, and proposes a systematic solution. By implementing these technologies, the security and trustworthiness of cloud computing systems can be improved, providing users with more secure and reliable cloud computing services, and promoting the industrialization and widespread application of cloud computing security technologies.

[0029] To address the security and trust issues of current cloud computing systems, the present invention provides the following specific technical solution: In a first aspect, the present invention provides a trusted cloud security computing mechanism for the operation of a trusted cloud computing system.

[0030] In this trusted cloud security computing mechanism, all devices within the trusted cloud computing system are subdivided into multi-layered trusted cloud units based on their functions, and a unified and quantifiable trusted cloud security metrics management method is provided. The trusted cloud security computing mechanism is the core concept, definition, and implementation of this invention. To specifically implement the trusted cloud metrics computing model and unify the metrics, this invention defines security and trust verification levels, and under the definition of multi-layered trusted cloud units, it extends from component unit computing to devices, facilities, and services. These concepts and mechanisms constitute a complete system and are the main inventive content of this invention.

[0031] like Figure 1 As shown, the trusted cloud computing system with a trusted cloud security computing mechanism provided by this invention, hereinafter also referred to as the trusted cloud computing system, integrates a trusted cloud mechanism module (this module is used to implement the trusted cloud mechanism, hence it is also referred to as the trusted cloud mechanism below) in all its internal devices. This module, after being hardened, fused, and integrated, forms a unified trusted cloud security computing system (i.e., the trusted cloud computing system provided by this invention) with conventional terminal devices, access devices, cloud servers, etc. Wherein:

[0032] The Trusted Computing (TPM) module is used to measure the security and trustworthiness of all devices in a trusted cloud computing system, and obtain the trust measurement results of each device, including the trust measurement of software firmware, key protection, and private key identity binding authentication.

[0033] The Trusted Cloud Security Computing (OpenSSL) module is used to encrypt the transmission protocols of all end-to-end data link connections, ensuring the security and trustworthiness of data transmission.

[0034] The OpenCryptoki / Chaps module is used to encrypt all data inputs and outputs, ensuring data security and trustworthiness.

[0035] The Trusted Cloud Metrics Calculation (TDx) module is used to evaluate, calculate, and classify all multi-layered trusted cloud units through a unified and quantified security metric, so as to determine the security and trustworthiness verification level of each device in all multi-layered trusted cloud units based on the trustworthiness metric results of each device in the trusted cloud computing system.

[0036] In this invention, the Trusted Cloud Metrics Computing (TDx) module can subdivide the trusted cloud computing system into multiple multi-layered trusted cloud units based on the device functions of each device in the trusted cloud computing system. Multiple units refer to computer device component units such as servers / network devices / storage devices, cloud implementation integration units, and isolation mechanism security units, etc. Multi-layered units refer to the fact that within the same multi-layered trusted cloud unit, the multi-layered trusted cloud unit includes, from bottom to top, components such as trusted computing chips, motherboards, operating systems, virtual environments, and trusted cloud device component units. Each component unit has a device security and trust level. For example, each trusted computing chip has a unique and definite security and trust level. Similarly, each different operating system also has a corresponding security and trust level.

[0037] The trusted cloud security computing mechanism provided by this invention aims to enhance the trustworthiness, confidentiality, and integrity of computer systems and cloud computing environments, and is a comprehensive integration of information security technologies. Through four secure computing modules—trusted computing, trusted network security, trusted confidentiality, and trusted measurement—it provides complete trustworthiness and security for trusted cloud computing systems, achieving the goal of shared isolation level security units.

[0038] A unified and quantified trusted cloud security metrics management model is an important component of a trusted cloud computing system. It is used to quantify, evaluate, calculate, and classify the security and trustworthiness of multi-layer trusted cloud units, and to perform unified quantitative calculations and classifications of the fuzzy concepts of security and trustworthiness of all multi-layer trusted cloud units, providing a unified security metric standard for the entire trusted cloud computing system.

[0039] In a trusted cloud computing system, a unified and quantitative trusted cloud security metrics management model includes management of security levels, trusted verification levels, and trusted cloud metric calculations. Among these:

[0040] Security levels include equipment security and trust level and data security level.

[0041] The device security and trust level is determined by the Trusted Cloud Measurement and Computing Module based on preset device security and trust level standards such as security chips, security devices, network security, the Cybersecurity Classified Protection 2.0 system, international FIPS 140-2, and related standards and specifications. This device security and trust level is divided into five levels, from SL5 to SL1, where SL5 represents the highest security level and SL1 represents the lowest.

[0042] Data security levels are subdivided based on criteria such as the degree of data confidentiality, and are represented using DSL (Data Security Level). For example, Top Secret corresponds to DSL5, Confidential to DSL4, Secret to DSL3, Internal Public to DSL2, and External Public to DSL1. By setting different data security levels, data can be classified and managed according to confidentiality requirements.

[0043] In the above description, the specific implementation of trusted cloud metric computation can be a general hash metric or a more advanced signature verification. Hash metrics can only guarantee integrity, while signature authentication can also ensure uniqueness and non-repudiation, offering a higher level of trust. This invention prioritizes the implementation of trusted verification levels, followed by trusted metric levels. This is the overall implementation principle. In general, the corresponding embodiments of this invention do not distinguish between trusted metrics or verification.

[0044] Trust verification level is an important parameter in a trusted cloud computing system, used to determine the trustworthiness of a security unit and its administrative access rights to data. The following explains the definition and application of trust verification level:

[0045] Trusted Degree (TDz) refers to the security operation level that enables management operations on data DSLx with the same security level. The subscript z indicates different independent units and shared isolation units; for example, TDtpm represents the trusted verification level of a TPM chip, and TDtc represents the trusted verification level of a trusted cloud shared isolation unit.

[0046] The Data Security Level (DSLx) is the highest security level of the data that this invention needs to protect. In a trusted cloud computing system, the Trusted Authentication Level (TDz) must be greater than or equal to the security level (DSLx) of the target data, i.e., TDz ≥ DSLx. This means that only when the Trusted Authentication Level of a security unit meets or exceeds the security level of specific data can that data and its application be placed in the environment of that security unit.

[0047] For example, if a user places data with a security level of DSLx and related applications in a security unit with a trusted verification level of TDz, is the data secure? In this regard, the overall trust measure of any cloud service in a trusted cloud computing system is composed of each security unit. Only when the trusted verification level of each security unit meets the condition TDz≥DSLx can the security and trustworthiness of the trusted cloud service be ensured.

[0048] In this invention, the Trusted Authentication Level (TDz) is used to determine whether an access operation to data falls within the set security operation level range. If the security level at which a certain security unit (i.e., a multi-layered trusted cloud unit) can access data is greater than or equal to the security operation level of the target data, the operation is allowed; if the security level of the accessed data is less than the security operation level of the target data, the operation is rejected.

[0049] This invention introduces a trusted verification level definition, and the trusted cloud security computing mechanism can ensure that the management and operation of data meet security requirements, and provides a flexible and scalable security control mechanism.

[0050] Trusted cloud metrics calculation is a crucial step in the operation of a trusted cloud computing system, used to determine the overall security operating level of the cloud computing system. The following explains the parameters involved in the trusted cloud metrics calculation process:

[0051] The User Terminal Security Operation Level (TDep) measures the security operation level of a user terminal. It is determined by the trusted verification levels of multiple independent security component units, including the TPM chip (TDtpm), firmware hardware (TDfw), operating system (TDos), virtual monitor (TDvmm), and terminal application (TDapp). The user terminal security operation level is determined by taking the minimum value.

[0052] TDep=MIN(TDtpm,TDfw,TDos,TDvmm,TDapp).

[0053] The Server Input Security Operation Level (TDin) measures the security operation level of the server entry point. It is determined by the user (TDuser), user terminal security operation level (TDep), terminal application (TDapp), and network connection (TDlink). The Server Input Security Operation Level is calculated using the minimum value, i.e.:

[0054] TDin=MIN(TDuser,TDep,TDapp,TDlink).

[0055] In the above calculations, MIN(x, y, z) represents the safety bucket effect, meaning the lowest plank determines the maximum water capacity of the bucket. By calculating and comparing the trustworthiness verification levels of each security unit, the lowest trustworthiness verification level can be found, thereby determining the overall security operation level. The Trustworthiness Cloud Measurement Calculation Module is used to: sort the device security trustworthiness levels of all devices in each multi-layered Trustworthiness Cloud unit, and determine the device security trustworthiness level of the device with the lowest device security trustworthiness level as the corresponding multi-layered Trustworthiness Cloud unit's security trustworthiness verification level; or it can be used to determine the link security trustworthiness verification level of the data link based on the security trustworthiness verification levels of the device component units, security isolation units, and cloud facility integration units between end-to-end points in the data link.

[0056] In summary, in this invention, TDz is a general variable or function used to calculate the overall security operation level (TDint) from the trusted verification levels of each independent security unit. For example,

[0057] TDint=MIN(TDtpm,TDfw,TDos,TDvmm,TDep,TDuser,TDiaas,TDapp,TDlink...).

[0058] In the trusted cloud computing system provided by this invention, during the data application service process from the terminal to the server, if the trust verification level of any security unit (i.e., the multi-layer trusted cloud unit) on the data link fails to meet the security level requirements of the server-side data application, then access to that security unit will be denied. Through layer-by-layer checks, the entire cloud computing system is ensured to leave no opportunity for security attacks.

[0059] The Trusted Cloud Metrics Module is a crucial node in the Trusted Cloud Computing System. It provides a comprehensive method for assessing the security of the cloud computing environment and ensures that only security units that meet the security requirements can participate in DSLx data and TDaxd application services.

[0060] A multi-layered trusted cloud unit (TFTU) refers to a security unit capable of independently performing trusted cloud security computation, assessment, authentication, and quantification. It serves as a region for providing secure shared application services and supports secure trusted cloud computing systems. A TFTU comprises device component units, security isolation units, and facility integration units. The trusted cloud metric computation module assesses the security and trustworthiness verification levels of these multi-layered TFTUs, ultimately calculating the end-to-end security and trustworthiness verification level.

[0061] Specifically, the process of assessing the security and trustworthiness verification level involves first assessing the security and trustworthiness verification level of the signature certificates of each component unit, and then calculating the overall security and trustworthiness verification level of the terminal device, user, network, facility, cloud security kernel, application, and data. By assessing the security and trustworthiness verification level, this application can ensure that data, applications, and services possess secure and trustworthy characteristics. This method of assessing the security and trustworthiness verification level can be used for security modular design, accurate assessment, and security structure mechanisms for level calculation.

[0062] Preferably, in a trusted cloud computing system, the trusted cloud measurement calculation module performs trusted measurement ranking on all trusted sub-units (including unit components) in a multi-layer trusted cloud unit and determines the trusted level of the multi-layer trusted cloud unit, whose trusted level depends on the trusted sub-unit with the lowest trusted verification level.

[0063] In summary, by introducing multi-layered trusted cloud units and trusted measurement calculation modules, this invention enables secure modular design, accurate evaluation, and graded calculation, providing a secure and reliable foundation for cloud computing system environments. This mechanism enhances the security of cloud computing and provides protection for the security of data, applications, and services.

[0064] In a second aspect, the cloud computing system provided by the present invention has various functions, as described below.

[0065] Trusted cloud computing systems, through the implementation of trusted cloud security computing mechanisms, can be applied to the following core areas: cloud certificate management, cloud access control management, cloud computing hierarchy, and cloud data services. These core applications are natively integrated into trusted cloud computing systems, and their implementation can improve the security and trustworthiness of the cloud computing environment, laying a solid foundation for the development of cloud computing systems. These applications are designed at a higher level to solidify the industrial foundation for cloud computing security.

[0066] Specifically, the certificate management function in the trusted cloud computing system is explained as follows:

[0067] In a trusted cloud computing system, trusted cloud certificate management is the process of unified management of device certificate API interfaces through the trusted cloud. It involves using APIs provided by the trusted cloud mechanism to perform secure and reliable management operations on device certificates. Specifically, the trusted cloud security management device also includes a certificate management module for unified management of access certificates for all device interfaces.

[0068] The certificate management methods of trusted cloud computing systems mainly include the following aspects:

[0069] Aspect 1: Unified Certificate API Interface. The trusted cloud computing system defines a unified certificate API interface to access and manipulate certificates on devices. This simplifies certificate management and improves trustworthiness and security. Through the trusted cloud certificate API interface, operations such as certificate generation, issuance, renewal, and revocation can be implemented.

[0070] Aspect 2: Trusted Cloud Confidential Computing Applications. The trusted cloud computing system also supports the application of the Trusted Cloud Confidential Computing (PCKCS#11 and PKI / CA) API, enabling confidential computing operations within the trusted cloud computing system and securely managing relevant certificates through trusted cloud certificate management methods. This application of confidential computing provides enhanced security and protection mechanisms, ensuring the confidentiality and integrity of sensitive data.

[0071] This invention enables unified management and secure, reliable operation of device certificates through trusted cloud certificate management. This ensures the authenticity and legitimacy of certificates, prevents tampering and abuse, and improves the security and reliability of the entire trusted cloud computing system. Simultaneously, the application of trusted cloud confidential computing enhances the protection of confidential data, ensuring the security and reliability of data during the computation process.

[0072] Specifically, the trusted cloud zero-trust access management function in the trusted cloud computing system is explained as follows:

[0073] In a trusted cloud computing system, trusted cloud zero-trust access management is achieved through unified end-to-end trusted cloud access control management. It utilizes the trusted cloud metrics computing API to calculate the trusted metric security level of cloud access control and provides services and end-to-end trusted cloud zero-trust links with corresponding security levels as needed. The trusted cloud security management device also includes a request management module, used to control the cloud server to respond to the zero-trust access request based on the security control level of the zero-trust access request and the security and trusted verification level of the cloud service entry point.

[0074] The key logic of this invention for zero-trust access management in trusted clouds includes:

[0075] End-to-end zero trust: Trusted cloud computing systems introduce a zero trust model to achieve comprehensive verification and authorization of access to the cloud computing system. Whether it is an internal user or an external user, they need to be identified and authorized to access the cloud resources, ensuring that only legitimate users can access the cloud resources.

[0076] Unified Access Control Management: Trusted cloud computing systems provide a unified access control management mechanism. Through comprehensive evaluation and control of user identity, permissions, and device status, it ensures that the security and trustworthiness verification level for accessing cloud resources matches the security level of the service. This allows for the provision of services with the appropriate security level as needed, guaranteeing access security within the cloud computing system.

[0077] Trusted Measurement Computing API Application: By utilizing the Trusted Cloud Measurement Computing API, access control is measured and calculated to determine its trusted security level. This measurement and calculation process considers various factors, such as user identity, permissions, device status, and network connectivity, to ensure that the security and trusted verification level of access meets the requirements.

[0078] This invention enables fine-grained control and security assurance of access to cloud computing systems through trusted cloud zero-trust access management. Users must be authenticated and authorized to access cloud resources, and corresponding services and end-to-end trusted cloud zero-trust links are provided according to security level requirements, thereby establishing a secure and trusted access environment.

[0079] Specifically, the trusted cloud computer hierarchical management function in the trusted cloud computing system is explained as follows:

[0080] In a trusted cloud computing system, a trusted cloud computer refers to a computer operating within a trusted cloud secure computing framework. Through trusted cloud secure computing technology, the security level of cloud computers can be partially, hierarchically, and with internal and external network isolation to enhance the security and trustworthiness of individual cloud computers. This allows for the segmentation and implementation of cloud computers at different security levels (SL3-SL4) while maintaining backward compatibility with lower security levels (SL1-SL2) for cloud computing applications. Furthermore, based on the security data application requirements of different security levels, hierarchical sharing can be implemented to fully utilize the overall resources of the cloud computers.

[0081] This invention, through a trusted cloud computing hierarchy, ensures that different levels of data and applications in a cloud computing environment receive appropriate security protections and isolation mechanisms. Higher-security-level cloud computers will employ stricter security measures to protect sensitive data and applications, while lower-security-level cloud computers will provide moderate security protection to meet the needs of non-sensitive data and applications.

[0082] This invention achieves efficient resource utilization and cost reduction through hierarchical sharing of cloud computing resources. Cloud computers with different security levels can share the overall resource pool, avoiding resource waste and enabling dynamic allocation and adjustment of resources according to demand. This improves the flexibility and scalability of cloud computing, meeting the needs of different users and applications.

[0083] In summary, Trusted Cloud Computing Classification uses trusted cloud secure computing technologies and frameworks to enhance and classify the security level of cloud computers, and to achieve classified resource sharing to meet the needs of data and applications with different security levels, while improving the security and efficiency of the cloud computing environment.

[0084] Specifically, the trusted cloud data service function in the trusted cloud computing system is described as follows:

[0085] In a trusted cloud computing system, the Trusted Cloud Data Service (TLCS) is centered around the Data Security Level (DSLx) and provides complete end-to-end cloud security and trust level services. It ensures that related applications and data exist in an environment with the same required security level during storage, processing, and transmission, and are isolated from other environments with lower security levels.

[0086] To provide trusted cloud data services, all related service equipment, users, networks, facilities, and services must meet the application service security level requirements of DSLx. This means they need to meet security standards and controls that match DSLx to ensure the confidentiality, integrity, and availability of data are protected.

[0087] In trusted cloud data services, data security is paramount. This involves protective measures such as data encryption, access control, audit trails, and disaster recovery. Data must be stored in a DSLx-compliant security environment to prevent unauthorized access, data leakage, or tampering. Simultaneously, data processing and transmission must also be conducted within this level of security to prevent malicious alteration or interception.

[0088] This invention provides a trusted cloud data service, allowing users to confidently store and process sensitive data on a cloud platform and obtain security protection commensurate with their security level. This provides users with a secure and reliable data storage and processing environment, while also meeting various compliance requirements and security standards.

[0089] In summary, within a trusted cloud computing system, the Trusted Cloud Data Service centers on the Data Security Level DSLx, providing comprehensive end-to-end cloud security and trust level services. By ensuring that relevant applications and data reside in an environment with the appropriate security level, and requiring all related service devices, users, networks, facilities, and services to meet application service security level requirements, the Trusted Cloud Data Service achieves comprehensive protection and security for data.

[0090] In summary, this invention provides a trusted cloud computing system with a unified secure computing framework and services to ensure the security and trustworthiness verification level of data and applications in the cloud computing environment. The trusted cloud computing system provided by this invention has the following advantages:

[0091] A trusted cloud computing system is a comprehensive secure computing framework that integrates trusted cloud network security computing modules, trusted cloud confidential computing modules, and trusted cloud metric computing modules, and applies them to the entire cloud cyberspace information system security and trustworthiness domain. It ensures a higher level of security for the sharing, isolation, and trustworthiness of data and applications.

[0092] Trusted cloud computing systems offer a range of native applications, including trusted cloud certificate management, trusted cloud zero-trust access management, trusted cloud computer tiering, and trusted cloud data services. These applications leverage secure computing APIs and metrics computing APIs to achieve unified certificate management, end-to-end zero-trust access control, tiered cloud computing, and data-level-centric data services.

[0093] Trusted cloud computing systems improve the security and trustworthiness verification level of local cloud computing through hierarchical, domain-based, and segmented approaches, providing corresponding security services for data applications with higher security levels while remaining compatible with existing low-security infrastructure and equipment. Only when the levels of all relevant multi-layered trusted cloud units are improved can higher-security services be enjoyed.

[0094] This invention can solidify the foundation for the industrialization of cloud network information security, provide a secure and reliable data application environment for the healthy development of the digital economy, provide a solid framework for building a localized national network infrastructure security industry chain, and provide secure computing technology support for data and applications with higher security levels.

[0095] In summary, this invention provides a unified secure computing framework and services for cloud computing environments, ensures the secure and trustworthy verification level of data and applications, and can promote the development of the network security industry.

[0096] like Figure 1 As shown, the trusted cloud computing system improved by this invention is structured as follows:

[0097] The Trusted Cloud Mechanism Hardening Module allows for different hardening technologies to achieve different levels of security and trustworthiness verification, providing different levels of Trusted Cloud security services. This includes hardware-level hardening and security measures for hardware components, security chips, encryption modules, etc.

[0098] Trusted cloud operating systems and trusted cloud computing systems need to be fully applied to each operating system. Factors such as the kernel isolation, development model, and user application environment of the operating system also determine the overall security and trustworthiness verification level. This means that the operating system needs to have secure design and implementation, including kernel-level isolation and security functions.

[0099] Trusted cloud terminal devices and users are also important components of a trusted cloud computing system. Terminal devices need to have a secure and trusted verification level and take corresponding security measures, such as hardware encryption, secure boot, and secure authentication. User authentication and access control are also necessary.

[0100] Trusted cloud networks and trusted cloud computing systems need to be implemented throughout the network environment, including the security configuration and management of network devices, firewalls, intrusion detection systems, etc., to protect the security of network communication and data transmission.

[0101] Trusted cloud infrastructure platform services: Trusted cloud computing systems also require the establishment of trusted infrastructure platform services, including data centers, servers, storage systems, etc. These facilities need to meet certain security standards and trusted verification levels to ensure the security of data and applications.

[0102] Trusted cloud applications and data: The ultimate goal of a trusted cloud computing system is to protect the security of applications and data. Applications need to be designed and developed in accordance with security standards, and adopt secure coding and encryption technologies. Data needs to be protected during storage, transmission and processing, including encryption, access control and data integrity.

[0103] The technical problems discovered and the technical solutions proposed in this invention will now be described in detail.

[0104] Discoveries regarding technical issues such as the security and trustworthiness of current cloud computing systems.

[0105] Cloud security and trustworthiness are critical issues that have emerged against the backdrop of rapid development and widespread application of information technology. As human society enters the information age, cyberspace, as an environment encompassing all information systems, is not only the foundation of human survival but also crucial for information preservation. Therefore, ensuring the security of cyberspace has become a fundamental requirement shared by both humanity and information. However, due to the vast and complex nature of cyberspace, information security issues within it are particularly prominent. In this context, cloud computing systems are considered the optimal paradigm for realizing cyberspace information systems. Solving the security and trustworthiness issues of cloud computing is fundamentally the primary goal and the direction that technical personnel are striving to achieve.

[0106] Cloud computing is a service-oriented model based on the internet, providing on-demand services and metered pricing, offering users a wide range of shared services. Cloud computing can be broadly divided into three layers: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Users can rent hardware servers, virtual machines, software development platforms, and application software provided by cloud computing, without having to purchase and maintain expensive infrastructure themselves. The convenience and cost-effectiveness of this model are of great significance to users.

[0107] Cloud computing systems leverage technologies such as distributed computing, parallel processing, and grid computing to automatically break down massive computational programs into smaller subroutines via a network. These subroutines are then processed and analyzed by a large system of multiple servers, ultimately returning the results to the user. Cloud computing is a collection of hybrid cloud computer network spatial information systems that enable multi-tenancy, multi-user, and multi-data application processing.

[0108] The security and trust issues inherent in resource sharing and isolation are challenges that cloud computing systems inevitably face, a consequence of their service-oriented computing model. Resource sharing introduces numerous information security and trust issues; for example, infrastructure and equipment platform security: cloud computing possesses virtually unlimited computing resources, but users struggle to determine the trustworthiness of these resources; service security: cloud computing provides virtually ubiquitous services, but users find it difficult to ascertain the trustworthiness of these services; and data security: cloud computing provides virtually unlimited storage space, but users are unaware of where their data is stored, whether others are using it, and have no control over their data. Consequently, users develop a distrust of cloud computing, which has become a primary and fundamental obstacle to its widespread adoption.

[0109] The core contradiction in cloud computing lies in balancing secure and trustworthy resource sharing and isolation. A one-sided pursuit of higher security levels often sacrifices significant resources and flexibility. Solutions need to seek the optimal balance of overall security levels, considering multiple aspects: achieving the highest overall security level; pursuing the fastest security performance in terms of efficiency; seeking the simplest and best open and unified standards in terms of technology; and achieving the most economical hardware support.

[0110] In conclusion, solving the security and trust issues of cloud computing systems is a complex and critical task. It requires a comprehensive consideration of the balance between resource sharing and isolation, and the formulation of comprehensive security strategies and measures. Only in this way can we truly promote the widespread application of cloud computing and ensure its security and trustworthiness.

[0111] The background technology and its shortcomings related to the present invention are described below.

[0112] To address the security and trust issues of computer and cloud computing systems, the IT industry has sporadically introduced several secure and trustworthy computing technologies for different fields over the past 20-30 years. These technologies are all open, open-source, and standardized (or have practically become de facto standards), such as TPM, OpenSSL, and PKCS#11 / OpenCryptoki / Chaps. These technologies have addressed the security and trust issues of computers and cloud computing to varying degrees and in different ways, but each technology has its own advantages, disadvantages, or focus. The following is a description of several background technologies related to the trusted cloud computing system provided in this invention, along with their advantages and disadvantages.

[0113] About Trusted Computing (TPM).

[0114] To address the security and trust issues of personal computers, a mature technology is the use of Trusted Computing Platform Modules (TPMs). In 2003, companies such as AMD, IBM, Intel, and Microsoft established the Trusted Computing Group (TCG) to promote the development of trusted computing technologies and standards. A TPM is a standalone secure computing hardware chip embedded in a computer system, used to ensure the integrity of device data, the confidentiality of data encryption, and the trustworthiness of user authentication.

[0115] TPM establishes a root of trust by introducing tamper-resistant hardware chips into the computer and uses the PCRx hash algorithm to measure all hardware and software. It provides a consistent metric for measuring the trustworthiness of firmware, hardware, operating systems, virtual machines, and other devices. TPM also uses built-in RSA private and public key pairs for authentication, similar to an identity certificate verification mechanism. It can bind the security characteristics of all devices and subjects to the private key of the root of trust and use various root keys to encrypt sensitive data on devices, etc.

[0116] However, TPM also has some limitations. First, it was designed primarily for the security and trustworthiness of standalone personal computer terminals and cannot directly support the security and trustworthiness of cloud network storage, requiring reliance on system software for cloud security extensions. Second, it may have some shortcomings in terms of performance and security levels. TPM implements the least private key (EK) function instead of standard PKCS#11 confidential computation, which may limit its user experience and scalability. For example, TPM may have limitations in implementing higher levels of privacy and security protection features (such as facial recognition).

[0117] In summary, TPM is a technology that helps improve the security and trustworthiness of personal computers, but it has some limitations in addressing cloud computing and certain advanced security needs, particularly in the area of ​​network security trust. As technology continues to evolve, it is necessary to comprehensively consider various security requirements and select appropriate security solutions.

[0118] Regarding OpenSSL for cybersecurity computing.

[0119] OpenSSL, short for Cybersecurity Computing, is used to protect network transmission security by authenticating the trustworthiness, non-repudiation, data confidentiality, and data integrity of both parties' devices and users.

[0120] OpenSSL is a network confidentiality transport security protocol, a security standard protocol built on top of the transport layer TCP / SSL (Secure Sockets Layer) and below the application layer. It provides end-to-end public key certificate verification and secure key exchange, ensuring the confidentiality and integrity of applications between communicating parties. OpenSSL is a completely open and open-source transport layer security protocol and application; it is a cross-platform implementation of the SSL / TLS / DTLS (Secure Transport Layer Protocol) and enjoys widespread support and development in the industry.

[0121] In the early days of the internet, the HTTP protocol was widely used to transmit data between clients and servers. However, because HTTP transmits data in plaintext, the transmitted data could be eavesdropped on and tampered with. To address this security issue, the SSL protocol was introduced. By using SSL, data is encrypted during transmission, ensuring its confidentiality and integrity. The development of OpenSSL has made HTTPS the standard for internet communication, providing users and websites with more secure data transmission. Now, almost all websites and applications use HTTPS to protect the transmission of sensitive data, such as login information, payment data, and personal privacy.

[0122] However, OpenSSL also has some drawbacks. First, it was primarily developed for browser application security, based on the assumption that the security and trustworthiness of the endpoint and server are unknowable, relying entirely on certificate authorities to authenticate their security and trustworthiness. This involves many human factors and is relatively cumbersome to manage. Second, most industry implementations are purely software-based, with keys, especially certificate private keys, stored in operating system files, lacking a true root of trust, and the problem of certificate and private key duplication also exists. All necessary protection protocol applications and cryptographic calculations are only protected by the operating system; if the operating system is compromised, everything will fail. Therefore, it is necessary to integrate TPMs and cryptographic devices with OpenSSL to achieve hardware-based and complementary security protection.

[0123] Furthermore, due to historical reasons, the OpenSSL cryptographic library and applications are very large and complex, containing many outdated, insecure, or obsolete cryptographic functions. To meet the needs of mainstream commercial applications and localization, OpenSSL needs to be streamlined and adopt modern and Chinese national cryptographic functions.

[0124] In summary, OpenSSL is a highly secure and reliable network transport security protocol that plays a crucial role in protecting data security during internet communication. However, it also has some limitations, including reliance on device security and trustworthiness, limitations in software implementation, and the need to update cryptographic functions. In practical applications, it is necessary to combine hardware security technologies and modern cryptographic algorithms to provide stronger and more secure network security protection.

[0125] Regarding confidential computing OpenCryptoki / Chaps.

[0126] Confidential computing protects and keeps confidential the data and applications in use by leveraging hardware-based secure modules or hardware-based trusted execution environments (TEEs). The goal of confidential computing is to provide a higher level of data and code integrity, and secure computing that ensures confidentiality in a hard-isolated environment.

[0127] However, the definition of confidential computing is relatively broad, and there is no unified API standard that can be shared by all security applications, which is one of its drawbacks.

[0128] Regarding the password token PKCS#11 / OpenCryptoki / Chaps.

[0129] The PKCS#11 standard defines a platform-independent, secure, and trusted API for cryptographic tokens. This API, known as "Cryptoki," defines the functionality for handling common cryptographic objects such as RSA keys, X.509 certificates, keys, and confidential data. The API provides all the operations needed to create, generate, modify, and delete these objects. PKCS#11 is widely used in cybersecurity, finance, and e-government, providing a standardized solution for data protection and encryption.

[0130] IBM has open-sourced the OpenCryptoki / Chaps project, which implements the PKCS#11 cryptographic token application and supports IBM's own cryptographic token hardware devices. It uses a unified standard and implementation, allowing for expansion to support more open cryptographic token devices.

[0131] However, PKCS#11 / OpenCryptoki / Chaps is primarily used in e-commerce, government affairs, and cybersecurity, relying on cryptographic token devices such as HSMs and smart cards to provide secure and trusted service authentication, rather than on the TPM security and trust functions of the terminal device. Using PKCS#11 / OpenCryptoki / Chaps requires constant internet connection to the HSM and the carrying of a smart card device, which inconveniences the user experience. Furthermore, it lacks binding with a root of trust (such as a TPM) and requires further hardening and extension of TPM / PKCS#11 to support functions such as facial recognition and device binding.

[0132] Therefore, further development and improvements are needed to enhance the functionality and user experience of PKCS#11 / OpenCryptoki / Chaps, including integration with trusted roots (such as TPM), hardware support for features such as face recognition and device binding, and TPM / PKCS#11 extensions.

[0133] Based on the above analysis, this invention provides a unified, complete, feasible, standard, open, and hard-integrated trusted cloud computing system to improve the security and trustworthiness of cloud network spatial information systems and protect shared, isolated, higher-security-level data and applications.

[0134] First, this invention leverages the advantages of existing independent security and trust technologies, complementing and enhancing them, taking the best from each other, and adapting foreign technologies to Chinese applications. It also systematically addresses their various defects and limitations, unifying and integrating them to comprehensively solve the fundamental problems of security and trust of all cloud information in cloud networks.

[0135] like Figure 1 As shown, the trusted cloud computing system provided by this invention includes the following parts:

[0136] The Trusted Computing Module delivers complete, converged, hardened, and open-source trusted computing services across all trusted cloud devices using minimal hardware costs and secure interface APIs.

[0137] The Trusted Cloud Security Computing Module employs a unified, hardened, and integrated security computing mechanism within the cloud network to ensure the security and trustworthiness of the cloud network.

[0138] The Trusted Cloud Confidential Computing Module utilizes hardware isolation units such as Trusted Execution Environments (TEEs) to protect and keep confidential the data and applications in use, providing a higher level of data and code integrity and ensuring hard isolation and secure computing within the environment.

[0139] The Trusted Cloud Measurement Calculation Module, based on a unified and quantitative method for calculating trust security levels, transforms the abstract and vague concepts of trust and security into a concrete and rigorous method for calculating trust security levels.

[0140] Through the above mechanisms, this invention provides complete, integrated, robust, and open-source trusted cloud security computing services on all trusted cloud computing systems. Simultaneously, it employs a unified quantitative method for calculating security levels based on trustworthiness metrics to ensure accurate calculation and evaluation of security levels.

[0141] The trusted cloud computing system of this invention can provide a higher level of security and trustworthiness, and solve the problems of security isolation and protection in cloud networks. Its implementation requires minimal hardware cost and security interface API, and transforms abstract concepts of trust and security into specific security level assessments through a unified quantitative calculation method.

[0142] The following sections describe the Trusted Cloud Secure Computing Module and its integration and hardening:

[0143] Regarding the Trusted Computing (TPM) module.

[0144] TPM (Trusted Platform Module) is a hardware security module used to store and perform security-related operations, such as key generation, encryption, and authentication. The core technologies of TPM mainly include the following aspects:

[0145] TPM 2.0 is the latest version of TPM technology, offering more features and enhanced security compared to the older TPM 1.2. TPM 2.0 supports more algorithms, including symmetric encryption, asymmetric encryption, and hash algorithms, as well as other new features such as certificate management, random number generation, and key derivation.

[0146] Remote Attestation (TPM) can be used to implement remote trusted authentication, which verifies the identity and integrity of a device using security credentials generated by the TPM. Remote trusted authentication can ensure mutual trust between communicating parties and prevent malware and tampering attacks.

[0147] SecureBoot (TPM) can be integrated with the system boot process to enable secure boot functionality. By using TPM to generate and verify digital signatures, the integrity and authenticity of software and firmware during system boot can be ensured, preventing the loading and execution of malware.

[0148] Trusted Execution Environment (TPM) can be used to create a Trusted Execution Environment (TEE), providing a secure, isolated environment for executing sensitive computational tasks. A TEE can protect applications and data from interference and malicious access by the operating system or other applications.

[0149] Enhanced Privacy: TPM can be used to enhance user privacy protection. It can generate and manage encryption keys for data encryption and decryption. TPM also provides anonymous authentication and verification capabilities, allowing user identity verification without revealing user identity information.

[0150] These factors combined enable TPM to play a greater role in the field of secure computing, providing more security features and protection mechanisms to safeguard system security and user privacy.

[0151] Regarding the Trusted Cloud Security Computing TPM / OpenSSL / TLS module.

[0152] Trusted cloud network security computing extends the concept of trusted computing to secure cloud network transmission. It improves the overall level of computer and network transmission security and trust by integrating and expanding network transmission security standards such as TPM (Trusted Platform Module), SSL / TLS (Secure Sockets Layer / Transport Layer Security) and DTLS (Datagram Transmission Layer Security), as well as PKI / CA (Public Key Infrastructure / Certificate Authority) applications, and integrating and expanding technologies such as OpenSSL+.

[0153] TPM (Trusted Platform Module) and OpenSSL are two independent security technologies. This invention integrates and strengthens them in a trusted cloud computing system, while also enhancing security through private key binding and cryptographic function security.

[0154] TPM integrates with OpenSSL, allowing for enhanced key protection and security. TPM generates and stores private keys, providing key protection and usage functionality. By integrating OpenSSL with TPM, TPM-generated keys can be used in OpenSSL operations for encryption, decryption, signing, and verification, ensuring key security and confidentiality.

[0155] TPM / OpenSSL Hardening: TPM is a hardware security module with hardened security functions. TPM chips are typically integrated into a computer's motherboard or processor, offering protection against physical attacks and tampering. This invention improves system security by hardening OpenSSL security functions, such as private keys and authentication cryptographic functions, into the TPM chip, preventing malicious software or attackers from unauthorized access to keys and sensitive data.

[0156] Private key binding: TPM can generate and store private keys and bind them to specific dedicated hardware modules or OpenSSL software to form a private key binding mechanism. Private key binding ensures that the private key can only be used in a specific environment, preventing the private key from being leaked or exploited by malicious software. This invention binds the private key to the TPM, so that the private key can only be used for encryption, decryption, or signing operations in environments certified by the TPM.

[0157] For cryptographic function security, TPM provides several secure functions and algorithms for cryptographic operations and function execution. These functions and algorithms are designed and verified to ensure their security and resistance to attacks. This invention enhances the security of OpenSSL software's cryptographic operations by using the cryptographic functions provided by TPM, preventing password cracking, dictionary attacks, and other cryptographic-related attacks.

[0158] In summary, this invention integrates and strengthens TPM with OpenSSL to provide enhanced security. Private key binding ensures the secure use of private keys, while cryptographic function security enhances the resistance to attacks on cryptographic operations. These measures collectively improve the security of systems and applications, protecting sensitive data and user privacy.

[0159] This invention integrates TPM and OpenSSL (which can be a minimal subset of national cryptographic or commercial cryptography) into a separate hardware security module. Trusted cloud network security computing achieves the functions required for network security transmission, such as the trustworthiness of identity device authentication, data confidentiality, data integrity, and non-repudiation.

[0160] Pure software-based OpenSSL keys have nowhere to be hidden, achieving only SL2 (Security Level 3) security. TPM's hardware integration allows for private key binding, ensuring the security and trustworthiness of devices and identities, reaching SL3 (Security Level 3). A more robust device system network achieves the target security level SL4 (Security Level 4). Although network transmission is encrypted, shared networks remain a major degradation factor, generally failing to reach SL5 (Security Level 5) security. In short, this invention's Trusted Cloud Network Security Computing extends the concept of trusted computing to cloud networks, achieving a higher level of security and trustworthiness.

[0161] Regarding the Trusted Cloud Confidential Computing Module (TPM / OpenCryptoki / Chaps).

[0162] Trusted Cloud Confidential Computing extends the concept of trusted computing to the secure and trusted environment of cloud computing cryptographic devices. It integrates and expands trusted computing, hardened PKCS#11 cryptographic device standards, and incorporates open-source OpenCryptoki / Chaps technologies. By merging TPM (Trusted Platform Module) and PKCS#11 hardening into a more independent hardened security module, Trusted Cloud Confidential Computing provides a higher level of security and trustworthiness.

[0163] The PKCS#11 standard enables applications to be isolated from independent cryptographic devices, communicate securely, store data, and perform computations, and allows for flexible innovation in various cryptographic token applications. Integrating TPM / PKCS#11 into a hardware security module provides more secure support for local HSM (Hardware Security Module) cryptographic devices and cryptographic token devices, and offers a unified and shared secure computing environment for cryptographic devices. While a TPM itself can implement a PKCS#11 cryptographic device, it is too small and unsuitable.

[0164] To support network or cloud HSM, trusted cloud confidential computing needs to be combined with trusted cloud network security computing, using the same secure APIs of TPM / OpenSSL / PKCS#11 and secure and trusted communication of cloud HSM / smart cards, including Privacy / CA, PKI / CA certification center communication and certificate management.

[0165] This method can also unify encryption and key management for cloud storage, whether it is local or network storage. PKCS#11 provides a unified and complete key generation, management, and authentication mechanism.

[0166] The pure software implementation of OpenCryptoki / Chaps keys leaves no place for them to be hidden, achieving a security level of SL2 (Security Level 2). Through simple TPM hardening and private key binding, the PKCS#11 / HSM mechanism storing keys in the operating system kernel is protected, achieving a security level of SL3. Further implementation of a hardened biometric PKCS#11 token device is equivalent to integrating a PKCS#11 smart card into a secure and trusted device, enabling two-factor authentication and achieving a security level of SL4. The target security level for HSM implementations in private networks and dedicated devices is SL5.

[0167] In short, Trusted Cloud Confidential Computing extends the existing concept of trusted computing to the cloud computing cryptographic device environment. Together with Trusted Cloud Cybersecurity Computing, it comprehensively and uniformly extends and enhances the Trusted Computing Group's (TCG) original Trusted Computing (TPM) concept for personal computers into the Trusted Cloud Computing field, or it can be understood as this huge trusted cloud computer.

[0168] TPM, OpenSSL, OpenCryptoki, and Chaps all possess absolute security and trust advantages in the fields of trusted computing, secure network transmission, and cryptographic token devices. Many of their native applications, such as private key authentication and binding, HTTPS, certificate management and querying, and cryptographic device management and querying, are essential functions in trusted cloud secure computing mechanisms. This invention aims to find the optimal balance in terms of overall security level—that is, speed, efficiency, and cost-effectiveness: achieving the highest overall security level, the fastest security performance, adopting simple and open unified standards, and achieving the most economical hardware support and tiered implementation.

[0169] Regarding the unified quantitative trusted cloud security measurement technology.

[0170] Unified quantitative trustworthy cloud security metrics technology is a crucial component of trusted cloud computing systems. Its primary purpose is to quantify various ambiguous security and trust concepts, categorizing them into five levels to enable mathematical calculations and expressions for data, applications, devices, facilities, identities, networks, systems, and hardware components. This unified quantitative trustworthy cloud security metrics is expected to lay the industrial foundation for the secure and trustworthy development of cloud networks and have a profound impact. This invention, through a unified measurement standard, can more accurately assess and measure the security and trustworthiness of various security units in a cloud network, enabling corresponding security measures and decisions.

[0171] The original TPM / SSL / PKCS#11 standard did not have a complete concept of security and trust verification level calculation or a vague descriptive security level definition. This invention provides, defines, and quantifies the multi-layered trusted cloud units in all cloud computing systems and uniformly implements a trusted cloud metric calculation scheme.

[0172] The unified quantitative trusted cloud security metric technology of this invention can provide a common language and framework for the fields of cloud computing and network security, enabling different security concepts to be compared, evaluated and calculated through specific numerical values, thus better understanding and managing security risks in cloud networks and providing a scientific basis for security decisions.

[0173] In summary, the introduction of a unified and quantifiable metric for trusted cloud security will promote the development of secure and trustworthy cloud networks and provide a solid foundation for the healthy development of the trusted cloud computing industry. Through standardized and quantifiable measurement methods, this invention can better assess and improve the security and trustworthiness of cloud networks, thereby providing users and organizations with more secure and reliable cloud services and applications.

[0174] Explanation of security levels.

[0175] Security level is a quantitative assessment of security, used to measure and describe the security level of different systems, data, or devices.

[0176] The device security and trust level of this invention is divided into five levels, from SL5 to SL1, representing static security level constants. These security levels are determined according to the definitions and descriptions of security chips, security devices, and standards such as Cybersecurity Classified Protection 2.0 and the international FIPS 140-2.

[0177] Data security level is represented by DSLx, where x represents the specific level. The data security level is consistent with the security level of security chips and security devices, and is defined with reference to data security level guidelines. The specific breakdown of data security levels is as follows:

[0178] Top Secret (DSL5): Corresponds to SL5, indicating the highest level of data security, requiring the highest level of protection and control.

[0179] Confidential (DSL4): Corresponding to SL4, it indicates a high level of data security that requires strict protection and control.

[0180] Secret (DSL3): Corresponding to SL3, it represents a medium level of data security, requiring a certain degree of protection and control.

[0181] Internal Disclosure (DSL2): Corresponding to SL2, it indicates a low level of data security that requires appropriate protection and control.

[0182] Externally Disclosed (DSL1): Corresponding to SL1, this indicates the lowest level of data security, requiring basic protection and control.

[0183] The breakdown and definition of these security levels are intended to provide a unified metric for accurately assessing and comparing the security of systems, data, and devices. They also align with the Cybersecurity Classified Protection 2.0 standard to ensure consistent metrics and standardization.

[0184] Regarding the definition of trusted verification levels.

[0185] The Trusted Validation Level (TZ) defines the TZ requirements for managing and operating a unit within a specific data security level (DSLx). By ensuring that the TZ of the Trusted Validation Level unit satisfies the condition TDz ≥ DSLx, secure and trusted operations on the data and corresponding trusted cloud services can be achieved.

[0186] Note that the trusted verification level definition involves three concepts: DSLx, TDaxd, and TDz; the following is an explanation of them:

[0187] Data Security Level (DSLx) is used to indicate the security level of data that needs protection. It includes levels such as Top Secret, Confidential, Secret, Internal Public, and External Public. DSLx identifies the sensitivity of the data and the requirements for its management.

[0188] Trusted Application Execution Degree (TDaxd) refers to the service level range within which a trusted verification level unit can manage data under a specific data security level (DSLx). TDaxd defines the specific permission scope for data management operations, such as write, read, and access. TDaxd is a concrete definition of the Trusted Application Execution Degree; it is a service level range.

[0189] TrustedDegree (TDz) represents the trusted verification level of a security unit. TDz can be a specific independent unit (such as a TPM chip) or a shared isolation unit (TDtc) (such as a trusted cloud shared isolation unit). The value of TDz must meet the condition: TDz ≥ DSLx, that is, the trusted verification level must be greater than or equal to the data security level to ensure that operations performed on the data in this security unit environment are trusted.

[0190] Regarding trusted cloud metric computing technology.

[0191] Trusted cloud metrics calculation involves multiple security units and the overall trusted verification level calculation is as follows:

[0192] Trusted Degree of Trusted Cloud (TDtc): This represents the level of trust verification in a cloud computing system. The value of TDtc is determined by multiple factors, including the security operation levels of the Trusted Computing Device (TPM), firmware (FW), and operating system (OS), as shown in the formula below. The value of TDtc is the minimum of the three, meaning that the trust verification level of the cloud computing system is limited by the weakest link.

[0193] TDtc=MIN(TDtpm,TDfw,TDos).

[0194] User terminal metric TDep (Trusted Degree of Endpoint): Represents the trusted authentication level of the terminal device. The value of TDep is determined by multiple factors, including TDtc, firmware (FW), operating system (OS), virtual machine monitor (VMM), and the security operation level of the terminal application environment (APP), as shown in the formula below. The value of TDep is the minimum value among these security operation levels to ensure that the trusted authentication level of the terminal device in the cloud computing system meets the minimum requirements.

[0195] TDep=MIN(TDtc,TDfw,TDos,TDvmm,TDapp).

[0196] The server-side input security operation level TDin (TrustedDegreeofInput) represents the level of trustworthiness of the input data received by the server. The value of TDin is determined by multiple factors, including the security operation levels of the user (TDuser), the terminal device (TDep), and the network connection (TDlink), as shown in the formula below. The value of TDin is the minimum of these security operation levels to ensure that the input data meets the server's security trustworthiness verification requirements.

[0197] TDin=MIN(TDuser,TDep,TDlink).

[0198] The overall Trusted Cloud Security Operation Level (TDint) can be obtained through the above measurement calculations. As shown in the formula below, TDint is the minimum value among the security operation levels of multiple security units, including TDtc, TDfw, TDos, TDvmm, TDep, TDapp, TDuser, TDiaas, TDlink, etc. In this way, the Trusted Cloud measurement calculation method ensures that the security and trustworthiness verification level of the entire cloud computing system will not be reduced by the weakest unit.

[0199] TDint=MIN(TDtc,TDfw,TDos,TDvmm,TDep,TDapp,TDuser,TDiaas,TDlink...).

[0200] MIN(x, y, z) represents the bucket-plank effect in security, where the lowest plank determines the maximum water volume in the bucket. Improving weak points is key to enhancing the overall cloud security level. For example, TDlink=SL1. Since the internet has too many unknown elements, end-to-end trusted network security SSL connection encryption can be used. An ideal trusted cloud mechanism achieves TDssl=SL4.

[0201] In this invention, any unit on the link line that fails to meet the security and trustworthiness verification level requirements of the server-side data application service from the terminal will be rejected, with multiple layers of checks to prevent security attackers from having any opportunity to exploit.

[0202] Regarding multi-layered trusted cloud units.

[0203] A multi-layered Trusted Cloud Unit (TUN) is an independent security unit with the capabilities for security and trust measurement, evaluation, authentication, and quantification. It should possess the following characteristics:

[0204] Independence: The multi-layered trusted cloud unit should exist independently, without interference or influence from other units. It can independently perform secure and trusted computation, evaluation, certification and quantification to ensure the accuracy of security performance and trust measurement.

[0205] Clearly defined security levels: A multi-tiered trusted cloud unit should clearly define the security levels of the data it protects and the applications it supports. This means that for each piece of data and application, its security level should be clearly defined in order to implement appropriate security measures and protections.

[0206] Secure shared service APIs and service ranges: Multi-tiered trusted cloud units should provide well-defined secure shared application service APIs. These APIs should be within a security service level range. A service range refers to the ability to provide different security service level APIs for the same data and applications, such as management level, write level, read level, and call level.

[0207] The design of a multi-layered trusted cloud unit should include three elements: the definition of security levels for data and applications, and the security service level range for shared application APIs. Through the modular design of these elements, the multi-layered trusted cloud unit can provide unified secure shared application services to support the implementation of secure and trusted computing.

[0208] The multi-layered trusted cloud unit includes a device component unit, a facility integration unit, and a security isolation unit, which will be described in detail below.

[0209] Regarding equipment component units.

[0210] Device component units are the building blocks of trusted cloud devices. They are assembled in a hierarchical structure to provide overall device security and trust metrics. The following are common device component units:

[0211] A TPM (Trusted Platform Module) chip is a trusted computing chip used to provide security functions and protection mechanisms for devices. It can store and process encryption keys, perform authentication, support secure boot processes, and more, thereby enhancing device security.

[0212] A security-integrated hardening module is a hardware module specifically designed for security, providing additional security accelerators, security features, and protections. It can include hardware encryption engines, random number generators, secure storage, and more to enhance device security.

[0213] Device hardware firmware refers to the software programs or instruction sets embedded in a device, used to manage and control hardware functions. It should be designed and verified for security to prevent tampering or malicious use.

[0214] The operating system is the core software of a device, responsible for managing and coordinating the operation of its various components. A secure operating system should have security features such as access control, authentication, and data encryption to protect the security of the device and its data.

[0215] A virtual machine manager is a software layer used to create and manage virtual machine environments. It should have features such as security isolation, virtual machine monitoring, and access control to ensure the security of the virtual machine environment.

[0216] Applications refer to the various software programs and services running on a device. Secure applications should have functions such as security authentication, data encryption, and access control to protect the security of application programs and data.

[0217] The security and trustworthiness verification level of each device component can be managed and certified by the manufacturer of each component, who will provide corresponding security certificates and signatures to demonstrate its security and trustworthiness. By using the aforementioned device component units and according to the following trust metric calculation formula, the overall device security operation level (TDdevice) can be calculated to assess the device's security.

[0218] TDdevice=MIN(TDtc,TDhw,TDfw,TDos,TDvmm,TDapp).

[0219] Regarding the overall combination unit of cloud infrastructure services.

[0220] The cloud infrastructure service unit refers to the infrastructure of a trusted cloud computing system. It is composed of multiple device components, network and storage devices, which form the core foundation of the trusted cloud, providing support and services for cloud computing. These device components include servers, network devices, and storage devices, especially the kernel components, which have a high level of security and trust verification to ensure the security of the trusted cloud.

[0221] In the infrastructure of a trusted cloud computing system, the cloud operating system kernel plays a crucial role. It is the core hardware and software of the cloud computing environment, responsible for critical functions such as resource management, security services, and access control. The cloud operating system kernel ensures the efficient utilization of cloud computing resources by effectively allocating and managing them. Simultaneously, it provides security services, such as authentication, access control, and encryption, to protect the security of data and applications within the cloud computing environment.

[0222] Resource management is a crucial function of the cloud operating system kernel. It ensures that users can use and share resources on demand by scheduling and allocating cloud computing resources, thereby improving resource utilization and efficiency. Resource management also includes monitoring and adjusting resource allocation to meet the needs of different users and applications.

[0223] Security services are another key function provided by the cloud operating system kernel. They include authentication, access control, data encryption, and security auditing to ensure the security of data and applications in the cloud computing environment. Authentication verifies the user's identity and permissions to prevent unauthorized access. Access control controls user access permissions to resources and services to protect the confidentiality and integrity of data. Data encryption protects the security of data during transmission and storage by encrypting it. Security auditing logs and monitors security incidents in the cloud computing environment to help identify and respond to security threats.

[0224] In summary, the infrastructure of a trusted cloud computing system consists of device components, network and storage devices, with resource management, security services and access control functions provided by the cloud operating system kernel device components. These components together construct a secure and trusted cloud computing system, providing users with secure and reliable cloud services and protecting the security of user data.

[0225] Regarding the security isolation unit.

[0226] Security isolation units play a crucial role in trusted cloud computing systems. They are used to implement different layers of isolation and protection within the cloud computing environment to ensure security and privacy between different users and applications. These security isolation units can be categorized into physical layer, hardware chip layer, operating system kernel layer, storage layer, network layer, virtual machine layer, and client packet layer, among others.

[0227] The physical layer security isolation unit isolates different users and applications through physical isolation methods, such as independent servers and network devices, to prevent interference and conflicts of physical resources.

[0228] The hardware-level security isolation unit includes security chips and hardware security modules, which protect the security of data and applications by providing hardware-level security functions and encryption support.

[0229] The operating system kernel layer’s security isolation unit uses Root / kernel / user modularization or virtualization technology to isolate different users and applications in an independent kernel or virtual environment, preventing interference and attacks between them.

[0230] The secure isolation unit in the storage layer ensures the confidentiality and integrity of data during the storage process through data encryption and access control, preventing unauthorized access and tampering.

[0231] The network layer security isolation unit protects the security of data transmission in the cloud computing environment through network isolation and encrypted communication, preventing data from being eavesdropped on and tampered with.

[0232] The security isolation unit at the virtual machine layer isolates different virtual machine instances through the isolation mechanism of the Virtual Machine Monitor (VMM), ensuring that their resources and execution environments are independent of each other and preventing the spread of malicious behavior.

[0233] The secure isolation unit of the customer grouping layer ensures secure isolation and privacy protection by grouping different users and applications and restricting their access and communication with each other.

[0234] The implementation and operation of these security isolation units directly affect the overall security and trustworthiness verification level of the multi-layered trusted cloud unit. By adopting appropriate security isolation mechanisms and measures, the trusted cloud can provide a higher level of data protection, privacy protection, and security, offering users a reliable cloud service environment.

[0235] Regarding multi-layer trusted cloud unit product vendors.

[0236] Ensuring the security and trustworthiness verification level of a multi-layered trusted cloud unit can be determined by each vendor. Each vendor of a multi-layered trusted cloud unit can take measures in design, computation, and compliance to improve the security and trustworthiness of its unit products. This includes, but is not limited to, the following aspects:

[0237] In design and development, vendors can adopt secure design principles and best practices to ensure the security and isolation of their multi-layered trusted cloud units. This includes security architecture design, security vulnerability assessment and remediation, and the use of encryption technologies.

[0238] Calculation and verification: Vendors can calculate and verify security and trust levels to ensure that their multi-layered trusted cloud units meet preset security requirements and level standards. This can include using security assessment tools and methods to conduct security testing and verification, as well as obtaining third-party assessments and certifications.

[0239] Compliance and certification allow vendors to ensure that their multi-tiered trusted cloud units meet applicable security standards and regulatory requirements. This includes adhering to relevant industry standards and specifications, such as ISO 27001 and FIPS 140-2, and verifying their compliance through relevant certification and compliance procedures.

[0240] Certificate chain signing allows vendors to provide secure and trusted verification levels of signed certificate chains for their multi-tiered trusted cloud units. These certificate chains can be used to verify the security and trustworthiness of the multi-tiered trusted cloud units and provide non-repudiable evidence.

[0241] In addition, third-party assessment and certification bodies can further enhance the reputation and credibility of multi-layer trusted cloud unit vendors. By conducting independent security assessments and verifications, these bodies can provide users with independent security guarantees and verifications, and enhance the credibility of multi-layer trusted cloud unit products.

[0242] This invention, through the joint efforts of various trusted cloud product manufacturers, collaboratively improves the security and trustworthiness verification level of multi-layer trusted cloud unit products, thereby establishing a secure and trustworthy trusted cloud industry chain, providing users with a more secure and trustworthy cloud service environment, and ensuring the overall security and reputation of the trusted cloud.

[0243] Regarding the trusted cloud security computing mechanism.

[0244] The Trusted Cloud Security Computing Mechanism, or simply Trusted Cloud Mechanism, refers to the function of the Trusted Cloud Security Management Device in this invention. It is an isolated unit within a Trusted Cloud Computing System, integrating hardened technical components such as TPM (Trusted Computing Module), SSL / TLS (Secure Sockets Layer / Transport Layer Security), PKCS#11 (Cryptographic Device Interface Standard), and Trusted Authentication Level (TDx). It implements a unified Trusted Cloud Security Computing Mechanism on all devices. In other words, the Trusted Cloud Security Management Device in this invention can be implemented by independent hardware or by programs located on all devices within the Trusted Cloud Computing System. It can be implemented in a distributed manner through software code and runs on all devices within the Trusted Cloud Computing System.

[0245] The goal of Trusted Cloud technology is to enable high-security applications in cloud networks, typically between SL3 (Security Level 3) and SL4 (Security Level 4). It provides a consistent Trusted Cloud secure computing API, enabling the protection and isolation of data and applications within the Trusted Cloud.

[0246] Trusted cloud technology plays a core role in trusted cloud computing systems. Its design and implementation are based on the core of this patented technology, aiming to provide security and trustworthiness for all devices and cloud computing environments. By integrating security technologies at the hardware and software levels, this invention provides users with secure and reliable security guarantees, ensuring the security and trustworthiness of data and applications in trusted cloud computing systems.

[0247] In summary, the Trusted Cloud Security Computing Mechanism Unit is the most important component of a trusted cloud computing system. By integrating various hardening technologies and secure computing components, it provides a unified cloud computing security environment and protection mechanism to achieve high security levels.

[0248] Regarding native applications of trusted cloud computing systems.

[0249] Trusted cloud computing system native applications refer to applications and services that directly utilize trusted cloud computing systems. These applications and services are originally designed and developed based on the security and isolation of trusted cloud mechanisms, aiming to provide a high level of security for computing and data processing with a high level of trusted verification.

[0250] These trusted cloud-native applications provide high-security, trusted-verification-level computing and data processing services by fully leveraging the security performance and trusted verification levels of trusted cloud mechanisms. Users can deploy these applications and services in trusted cloud computing systems to enjoy a higher level of security while reducing security risks and the possibility of data leakage.

[0251] Regarding Trusted Cloud Certificate Management.

[0252] Trusted cloud certificate management is one of the key mechanisms to ensure secure communication and entity / user authentication within a trusted cloud computing system. It involves the generation, issuance, verification, and management of certificates for devices and users.

[0253] In a trusted cloud computing system, the local device unit can provide the following certificates:

[0254] Device Trust Measurement Security Level Certificates: Each vendor of a multi-tiered trusted cloud unit should enhance its security and trust verification level through design, computation, and compliance measures, and sign it using a trust certificate chain. These certificates include evaluation factors such as trusted chips, terminal devices, systems, development environments, virtual machine environments, and applications. The correct trust measurement security level certificate chain is dynamically provided to the certifying party based on the actual environment requirements.

[0255] Device administrators and users' trusted verification level certificate chain: These certificates involve evaluation factors such as user identity ID, user login, enterprise, network, mobile phone, two-factor authentication, bank, and location. Based on actual needs, a trusted measurement security level certificate bound to the device chain is dynamically provided to the authentication party. To protect privacy, unnecessary personal device information certificates should not be disclosed.

[0256] The remote network certificate management technology provided by this invention includes the following aspects:

[0257] PKI / CA Certification Centers: Provide public key infrastructure (PKI) and certificate authority (CA) services for generating and issuing certificates, as well as verifying the validity and integrity of certificates.

[0258] KMS (Key Management Service): Used to generate and manage encryption keys to ensure the confidentiality and integrity of communications.

[0259] HSM (Hardware Security Module): Provides hardware-level key protection and encryption operations to enhance the security of certificates and encryption operations.

[0260] Remote certificate management services are primarily used in cloud computing infrastructure centers to provide unified certificate management services for shared cloud servers and other devices. They communicate with the Trusted Cloud Secure Computing API and offer unified, flexible services such as PKI / CA, KMS, and HSM, mainly used for tenant binding, cloud service migration, and service expansion. However, they cannot replace the root and services of Trusted Cloud Secure Computing on cloud servers and other cloud devices, because cloud service providers may have internal security risks, and such a Trusted Cloud mechanism and root are necessary for all devices.

[0261] The goal of Trusted Cloud Certificate Management technology is to achieve a unified and trusted certificate management mechanism, ensuring secure communication and entity authentication for devices and users in a trusted cloud computing system. It can also be compatible with other secure and trusted ecosystems. For example, Apple terminal devices have a high level of security and trust verification, but users may not be able to obtain their complete security and trust verification certificate chain or a unified certificate format, and can only subjectively assess their security and trust verification level.

[0262] This invention enhances the security and trustworthiness of trusted cloud computing systems by establishing and maintaining a trusted cloud certificate management mechanism, providing more secure and reliable communication and data protection.

[0263] Regarding Trusted Cloud Zero Trust Technology.

[0264] Trusted cloud zero trust, a core component of the trusted cloud security computing mechanism, is a novel security strategy and architecture. It employs principles such as micro-data boundaries, no distinction between internal and external networks, continuous verification, and on-demand upgrading of the trusted verification level. The goal of zero trust is to establish a security model that does not trust any entity, ensuring security through continuous verification and authorization.

[0265] In trusted cloud computing systems, zero trust is achieved through the following methods:

[0266] Micro-data boundaries: This involves subdividing data access and control into smaller units, enabling fine-grained control and authentication of each unit. This reduces potential risks and improves data security and trustworthiness.

[0267] No distinction between internal and external networks: Instead of relying on the traditional distinction between internal and external networks, all access is treated as potentially untrusted behavior, requiring authentication and authorization to obtain access rights. This prevents security vulnerabilities and attacks between internal and external networks.

[0268] Continuous verification: Users, terminals, applications, and connections are continuously verified to ensure their security and trustworthiness. If any factor does not meet the security operation level calculation formula, the security operation level can be improved by providing more information, and appropriate access control and application authorization can be obtained.

[0269] Upgrade Trusted Authentication Level and Authorize Access as Needed: Dynamically upgrade the trusted authentication level as required and authorize access and application permissions accordingly. This allows for flexible management and control of secure access and data applications based on actual needs and risk profiles.

[0270] The key to Trusted Cloud Zero Trust technology is the dynamic security operation level and authorization calculation function. By calculating the trusted verification level of users, terminals, applications and connections, and using it as the input variable for zero trust access control and application authorization, the final security operation level result determines the service range (TDaxd) of zero trust data applications, and provides corresponding levels of data services according to the security operation level.

[0271] Zero Trust and Trusted Measurement security level calculations are uniformly defined into 5 security and trust levels. The results of these level calculations serve as the input variables for zero-trust access control and application authorization. The Dynamic Security Operation Level (TDauth) authorization calculation function is as follows:

[0272] TDauth=MIN(TDuser,TDep,TDapp,TDlink)≥TDaxd≤DSLx;

[0273] These are all dynamic. If the above calculation formula is not met, providing more user, ep (endpoints), app, and link information as needed can improve the security operation level. TDaxd is the service area for zero-trust data applications, and it is also dynamic, providing corresponding levels of data services based on the TDauth level.

[0274] In summary, Trusted Cloud Zero Trust technology is an innovative security technology that achieves fine-grained access control and application authorization through dynamic security operation levels and continuous verification. It provides a more flexible, sophisticated, and trustworthy security model to meet ever-changing security needs and threat environments.

[0275] Regarding the Trusted Cloud Computing Classification.

[0276] In trusted cloud computing systems, trusted cloud computers can be classified according to their data security service levels. The following are some core parameters regarding trusted cloud computer classification:

[0277] Security levels of trusted cloud computers: Trusted cloud computers can be classified and graded according to the security operation levels implemented by their various layers of trusted cloud units. Generally speaking, the security level increases progressively from SL1 (lower) to SL4 (higher). By fully utilizing trusted cloud secure computing technology through integration and hardening, the security and trustworthiness of local trusted cloud computers can be improved.

[0278] Tiered Security Enhancement: To ensure backward compatibility with low-security-level (SL1-SL2) cloud computing applications, trusted cloud secure computing technology can be used to partially, tieredly, and with internal and external network isolation to enhance the security level of trusted cloud computers (SL3-SL4). Through unified quantitative trusted cloud security metric calculations, unknown trusted or low-trusted devices, networks, terminals, and identities will be denied access to high-security-level data application cloud services, even if they are on the same trusted cloud computer, they will not be able to access high-security-level data. Simultaneously, high-security trusted cloud devices and facilities can share low-trust-level infrastructure (such as networks and storage), using encryption to exclusively access high-security trusted verification-level data and application services.

[0279] Security Attacks and Trusted Cloud Secure Computing: Security attacks are ubiquitous and opportunistic. Trusted cloud secure computing, based on the innovation and expansion of trusted computing, has constructed a unified trusted cloud computing technology roadmap and standard. This lays the foundation for the industrialization of trusted cloud security and establishes a framework for trusted cloud security applications. The trusted cloud security operation level calculation has multiple layers of checks, making it difficult for security attacks to penetrate.

[0280] In summary, trusted cloud computing can be categorized according to security levels, and its overall security and trustworthiness can be improved through trusted cloud secure computing technology mechanisms. Data security level becomes central, trusted cloud zero trust is used for access control and authorization, and trusted cloud secure computing provides technical support and a standardized framework for building secure and trustworthy cloud computing.

[0281] About Trusted Cloud Data Services.

[0282] Under the Trusted Cloud Security Computing Mechanism, Trusted Cloud Data Services are protected and evaluated based on Data Security Level (DSLx). The following are some key parameters regarding Trusted Cloud Data Services:

[0283] Data protection and storage: Centered on data, select trusted cloud storage and computing units with appropriate security levels on the cloud server side to ensure that TDserver≥DSLx, or encrypt and store the data.

[0284] Module Design: Design data and application modules to integrate with storage and computing units for unified management and management operations in environments supporting DSLx-related levels, using micro-boundaries to manage these data and application modules.

[0285] Multiple security levels for applications and application services API: Supports different operations such as execution, abstraction, read and write on TDaxd. Through the supported TDaxd (ApplicationExecutionDegree) ranges, it enables application processing at different security levels. TDaxd represents the shared security operation levels supported by the server-side security application API, typically between DSL1 and DSLx. These applications have a security level of SLx and are protected by the security module along with DSLx data. The TDaxd API provides support for different security levels of DSLx data, providing DSLx data processing capabilities for shared applications at different levels. The TDaxd API is a secure and reliable guarantee for DSLx data.

[0286] Trusted Cloud Zero Trust Access Control Unit (AD): AD needs to support TDad≥DSLx for authorization services and support TDauth=MIN(TDuser, TDep, TDapp, TDlink) metric adjustment for Trusted Cloud Zero Trust.

[0287] Trusted Cloud Service IDP Proxy Unit: The IDP proxy unit also needs to support TDidp≥DSLx security services and connect to the relevant network link unit TDlink≥TDaxd, or start encrypted data transmission TDssl≥TDaxd.

[0288] User terminal: The security operation level of the user terminal is TDep=MIN(TDfw, TDos, TDvmm, TDapp), and TDep≥TDuser≥TDaxd is required.

[0289] Data security level-centric service: In an ideal security implementation, the data security level (DSLx) is central, and the storage, processing, and micro-boundaries of related applications and data are isolated within a software-defined server network environment (SLx) of the same security level. Trusted Cloud Zero Trust Access Control and Authorization correspond to data applications within the security level service interval (SLx-SL1). The Trusted Cloud Zero Trust Access Control Unit comprehensively verifies end-to-end network connections, terminal devices, and user identities to ensure that the Trusted Measurement Security Authorization Level (TDauth) is met, or the authorization level is upgraded (TDauth+1), or access is denied.

[0290] In the Trusted Cloud Data Service, the security operation level of each multi-layer Trusted Cloud unit must meet the requirement of TDx≥TDaxd. Otherwise, operations with a data security level of TDaxd will not be possible. Even if only one unit does not meet the requirements, the service will be rejected. This layered approach ensures security.

[0291] The trusted cloud computing system provided by this invention will now be described in conjunction with some scenarios.

[0292] Example 1: Integration of TPM and TC Trusted Cloud Mechanism Units.

[0293] In modular security design, TDtpm represents the TPM chip unit, and TDtc represents the trusted verification level of the trusted cloud mechanism unit. The following relationship exists between these two units:

[0294] Trusted verification level of data and applications protected by the security unit: As a secure isolation unit, the TDtpm protects data and internal applications with a trusted verification level of DSL5. In a typical integrated platform operating system environment, the operating system cannot directly manage high-security-level data within the TDtpm, such as reading or writing TPMEK (Endorsement Key) private keys. Only chip design and manufacturing manufacturers can perform such management operations under strictly specific environments. The operating system can only provide operations within the TDaxd security level service range through TPM security API calls, such as internal operations like private key signature calculations. The security level range of these security APIs is determined by service requirements and can include levels from DSL5 to DSL2, such as super vendor administrator, administrator login, user login, and public levels.

[0295] The security level range of the provided shared application service API: TDaxd (Application Execution Degree) represents the different security operation levels that the server-side security application API can support for application sharing. This security level range can be between DSL1 and DSLx, where DSLx represents the highest data security level that the application can provide. The security level of these applications themselves and their corresponding data are objects protected by the security module. The multiple levels supported by the TDaxd API form a range, simply referred to as the service level range. The same DSLx data can provide APIs with different security level functions to provide DSLx data processing for shared applications of different levels, such as creating, writing, reading, statistics, abstraction, and cryptographic operation results.

[0296] In the TDtpm example, when the TPM chip is integrated into the device platform, its TDaxd security level service range can be DSL4 to DSL2. Within the device's operating system environment, DSL5 level operations, such as resetting the private key, are not possible on the TPM chip.

[0297] As for the TDtc secure isolation unit, its trusted authentication level TDtc is based on the minimum value of TDtpm, TDfw (firmware), and TDos (operating system), where TDtc = MIN(TDtpm, TDfw, TDos). Typically, the TPM chip provides core key management and private key-bound authentication mechanisms for OpenSSL and OpenCryptoki / Chaps, and this part of the API can achieve a security level of SL4. However, the complete trusted cloud mechanism API implementation also depends on the platform firmware and the root and kernel of the operating system, and even the application environment. If the operating system is rooted or enters the development environment, the overall trusted authentication level of TDtc and TDtpm will be affected. However, a small portion of the TPM chip, related keys, private key APIs, and data may still be secure and trusted.

[0298] Therefore, there is an interdependence between TDtpm and TDtc. The trusted verification level of TDtc is affected by TDtpm, TDfw and TDos, while TDtpm, as a security isolation unit, protects data and applications and is at the DSL5 security level.

[0299] Example 2: Scenario of zero-trust financial institutions.

[0300] The trusted cloud computing system provided by this invention supports zero-trust applications. Specifically, applications supporting various Dynamic Trusted Authentication Levels (TDauth) can provide different levels of access control and authentication. Taking a bank customer database application as an example, the following are some typical security levels and corresponding authentication requirements:

[0301] SL5 (Security Level 5): The highest level of data security. Data management and operation at this level can only be performed by relevant personnel within the bank's back office.

[0302] SL4 (Security Level 4): Used for large-value payment transactions, requiring U-shield authentication. In this case, users need to use a U-shield device with SL4-level security authentication capabilities for identity verification to ensure a high level of security.

[0303] SL3 (Security Level 3): Used for payment transactions, requiring two-factor authentication. In this case, users need to complete more than two authentication steps, such as password, fingerprint, or SMS verification code, to provide higher security.

[0304] SL2 (SecurityLevel 2): ​​Used for logging into web pages and browsing user account information. In this mode, users need to perform basic authentication, such as using a username and password, to access web pages and view account information.

[0305] SL1 (SecurityLevel1): Used to display user registration information. In this case, users only need to provide basic identity information, such as username, to display registration information.

[0306] The concept of zero-trust access control in trusted cloud computing can be seamlessly integrated into both server-side and endpoint environments, supporting secure data applications both locally and in the cloud. This means users can securely access data from any location and on any device, enjoying services tailored to their security level. This integration is achieved through trusted cloud security computing mechanisms and related technologies, ensuring secure access and a positive user experience in a zero-trust environment.

[0307] In summary, typical zero-trust applications can provide different levels of access control and authentication based on varying dynamic trust verification levels. The concept of trusted cloud zero-trust access control requires seamless integration between the server and endpoint, while simultaneously supporting secure data applications both locally and in the cloud, to enhance the user experience.

[0308] Example 3: Scenario of enterprise cloud employee authorization service.

[0309] Implementing trusted cloud security computing mechanisms in enterprise-level trusted cloud computing systems can enhance enterprises' security management and access control over cloud employees, ensuring data and system security. The following are some methods and measures for implementing trusted cloud security computing mechanisms to help enterprises effectively manage cloud employees:

[0310] Identity authentication and access control: Implement robust identity authentication mechanisms such as multi-factor authentication, single sign-on (SSO), and access tokens. This ensures that only authorized employees can access enterprise cloud resources. Simultaneously, the security and trustworthiness of employee devices is crucial. Device security can be ensured through dedicated trusted chips, platforms, and identity binding, which will determine the highest level of data security that employee can access within the enterprise.

[0311] Data encryption and isolation: For highly sensitive data, whether stored locally on the device or in the enterprise data service center, encryption technology is used to protect the data and ensure its confidentiality during transmission and storage. Furthermore, trusted cloud zero-trust micro data boundary technology can also be used for data isolation, ensuring that only authorized employees with sufficient security and trust verification capabilities can access sensitive data.

[0312] Access Management and Control: Establish a strict access management mechanism to ensure that cloud employees can only access the resources and data they need. Use a role-based access control (RBAC) model to grant permissions to specific job responsibilities, preventing excessive or abusive access.

[0313] It is important to note that all the aforementioned security mechanisms and related multi-layered trusted cloud units are built upon the trusted root of the trusted cloud security computing mechanism. Their security and trust verification levels require certificate authentication, including for terminal devices, user identities, networks, enterprise private cloud data centers, servers, zero-trust access control mechanisms, cloud applications, and cloud data. Only when all relevant units meet the corresponding security service level requirements can they access the relevant data services.

[0314] In summary, by implementing trusted cloud security computing mechanisms, enterprises can effectively manage the security and permissions of cloud employees, and protect sensitive data and system resources from unauthorized access and misuse. These measures require comprehensive consideration of technology, strategies, and personnel training to establish a comprehensive cloud security management framework.

[0315] Regarding the implementation method of the trusted cloud computing system provided by this invention.

[0316] The trusted cloud computing system technology provided by this invention is a comprehensive technical approach that "dredging" the way forward. It follows the natural development direction of cloud network information security, namely resource sharing and isolation. Through a unified, complete, standardized, open, and robustly integrated trusted cloud security computing technology, it acts like a solid embankment, using the trusted foundation of equipment and unified network security standards to extend and irrigate local or surrounding shared applications. This promotes cooperation and mutual benefit, guiding this secure and reliable information torrent into the East China Sea and contributing to the global internet for all humanity. It is not a purely patchwork solution that "blocks" the way forward: using dedicated networks, dedicated terminals, and dedicated servers for physical isolation. It is not about patching local or point-by-point issues after security problems arise, nor is it about building embankments based solely on individual riverbed elevation differences or river section directions—the result of which is self-evident.

[0317] An open-source implementation of a trusted cloud computing system.

[0318] The trusted cloud security computing mechanism (the application functions corresponding to the trusted cloud computing system) provided by this invention can be implemented and promoted in an open-source manner, for example:

[0319] Trusted Computing TPM2.0: Microsoft open-sourced its TPM2.0 software simulator, and Google open-sourced the OpenTitanTPM2.0 project. These open-source projects make TPM2.0's functionality more transparent and verifiable, promoting the popularization and application of its standards.

[0320] Trusted Cloud Network Security Computing SSL / TLS: OpenSSL is a widely used open-source SSL / TLS protocol library that provides encryption and authentication functions. For example, OSCHINA is an open-source communication community, and Peking University promoted the GMSSL national cryptographic open-source project. These projects have played an important role in ensuring communication security.

[0321] Trusted Cloud Confidential Computing PKCS#11: IBM has open-sourced OpenCryptoki or Google Chrome Chaps, supporting its own IBM ZEP11 token series hardware environment, democratizing large-scale business confidential computing capabilities. Additionally, SoftHSM2 is also an open-source PKCS#11 cryptographic machine implementation, providing complete code and transforming it into a hardware-secure module cryptographic machine through dedicated physical encapsulation. These open-source projects make the use of cryptographic devices more secure and trustworthy, playing a crucial role in protecting keys and executing cryptographic operations.

[0322] This invention uses dedicated physical devices and chips to protect key secrets such as keys, root private keys, signature authentication cryptographic function operations, and random number generation. This enables trusted cloud secure computing devices to provide cryptographically unbreakable protection. The open-source approach makes the technology more transparent and auditable, providing a foundation for long-term security and trustworthiness.

[0323] A unified security interface for trusted cloud computing systems.

[0324] Establishing a unified trusted cloud secure computing interface is crucial to enabling secure and reliable communication and collaboration between different trusted cloud devices. By defining a minimal secure interface API, functions such as handshakes, encrypted transmission, key generation and management, certificate format management, and PKI / CA certificate authentication and management between devices can be performed securely and reliably.

[0325] Establishing a unified trusted cloud secure computing interface language can have a similar impact on the security and trustworthiness of cloud network information. Such a unified interface will provide a common foundation for trusted cloud computing, ensuring secure and reliable interaction and sharing between different devices and systems. Through a unified interface, trusted cloud devices can verify each other's security and trustworthiness levels and share data at corresponding security levels. This will help improve the overall security and trustworthiness of cloud network information systems, and the unified interface language will also help promote the development of trusted cloud secure computing, facilitating technology standardization and interoperability.

[0326] Therefore, this invention establishes a unified trusted cloud secure computing interface language, which is crucial for promoting the development of cloud network information security and trustworthiness. It will provide greater opportunities for cooperation and innovation in the field of trusted cloud computing and provide a solid foundation for the security and trustworthiness of information systems.

[0327] Controllable does not equate to safe and reliable.

[0328] Controllability is not the same as security and trustworthiness, because controllability is only one aspect of security, while security and trustworthiness also require consideration of other factors. The following is a further explanation of controllability, insider threats, and security and trustworthiness:

[0329] Controllability: Controllability refers to the ability to manage and control a system, network, or data. In the field of information security, controllability means the ability to implement necessary security measures to protect systems and data, including access control, permissions management, and security policies. The existence of controllability can help organizations effectively respond to security threats and risks.

[0330] Security and trustworthiness: Security and trustworthiness refer to the security and reliability of a system, network, or data. It involves not only technical protective measures but also factors such as organizational management practices, personnel security awareness, and security culture. Security and trustworthiness require systems to maintain a high degree of integrity, confidentiality, and availability in the face of various threats and attacks, and to withstand internal and external audits and verifications.

[0331] Insider: An insider is an individual or entity within an organization who uses their position and authority to sabotage, steal, or leak sensitive information. Insiders may be malicious employees, partners, or external attackers who gain unauthorized access. Insider threats are a significant security challenge for organizations because they can exploit legitimate access to launch various attacks.

[0332] In reality, even with a certain degree of controllability, complete security and reliability cannot be guaranteed. Here are some reasons:

[0333] Insider threat: Insiders may abuse their access privileges to engage in malicious activities, such as stealing sensitive information, damaging systems, or providing unauthorized access. This poses a significant threat to security and trustworthiness.

[0334] Misconfiguration: Even if a system is technically controllable, incorrect configuration and management can expose it to risks and attacks. Misconfiguration errors may include weak passwords, failure to update security in a timely manner, and incorrect access control settings.

[0335] External attacks: Even with strict internal controls and management, external attackers can still gain access to the system through vulnerability exploitation, social engineering, and other methods. These attacks may bypass internal control measures.

[0336] Therefore, achieving security and trustworthiness requires a comprehensive consideration of technical, managerial, and human factors. This includes implementing appropriate security controls, conducting continuous security assessments and monitoring, cultivating employee security awareness, and establishing appropriate security strategies and processes to prevent insider threats and external attacks.

[0337] Furthermore, controllability is highly subjective rather than purely technical. What is controllable by one group may not be what other groups wish to be controllable, so it is not equivalent to security and trustworthiness, much less to privacy protection.

[0338] The foundation of trusted technology is a secure root of trust.

[0339] Trusted computing is a computing model and technology built on a secure root of trust, designed to protect data and applications in a computing environment from malicious attacks and unauthorized access. The following is a further explanation of trusted computing technology:

[0340] Trusted Root Foundation: The foundation of trusted computing technology is the trusted computing infrastructure, which includes hardware and software components designed to provide a secure and trusted computing environment. These components typically include Trusted Platform Modules (TPMs), security chips, Trusted Execution Environments (TEEs), etc. The design and implementation of the trusted root foundation aims to ensure the integrity, confidentiality, and availability of the computing environment, and to provide trusted measurement and verification of computing processes and data.

[0341] Security protection mechanisms: Trusted computing technology protects the computing environment through multiple security protection mechanisms. These include:

[0342] Secure Boot and Verification: The secure boot process ensures that the computer system's software and firmware have not been tampered with or replaced by malware. The verification process uses technologies such as digital signatures and hash algorithms to verify the integrity and trustworthiness of the boot environment.

[0343] Encrypting and protecting data: Trusted computing technologies use encryption algorithms and security protocols to protect the confidentiality and integrity of data. Sensitive data can be protected during the computing process to prevent unauthorized access and tampering.

[0344] Access control and authentication: Trusted computing technologies provide robust access control mechanisms to ensure that only authenticated and authorized users can access protected resources and functions. This includes using authentication technologies (such as two-factor authentication) and access control policies to restrict access to systems and data.

[0345] Security Isolation: Trusted computing technology uses isolation mechanisms to separate different computing tasks and applications to prevent malware or attackers from spreading from one application or task to the entire computing environment.

[0346] Trusted Measurement and Verification: Trusted computing technology provides mechanisms for trusting and verifying the computing environment and execution processes. By using components such as the Trusted Platform Module (TPM), trust metrics of the computing environment can be generated and verified, such as the integrity of the startup process and the trusted state of the software. These trust metrics can be used to ensure that the system operates in a normal and trusted state.

[0347] Trusted Computing Applications: Trusted computing technology has wide applications in many fields, including cloud computing, the Internet of Things (IoT), and mobile devices. In cloud computing, trusted computing technology can provide secure computing resources and data isolation to protect user privacy and sensitive data. In the Internet of Things (IoT), trusted computing technology can ensure the security of devices and communications to prevent unauthorized access and attacks.

[0348] In summary, the trusted computing technology of this invention, built upon a secure root of trust, provides a series of security protection mechanisms, trust metrics, and verification mechanisms to ensure the security and trustworthiness of the computing environment. The application of this technology can effectively prevent malicious attacks and unauthorized access, protecting the security of data and computing resources.

[0349] Regarding the generalization of trusted cloud computing systems.

[0350] The generalization of trusted cloud computing systems refers to the comprehensive development of trusted computing, trusted verification levels, encryption, and other technologies in the field of trusted cloud secure computing. The following is a further explanation of several key points mentioned:

[0351] The convergence of trusted cloud secure computing: making cloud secure computing technologies more robust, trustworthy, secure, high-speed, unified, and complete. This means that in the cloud computing environment, various secure computing technologies should be better integrated and combined to form a unified security framework, providing more powerful, secure, trustworthy, and efficient security protection.

[0352] Unified integration of local and network security device services: This involves merging and unifying the security device services of local devices and network services. For example, local devices can be bound to trusted computing modules (such as TPM), secure sockets (SSL), and cryptographic mechanisms (PKCS#11), while network services can be bound to key management services (KMS), hardware security modules (HSM), identity access management (IAM), active directory (AD), etc.

[0353] Unifying Trust Measurement Calculation with a Trusted Authentication Level Certificate Chain Mechanism: By introducing a trusted authentication level certificate chain mechanism, quantitative trust measurement calculations are performed on various units such as end-to-end terminal devices, users, networks, facilities, and services. Appropriate authorization and permissions are assigned to each entity based on the security level of the application and data.

[0354] Trusted cloud secure computing: Deeply, widely, and comprehensively promote trusted cloud computing and apply it to all devices. This means that the concept and technology of trusted cloud secure computing should be popularized in various devices and systems, whether mobile devices, edge devices, or cloud servers, all of which should have the capabilities of trusted computing and trusted security protection.

[0355] Universal Trusted Authentication Level Calculation and Authentication: This approach applies trusted authentication level calculation and authentication to various entities, including entity identities, devices, enterprises, banks, biometrics, systems, and applications. By calculating and authenticating the security operation levels of these entities, it ensures that they meet relevant security standards and requirements.

[0356] Widespread encryption protects all data, both static and dynamic: Encryption techniques are extensively used to protect statically stored data, dynamically transmitted data, and in-memory computational data. Whether data is on static storage media, during transmission, or during computation, it should be appropriately encrypted to ensure its confidentiality and integrity.

[0357] By promoting and applying trusted cloud generalization, the security and trustworthiness of the entire cloud computing environment can be improved, the security of various devices and data can be protected, and a unified standard and mechanism can be provided for entity authentication and secure authorization.

[0358] In summary, through a unified and generalized trusted cloud secure computing shared isolation unit mechanism, a complete industrialization route for high-security information is provided for data transmission of all cloud network devices, data storage encryption of all devices, and entity identity authentication.

[0359] Summary of trusted cloud computing systems.

[0360] In summary, the trusted cloud computing system of this invention is a comprehensive information security technology designed to enhance the trustworthiness, confidentiality, and integrity of computer systems and cloud computing environments, and includes at least the following key technologies:

[0361] The strategic direction for cloud network information security is as follows: from abstract concepts of security and trustworthiness to cryptographic theory and secure computing technology, then to quantitative trusted cloud secure computing methods, and finally back to the data application of all trusted cloud mechanisms and trusted verification levels.

[0362] Cloud core security and trust issues: Solving the balance between information sharing and security isolation, especially in networked, cloud-based and virtualized environments, by unifying the framework and priorities of trusted cloud security computing, and achieving a unified and technically feasible security and trust verification hierarchy solution.

[0363] Trusted cloud secure computing technology: This integrates hardened, standard open-source, and converged trusted cloud secure computing network technologies, including Trusted Computing TPM, OpenSSL / TLS, PKCS#11 / OpenCryptoki / Chaps, and TDx. It also unifies the relationship between trusted security level metrics, certificate chain management, and trusted cloud computing security verification levels.

[0364] Unified extensions for trusted cloud secure computing: Unified extensions have been implemented in trusted cloud device units, trusted cloud device extensions, trusted cloud computing system kernel extensions, trusted cloud service extensions, trusted cloud data object extensions, trusted cloud zero-trust network extensions, and software-defined cloud extensions. This includes extensions to various devices, systems, virtual machines, applications, and infrastructure virtual machines, platform systems, and application software; as follows:

[0365] Security Risk Assessment and Dynamic Authorization: A security risk assessment mechanism is introduced to dynamically evaluate identities, terminal devices, and applications to achieve dynamic trust level calculations. Based on the assessment results, dynamic authorization and adjustments are made to ensure that only legitimate and trusted entities can access sensitive data and resources.

[0366] Trusted Cloud Zero Trust Network Extension: In trusted cloud secure computing, the concept of Zero Trust Network is adopted. Trusted authentication of terminal devices and applications is implemented, combined with dynamic risk assessment and trust level calculation, to achieve fine-grained control and isolation of network communication, thereby improving the overall system security.

[0367] Software-Defined Cloud Expansion: Further advance the development of Software-Defined Cloud by virtualizing computers, storage devices, and network devices, and employing technologies such as NFV (Network Function Virtualization), vSwitch, VLAN (Virtual Local Area Network), and VxLAN (Virtual Extensible LAN) to achieve a flexible and adjustable cloud computing environment, while strengthening the characteristics of trusted cloud secure computing.

[0368] Through these extensions, the trusted cloud security computing mechanism can more comprehensively address the security challenges in cloud computing environments, achieving a higher level of trustworthiness, confidentiality, and integrity protection. This will provide users and organizations with more secure and reliable cloud sharing services, promoting the sustainable development of cloud computing.

[0369] The Trusted Cloud Computing System provided by this invention is a comprehensive information security technology for enhancing the trustworthiness, confidentiality, and integrity of computer systems and cloud computing environments. The four types of secure computing in Trusted Cloud (Trusted, Cybersecurity, Confidentiality, and Measurement) are specifically designed for the trustworthiness and security of cloud information system infrastructure and equipment platforms, providing a complete Trusted Cloud secure computing shared isolation level security unit for cloud computing.

[0370] Figure 2 This is another network topology diagram of the trusted cloud computing system provided by the present invention, by Figure 2 It is understood that the trusted cloud computing system provided by the present invention includes various other trusted devices such as terminal device 10, access device 20, network device 30, cloud server device 40, and data server device 50, as well as a trusted cloud mechanism module 60 integrated in all devices of the trusted cloud computing system; the trusted cloud mechanism module 60 includes at least:

[0371] The trusted computing module 61 is used to perform security and trust measurement processing on all devices in the trusted cloud computing system and obtain the trust measurement results of each device.

[0372] The Trusted Cloud Security Computing Module 62 is used to perform encrypted, secure, and trusted processing on the transmission protocols of all end-to-end connections in the Trusted Cloud Computing System.

[0373] The trusted cloud confidential computing module 63 is used to perform encrypted, secure, and trusted processing on the input and output of all data in the trusted cloud computing system.

[0374] The Trusted Cloud Measurement Calculation Module 64 is used to uniformly evaluate, calculate and classify each device based on the trust measurement results of each device in the Trusted Cloud Computing System, so as to obtain the security and trust verification level of each device.

[0375] In some other embodiments of this application, the trusted cloud mechanism module 60 also includes a certificate management module for unified management of access certificates for the interfaces of all devices; in this case, each device is equipped with a security and trust metric level certificate provided by the trusted cloud device manufacturer.

[0376] In other embodiments of this application, the trusted cloud mechanism module 60 further includes a request management module, which controls the cloud server to respond to the zero-trust access request based on the security control level of the zero-trust access request and the security and trust verification level of the cloud service entry point.

[0377] In this invention, all functional modules in the Trusted Cloud Mechanism Module 60 can be implemented using dedicated hardware or software. Preferably, when implemented using software, the Trusted Cloud Mechanism Module 60 is a Trusted Cloud Secure Computing Management Mechanism, or Trusted Cloud Mechanism for short, which is implemented by programs running on all devices in the Trusted Cloud Computing System, meaning that corresponding security functions run on all devices in the Trusted Cloud Computing System.

[0378] In summary, this invention provides a trusted cloud computing system. This trusted cloud computing system includes a trusted cloud mechanism module comprising: a trusted computing module for performing security and trust measurement processing on devices to obtain the trusted measurement results of the devices; a trusted cloud network security computing module for performing encrypted security and trust processing on the transmission protocols of all end-to-end connections in the trusted cloud computing system; a trusted cloud confidentiality computing module for performing encrypted security and trust processing on the input and output of all data in the trusted cloud computing system; and a trusted cloud measurement computing module for performing unified evaluation, calculation, and classification processing on each device based on the trusted software measurement results of each device in the trusted cloud computing system to obtain the security and trust verification level of each device. In the solution provided by this invention, the trusted cloud mechanism module performs unified management of security and trust measurement on all devices within the trusted cloud computing system, allowing users to clearly understand the security and trust verification levels of the computing resources, cloud services, and data they use. This makes the security levels of various resources in the trusted cloud computing system perceptible to users, improving the user experience.

[0379] In the several embodiments provided in this invention, it should be understood that the disclosed systems and methods can also be implemented in other ways. The system and method embodiments described above are merely illustrative.

[0380] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0381] While the embodiments disclosed in this invention are as described above, the content is merely for the purpose of facilitating understanding of the invention and is not intended to limit the invention. Any person skilled in the art to which this invention pertains may make any modifications and variations in form and detail of the implementation without departing from the spirit and scope disclosed herein; however, the scope of patent protection for this invention shall still be determined by the scope defined in the appended claims.

Claims

1. A trusted cloud computing system, characterized by, The trusted cloud computing system comprises a trusted cloud mechanism module integrated in all devices in the trusted cloud computing system; The trusted cloud mechanism module comprises: a trusted computing module for performing secure and trusted measurement processing on a device to obtain a trusted measurement result of the device; a trusted cloud network security computing module for performing encrypted and secure and trusted processing on a transmission protocol of all end-to-end connections; a trusted cloud secret computing module for performing encrypted and secure and trusted processing on input and output of all data; a trusted cloud measurement computing module for determining a secure and trusted verification level of each device according to the trusted measurement result of each device; a request management module for controlling the cloud server to respond to a zero-trust access request according to a secure control level of the zero-trust access request and a secure and trusted verification level of an entrance of the cloud server; wherein the secure and trusted verification level is used for unified measurement, and the trusted cloud mechanism module is hardened, fused and integrated to form a unified trusted cloud security computing system with conventional terminal devices, access devices and cloud servers; The trusted cloud measurement computing module is further configured to: subdivide the cloud computing system into a plurality of multi-layer trusted cloud units according to device functions of the devices, perform unified quantitative calculation and grading on secure and trusted fuzzy concepts of all the multi-layer trusted cloud units, and the multi-layer trusted cloud units comprise device component units, secure isolation units and cloud facility integrated units; the unified quantitative calculation and grading on the secure and trusted fuzzy concepts of all the multi-layer trusted cloud units comprises: determining a device secure and trusted level of a device according to a preset device secure and trusted level standard, and determining a data secure level of data according to a data privacy standard; wherein the determining the device secure and trusted level of the device according to the preset device secure and trusted level standard comprises: sorting the device secure and trusted levels of all component units in each multi-layer trusted cloud unit respectively, and determining a device secure and trusted level of a device with the lowest device secure and trusted level as a secure and trusted verification level of a corresponding multi-layer trusted cloud unit; and the determining the data secure level of the data according to the data privacy standard comprises: determining a lowest secure and trusted verification level of device component units, secure isolation units and cloud facility integrated units between ends of a data link as a link secure and trusted verification level of the data link between the ends according to the secure and trusted verification levels of the device component units, the secure isolation units and the cloud facility integrated units between the ends of the data link; The trusted cloud measurement computing module is further configured to: determine the link secure and trusted verification level of the data link and a data secure level of target data according to a data request, and judge whether the link secure and trusted verification level is within the data secure level range; if yes, the cloud server is allowed to respond to a service operation corresponding to the data request, and if no, the cloud server is refused to respond to the service operation corresponding to the data request.

2. The trusted cloud computing system of claim 1, wherein, Each device is provided with a secure and trusted measurement level certificate provided by a trusted cloud device manufacturer, and the trusted cloud mechanism module further comprises a certificate management module for uniformly managing access certificates of interfaces of the devices.

Citation Information

Patent Citations

  • Network security protection system based on flow monitoring

    CN115589322A