A privacy computing method and system based on TEE
Patent Information
- Application Number
- CN202311180338.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-13
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-09-13
AI Technical Summary
[0020]为此,本申请提供一种基于TEE的隐私计算方法和系统,以解决现有技术存在的客户节点的计算负担重和网络交互量大且扩展性差等问题
[0046]1、一种基于TEE的隐私计算方法,通过客户节点验证存储enclave,存储enclave代理验证计算enclave,从而简化客户节点的负担和交互量,降低客户节点的同步、同时在线的要求;且采用存储和计算分离方式可以保证数据的安全性。
Smart Images

Figure CN117235789B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of privacy computing technology, specifically to a privacy computing method and system based on TEE. Background Technology
[0002] Privacy-preserving computation refers to a series of techniques for processing data while protecting the privacy of the input data. Currently, the main privacy-preserving computation techniques include multi-party secure computation using cryptographic protocols, homomorphic encryption, federated learning, and trusted execution environments using trusted hardware.
[0003] A Trusted Execution Environment (TEE) is a secure execution environment used to protect sensitive data and perform critical operations. A TEE provides an isolated execution environment, typically implemented through a combination of hardware and software, designed to run specific trusted applications on computing devices, ensuring these applications execute in a protected environment and preventing unauthorized access and malicious attacks.
[0004] The main features and functions of TEE include:
[0005] Isolation: TEE provides an execution environment isolated from the operating system and other applications. This means that applications running in a TEE cannot be accessed or interfered with by other applications or malware, thus protecting the security of sensitive data and critical operations.
[0006] Security Verification: TEEs ensure the trustworthiness of applications by verifying their origin and integrity. This typically involves using digital certificates or code signing to verify the authenticity of the application and prevent the injection and execution of malicious applications.
[0007] Secure Storage and Processing: TEE provides secure storage and processing mechanisms to protect sensitive data. It offers hardware-level encryption and decryption capabilities to ensure the confidentiality and integrity of data during storage and processing.
[0008] Secure Communication: The TEE provides a secure communication channel to protect data transmission between the TEE and other trusted entities. This ensures the confidentiality and integrity of data during transmission, preventing data leakage or tampering.
[0009] Trusted Computing: TEE provides trusted computing capabilities, meaning computational operations can be performed in a trusted environment. This allows sensitive data to be computed without being exposed to the operating system and other applications, providing enhanced security and privacy protection.
[0010] TEE (Trusted Execution Environment) is widely used in mobile devices (such as smartphones and tablets), IoT devices, embedded systems, and cloud servers. It protects sensitive user data on mobile devices, preventing access from malicious applications and attackers. In IoT devices, TEE ensures secure communication and data exchange between devices. In cloud servers, TEE provides a trusted computing environment, protecting sensitive data and critical operations in the cloud.
[0011] Currently, specific TEE implementation solutions include Intel SGX and AMD SEV, among others.
[0012] Intel Software Guard Extensions (SGX) is a security extension technology introduced by Intel that aims to provide hardware-level isolation and protection, ensuring that applications run in a protected execution environment and protecting their code and data from unauthorized access and tampering.
[0013] The main features and functions of Intel SGX include:
[0014] Isolation and Protection: Intel SGX utilizes CPU-level hardware expansion to create an isolated environment called an "enclave." An enclave is a protected area of memory where code and data can only be accessed by authorized applications. Through hardware-level memory encryption and access control, Intel SGX protects code and data within the enclave from malware and operating system interference.
[0015] Security Verification and Authentication: Intel SGX uses hardware-based digital signatures and verification mechanisms to ensure the authenticity and integrity of secure zones. Each secure zone has a unique identifier that can be used to verify its origin and integrity, preventing the injection and execution of malicious secure zones.
[0016] Encryption and Decryption: Intel SGX provides hardware-level encryption and decryption capabilities to protect data in secure zones. Secure zones can use dedicated keys for encryption and decryption, ensuring data confidentiality in memory.
[0017] Secure Remote Authentication: Intel SGX supports a secure remote authentication mechanism, allowing verification of the trustworthiness of remote secure zones. By using the remote authentication protocol, other entities can verify the identity and integrity of remote secure zones, establishing a secure communication and collaboration environment.
[0018] High performance and ease of use: Intel SGX is designed as a high-performance security solution, minimizing its impact on application performance. Furthermore, it provides an easy-to-use software development kit (SDK) to help developers easily use Intel SGX to build secure applications.
[0019] However, existing TEE implementations have high computational burden and network interaction volume on client nodes, requiring client nodes to be synchronous and online simultaneously, resulting in poor performance. Furthermore, existing TEE implementations are difficult to scale, making it difficult to construct business solutions and limiting applicable scenarios. Summary of the Invention
[0020] To address these issues, this application provides a privacy-preserving computation method and system based on TEE, thereby resolving problems such as heavy computational burden on client nodes and large network interaction volume with poor scalability in existing technologies.
[0021] To achieve the above objectives, this application provides the following technical solution:
[0022] Firstly, a privacy-preserving computation method based on TEE includes:
[0023] Step 1: Receive the computing service request and task agreement initiated by the client node of the initiating party;
[0024] Step 2: Invite client nodes that require authorization as specified in the task agreement and send the task agreement.
[0025] Step 3: Receive the task consent form signed by the authorized client node using its private key, and start the storage enclave corresponding to each client node; the storage enclave pre-stores the hosting declaration and dataset of the corresponding client node;
[0026] Step 4: Start the enclave calculation;
[0027] Step 5: Send the task agreement and computation enclave information to all storage enclaves; each storage enclave and its corresponding client node remotely verify each other. After successful verification, each participating client node sends the task agreement to its corresponding storage enclave again; the storage enclave extracts data according to the data requirements in the task agreement and the authorization policy in the hosting statement, and verifies with the computation enclave. After successful verification, the storage enclave sends the task agreement to the computation enclave; the computation enclave checks whether all task agreements are consistent. If they are consistent, each storage enclave sends the dataset of the corresponding client node to the computation enclave; the computation enclave receives the datasets sent by all storage enclaves and confirms whether the client node identity is consistent with the task agreement. If they are consistent, it starts the computation according to the computation script in the task agreement. After the computation is completed, it sends the computation result to the corresponding storage enclave in the task agreement; the storage enclave archives the result or forwards it to the corresponding client node.
[0028] Preferably, step 3, which involves pre-storing the hosting declaration and dataset of the corresponding client node in the storage enclave, includes the following steps:
[0029] The system receives a secure storage request from a client node and starts a storage enclave based on the request. The client node remotely verifies the storage enclave. After successful verification, the client node sends a hosting declaration to the storage enclave and digitally signs the hash value of the hosting declaration and the dataset. The storage enclave contacts the CA service node to verify the hosting declaration. After successful verification, the storage enclave seals the client node's hosting declaration and the corresponding dataset.
[0030] Receive the managed declaration sent by the storage enclave and record the correspondence between the data storage of the client nodes and the storage enclave.
[0031] Preferably, in step 5, when the storage enclave extracts data according to the data requirements of the task agreement and the authorization policy in the hosting statement, it directly extracts datasets without an authorization policy; for datasets authorized by specific applications, it checks whether the calculation script in the task agreement is in the list of agreed applications; for datasets requiring authorization, it verifies whether the task agreement sent by the client node is consistent with the task agreement sent by the management node, and if they are consistent, it extracts the corresponding dataset.
[0032] Preferably, when the computation enclave is in cluster mode, all computation enclaves form a tree structure, and the storage enclave starts from the root node of the tree structure and performs remote verification of the computation enclaves of its lower nodes in turn.
[0033] Preferably, after mutual verification between computational enclaves in a tree structure, the upper-level computational enclave securely sends the key to the child computational enclave.
[0034] Preferably, in the tree structure, the communication information between every two computed enclaves needs to be accompanied by a counter value for communication synchronization.
[0035] Preferably, after the enclave is calculated, log text and a random key are generated. The log text is then encrypted using the random key to obtain ciphertext. The random key is then split and sent to each storage enclave separately.
[0036] Preferably, the random key is split using mn secret sharing.
[0037] Preferably, when the number of participants exceeds a predetermined threshold, the enclave is calculated to recover the random key, and the locally sealed log ciphertext is desealed based on the random key.
[0038] Secondly, a privacy-preserving computing system based on a TEE (Transmission Equipment) is provided, wherein the TEE-based privacy-preserving computing system is used to implement the aforementioned TEE-based privacy-preserving computing method, comprising:
[0039] Client nodes are used to initiate business requests to management service nodes;
[0040] The management service node is used to respond to service requests from client nodes, manage compute enclave nodes and storage enclave nodes, and is also responsible for issuing announcements and other coordination tasks.
[0041] CA service nodes are used for authentication of client nodes.
[0042] And for client nodes to verify the software running in compute enclave nodes and storage enclave nodes;
[0043] Multiple storage enclave nodes are used for secure storage of client node data;
[0044] Multiple compute enclave nodes are used for secure computation on client nodes.
[0045] Compared with the prior art, this application has at least the following beneficial effects:
[0046] 1. A privacy-preserving computation method based on TEE, which simplifies the burden and interaction of client nodes by having client nodes verify the storage enclave and the storage enclave proxy verify the computation enclave, thereby reducing the requirements for client node synchronization and simultaneous online operation; and the separation of storage and computation can ensure data security.
[0047] 2. A privacy-preserving computing system based on TEE can be used in data exchanges, as well as by large data owners and big data service providers. It is easy to implement privacy-preserving computing and easy to scale performance and scale. Attached Figure Description
[0048] To more intuitively illustrate the prior art and this application, several exemplary figures are provided below. It should be understood that the specific shapes and structures shown in the figures should not generally be regarded as limiting conditions for implementing this application; for example, based on the technical concept disclosed in this application and the exemplary figures, those skilled in the art are able to easily make conventional adjustments or further optimizations to the addition / reduction / classification, specific shapes, positional relationships, connection methods, size ratios, etc. of certain units (components).
[0049] Figure 1 A flowchart of a privacy computing method based on a TEE (with a management service node as the execution subject) provided for Embodiment 1 of this application;
[0050] Figure 2 A flowchart of a privacy-preserving computation method based on TEE (bidirectional interaction between storing the enclave and computing the enclave) provided for Embodiment 1 of this application;
[0051] Figure 3 This is a schematic diagram of a privacy computing system based on TEE provided in Embodiment 2 of this application. Detailed Implementation
[0052] The present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0053] In the description of this application: unless otherwise stated, "a plurality of" means two or more. The terms "first," "second," "third," etc., in this application are intended to distinguish the objects referred to and do not have any special meaning in terms of technical connotation (e.g., they should not be construed as an emphasis on importance or order). Expressions such as "comprising," "including," and "having" also mean "not limited to" (certain units, components, materials, steps, etc.).
[0054] The terms used in this application, such as "upper," "lower," "left," "right," and "middle," are generally used to facilitate intuitive understanding by referring to the accompanying drawings, and are not absolute limitations on the positional relationships in the actual product. Changes in these relative positional relationships, without departing from the technical concept disclosed in this application, should also be considered within the scope of this application.
[0055] Example 1
[0056] The goal of this embodiment is to build a computational method for secure collaborative data analysis by multiple participants, applicable to large data owners, big data service providers, and data exchanges. Its features include ease of implementation in diverse privacy-preserving computation applications and easy scalability and performance enhancement of the platform.
[0057] Please see Figure 1 This embodiment provides a privacy-preserving computation method based on a TEE, including:
[0058] S1: Receive computing service requests and task agreement initiated by the client node of the initiating party;
[0059] Specifically, a client node (i.e., the initiating client node) sends a computation service request to the management service node and submits a task agreement. The task agreement may contain the following information: service number, time limit, participants (including the initiator and the result recipient), dataset description, dataset classification, dataset checksum (hash value), task script (Python script for processing the dataset), processing of task results and outputs, and various other configurations.
[0060] S2: Invite client nodes that require authorization in the task agreement and send the task agreement;
[0061] Specifically, the management service node sends an invitation to the client node that needs to use the authorization in the task agreement and sends the task agreement.
[0062] S3: Receive the task consent form signed by the authorized client node using its private key, and start the storage enclave corresponding to each client node; the storage enclave pre-stores the hosting declaration and dataset of the corresponding client node;
[0063] It should be noted that in this embodiment, "enclave" refers to trusted software running in a TEE created using Intel SGX technology. Although this embodiment uses relevant Intel SGX terminology, it is not limited to a specific hardware platform.
[0064] Specifically, each authorized client node receives a task consent form issued by the management service node, reviews the consent form locally, checks its security, and simulates the execution of the task script. If an authorized client node needs to participate in the computation task, it signs the consent form using its private key and sends it to the management service node. The management service node then starts the storage enclave corresponding to each participating client node.
[0065] More specifically, in this embodiment, the storage enclave pre-stores the hosting declaration and dataset of the corresponding client node. The specific process of a client node securely storing data in the storage enclave includes:
[0066] S301: Receives a security storage request initiated by a client node and starts the storage enclave according to the security storage request;
[0067] Specifically, the client node initiates a secure storage request to the management service node, and the management service node starts the storage enclave. The client node remotely verifies the storage enclave. After successful verification, the client node sends a hosting declaration to the storage enclave and digitally signs the hash value of the hosting declaration and the dataset. The storage enclave contacts the CA service node to authenticate the hosting declaration. After successful authentication, the client node's hosting declaration and the corresponding dataset are sealed.
[0068] The hosting statement includes a data description, duration, and authorization policy. Authorization policies can be categorized into three types: no authorization policy, application-specific authorization policy, and authorization-required policy. These three policies indicate the permissions of various types of applications to use specific data. Application-specific applications refer to standard applications that are common to the system and have been tested. These types of applications have clearly defined privacy protection and security consensus for client nodes. For customized applications, the client node should determine whether data security can be guaranteed. This refers to whether the application's computation results will leak privacy. While the computation process within the TEE is certainly protected, clients may be able to deduce private information from the computation results. Preventing this possibility requires review by business personnel.
[0069] S302: Receive the managed declaration sent by the storage enclave and record the correspondence between the data storage of the client node and the storage enclave;
[0070] Specifically, the storage enclave submits the hosting declaration and dataset to the management service node while sealing the hosting declaration. The management service node records the correspondence between the client node's data storage and the storage enclave. Other operations performed by the client node on the storage enclave include data operation requests such as adding, deleting, modifying, and querying data.
[0071] S4: Start the enclave computation;
[0072] Specifically, the management service node starts computing the enclave.
[0073] S5: Send the task agreement and computation enclave information to all storage enclaves.
[0074] Please see Figure 2 Each storage enclave remotely verifies with its corresponding client node. After successful verification, each participating client node resends the task agreement to its corresponding storage enclave. The storage enclave extracts data according to the data requirements in the task agreement and the authorization policy in the hosting statement, and verifies with the compute enclave (which can be done remotely or locally). After successful verification, the storage enclave sends the task agreement to the compute enclave. The compute enclave checks whether all task agreements are consistent. If they are consistent, each storage enclave sends the dataset of the corresponding client node to the compute enclave. The compute enclave receives the datasets sent by all storage enclaves and confirms whether the client node's identity matches the task agreement. If they match, it starts the calculation according to the calculation script in the task agreement. After the calculation is completed, it sends the calculation result to the corresponding storage enclave in the task agreement. The storage enclave archives or forwards the result to the corresponding client node.
[0075] In this step, each storage enclave and its corresponding client node remotely verify each other. After successful verification, each participating client node resends the task consent form to its corresponding storage enclave, indicating that the client node authorizes the dataset used by the computing task. The reason for resending the task consent form in this step is that the signature held by the management service node cannot be reused, as the management service node is untrusted, its freshness cannot be guaranteed, and it may be vulnerable to replay attacks.
[0076] In this step, when the storage enclave extracts data according to the data requirements of the task agreement and the authorization policy in the managed statement, it directly extracts datasets without an authorization policy; for datasets authorized for specific applications, it checks whether the calculation script in the task agreement is in the list of agreed applications; for datasets that require authorization, it verifies whether the task agreement sent by the client node is consistent with the task agreement sent by the management node, and if they are consistent, it extracts the corresponding dataset.
[0077] For security reasons, the TEE privacy computing enclave avoids sending intermediate results to external parties during the entire implementation process. Therefore, the task script can define the task's execution result but cannot send the result externally. Feedback on the task result can only be sent by the TEE privacy computing enclave after confirmation by each participating client node.
[0078] In this embodiment, for services that require a large amount of computing power or fast real-time response, such as inference services for large models, computing enclaves can be clustered to enhance computing power.
[0079] The main difference between the enclave process in a clustered computing environment and the process software in a regular cluster lies in the fact that each computing enclave needs to be verified to assure the verifier of the identity of the software running within it. There are two methods for verifying each computing enclave in the cluster: Method 1, the verifier verifies each computing enclave in the cluster one by one; Method 2, the verifier remotely verifies the computing enclave on the master node in the cluster, and the master node computing enclave then verifies each computing enclave on the slave nodes one by one. However, both of these methods are extremely inefficient for verifying clustered computing enclaves, severely impacting real-time response. Furthermore, if the computing enclave nodes in the cluster perform mutual verification, the number of verifications per node can reach the number of nodes in the cluster.
[0080] Therefore, this embodiment provides a fast verification mode for cluster TEE:
[0081] Assuming there are n computational enclave nodes in the cluster, the verification process involves forming a tree structure with all cluster computational enclaves. The verifier first verifies the root computational enclave node. Starting from the root node, each upper-level node in the tree structure performs remote verification of its lower-level TEE nodes. The verification between computational enclave nodes is bidirectional, so the verification time from the root node to the leaf node is only log n.
[0082] Because the verification between computing enclave nodes is bidirectional, a secure channel can be established between the upper-layer node computing enclave and the child node computing enclave, ensuring the trustworthiness of the software running within them.
[0083] Trust Transmission: After mutual verification between computation enclave nodes in the tree structure, the upper-level computation enclave node securely sends the key to the child computation enclave node. This secure key is passed from the root computation enclave node all the way down to the bottom-level leaf computation enclave node, so that all TEE nodes can use the same global communication and verification key.
[0084] During the computation process, any two computation enclave nodes in the cluster may interact. However, in this mode, subsequent computation enclave nodes no longer verify each other. Therefore, a global key is used as a root of trust for mutual communication and authentication during subsequent interactions.
[0085] After the global key is transferred, normal business interactions between all nodes no longer require remote authentication between any two nodes. Instead, the global key is used directly for encryption and identity verification during business communication.
[0086] To prevent external tampering or replay attacks (attacks that disrupt availability or cause packet loss are beyond our defenses), communication between every two compute enclave nodes requires an appended counter value for synchronization. Each compute enclave node maintains two counter structures: a send counter and a receive counter. The send counter is randomly initialized locally and increments by 1 after each message is sent. The receive counter is initialized from the count value of the first received message and increments by 1 after each received message.
[0087] The plaintext structure of the sent message is as follows:
[0088] Source address || Destination address || Send count || Service information
[0089] The message is encrypted and verified using a global key.
[0090] Upon receiving the message, the receiver uses the global key for verification and decryption. If this is the first communication, the receiver counter value is initialized using the send counter from the plaintext message; otherwise, the send counter value is compared with the receiver counter value. If they are equal, the message is accepted; otherwise, an error warning is issued.
[0091] In this embodiment, when a dispute arises, all parties need to intervene and historical data needs to be retrieved. This process must adhere to the principle of mutual agreement, therefore, logs need to be generated and saved.
[0092] The compute enclave can perform any business computation, while the storage enclave is responsible for data management and proxying for client nodes. Since the compute enclave can perform any business computation, various business functions have access to the data encapsulated in the compute enclave. Therefore, log generation can be handled by the compute enclave, while saving and retrieving logs is more appropriately handled by the storage enclave.
[0093] The computation enclave uses the log generation algorithm in the execution script to generate log text from the task agreement, dataset, and calculation results of all parties as log materials. After generating a random key, it encrypts the log text to obtain ciphertext. The computation enclave then stores the ciphertext and the corresponding task agreement locally.
[0094] The computation enclave splits the random key using the mn secret sharing method and sends it to each of the relevant storage enclaves. Each relevant storage enclave receives a portion of the random key and stores it locally along with the corresponding task agreement.
[0095] Security Analysis: The log information is encrypted and sealed by the computation enclave, and the encryption key is ultimately kept by the storage enclave. Therefore, the ownership and desealing of the logs are still controlled by the client nodes and the trusted storage enclave.
[0096] In this embodiment, after a dispute arises, a certain number of participants can initiate an audit with the management service node. The audit process is the same as the computational process. Specifically:
[0097] 601: Receive audit service request and task agreement initiated by the client node of the initiating party;
[0098] 602: Initiate an audit invitation for customer nodes that require authorization as specified in the task agreement and send the task agreement.
[0099] 603: Receives a task consent form signed by an authorized client node using its private key, and starts the storage enclave corresponding to each client node; the storage enclave pre-stores the hosting declaration and dataset of the corresponding client node;
[0100] Specifically, each authorized client node receives a task consent form issued by the management service node, reviews the consent form locally, checks its security, and simulates the execution of the task script. If an authorized client node needs to participate in the computation task, it signs the consent form using its private key and sends it to the management service node. The management service node then starts the enclave storing the historical tasks and corresponding logs for each participating client node.
[0101] 604: Start calculation enclave;
[0102] 605: Send the task agreement and computation enclave information to all storage enclaves;
[0103] Each relevant client node remotely verifies the storage enclave. Upon successful verification, the storage enclave authenticates the client node and receives a task consent form from the client node, indicating authorization for the dataset used by the computation task. (The signature held by the management node cannot be reused because the management node is untrusted, its freshness cannot be guaranteed, and it may be vulnerable to replay attacks.)
[0104] The storage enclave extracts data according to the data requirements of the task agreement;
[0105] The storage enclave accesses the compute enclave. The storage enclave performs remote (or local) authentication on the compute enclave, and the compute enclave performs remote authentication on the storage enclave. After successful mutual authentication, the storage enclave sends a task agreement to the compute enclave. The compute enclave verifies the consistency of all task agreements. Once consistency is achieved, each storage enclave sends the corresponding client node's dataset to the compute enclave. The compute enclave receives the datasets sent by all storage enclaves and confirms that the client node's identity matches the task agreement.
[0106] The computation enclave receives partial keys sent by all participating storage enclaves. When the number of participants exceeds a predetermined threshold, the computation enclave recovers the key to decrypt the logs and decrypts the locally sealed ciphertext logs. The computation enclave then uses the key to decrypt the corresponding encrypted logs and begins running the computation script according to the audit task agreement.
[0107] After the calculation is completed, the calculation enclave sends the calculation result to the corresponding storage enclave in the task agreement. The storage enclave either archives the result or forwards it to the client node.
[0108] In this embodiment, the service node will periodically destroy the sealed logs according to the policy.
[0109] In this embodiment, the privacy data related to the logs is encrypted by the TEE and sealed locally. Unless all participating parties and the corresponding TEE participate in unison, the privacy data cannot be recovered.
[0110] It should be noted that in this embodiment, "computation enclave" and "storage enclave" both refer to application software running in the TEE, equivalent to the enclave in Intel SGX technology. However, the terms "computation enclave" and "storage enclave" are used in this embodiment to be independent of specific hardware platforms. In the specific implementation, the "computation enclave" is a trusted application running in the TEE that processes data from multiple parties according to the needs of client nodes, and the "storage enclave" is a trusted application running in the TEE that authenticates each client node and securely encapsulates the data of that node.
[0111] The privacy-preserving computation method based on TEE provided in this embodiment simplifies the burden and interaction volume of client nodes by storing data before computation, with the client node verifying the storage enclave and the storage enclave proxy verifying the computation enclave. This reduces the requirements for client node synchronization and simultaneous online operation. Since client node data may participate in different computation tasks multiple times over a long period, separating storage and computation can ensure the availability and efficiency of the service.
[0112] Example 2
[0113] Please see Figure 3 This embodiment provides a TEE-based privacy computing system, which is used to implement the TEE-based privacy computing method of Embodiment 1, including:
[0114] Client nodes are used to initiate business requests to management service nodes;
[0115] Specifically, client nodes can submit dataset samples and basic descriptions to the management service node to display the dataset (such as data samples, formats, or virtual data); client nodes can also edit and debug business scripts for datasets from other client nodes.
[0116] The management service node is used to respond to service requests from client nodes and manage tasks such as the allocation, startup, and shutdown of compute enclave nodes and storage enclave nodes. It is also responsible for issuing announcements and other coordination work.
[0117] CA service nodes (remote authentication service nodes) are used for client node authentication and for client nodes to verify the software running in compute enclave nodes and storage enclave nodes.
[0118] Specifically, in this embodiment, each client node registers and uploads its public key to the management service node, and the CA service node issues a certificate for subsequent authentication. The username and password authentication method is suitable for centralized, trusted management scenarios outside the TEE, but not for authentication within the TEE. Since it is assumed that each client node trusts the software within the TEE and not centralized external information, usernames and passwords need to be registered with each TEE node. Therefore, using a CA system is more appropriate in this embodiment.
[0119] Multiple storage enclave nodes are used for secure storage of client node data;
[0120] Multiple compute enclave nodes are used for secure computation on client nodes.
[0121] Specifically, the compute enclave nodes and storage enclave nodes are responsible for the secure storage and secure computation of client node data, and complete privacy-preserving computation tasks through multi-party collaboration.
[0122] This embodiment provides a privacy computing platform based on TEE that can be used in data exchanges, as well as by large data owners and big data service providers. It is easy to implement privacy computing and easy to expand performance and scale.
[0123] For specific limitations on TEE-based privacy computing platforms, please refer to the limitations on TEE-based privacy computing methods mentioned above, which will not be repeated here.
[0124] The technical features of the above embodiments can be combined in any way (as long as there is no contradiction in the combination of these technical features). For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described; these embodiments not explicitly written should also be considered to be within the scope of this specification.
[0125] The present application has been described in a relatively specific and detailed manner above through general descriptions and specific embodiments. It should be understood that, based on the technical concept of the present application, several conventional adjustments or further innovations can be made to these specific embodiments; however, as long as they do not depart from the technical concept of the present application, the technical solutions obtained by these conventional adjustments or further innovations also fall within the protection scope of the claims of the present application.
Claims
1. A privacy-preserving computation method based on TEE, characterized in that, include: Step 1: Receive the computing service request and task agreement initiated by the client node of the initiating party; Step 2: Invite client nodes that require authorization as specified in the task agreement and send the task agreement. Step 3: Receive the task consent form signed by the authorized client node using its private key, and start the storage enclave corresponding to each client node; the storage enclave pre-stores the hosting declaration and dataset of the corresponding client node; Step 4: Start the enclave calculation; Step 5: Send the task agreement and computation enclave information to all relevant storage enclaves; each storage enclave and its corresponding client node remotely verify each other. After successful verification, each participating client node sends the task agreement to its corresponding storage enclave again; the storage enclave extracts data according to the data requirements in the task agreement and the authorization policy in the hosting statement, and verifies with the computation enclave. After successful verification, the storage enclave sends the task agreement to the computation enclave; the computation enclave checks whether all task agreements are consistent. If they are consistent, each storage enclave sends the dataset of the corresponding client node to the computation enclave; the computation enclave receives the datasets sent by all storage enclaves and confirms whether the client node identity is consistent with the task agreement. If they are consistent, it starts the computation according to the computation script in the task agreement. After the computation is completed, it sends the computation result to the corresponding storage enclave in the task agreement; the storage enclave archives the result or forwards it to the corresponding client node.
2. The privacy-preserving computation method based on TEE according to claim 1, characterized in that, In step 3, the specific process of pre-storing the hosting declaration and dataset of the corresponding client node in the storage enclave includes: The system receives a secure storage request from a client node and starts a storage enclave based on the request. The client node remotely verifies the storage enclave. After successful verification, the client node sends a hosting declaration to the storage enclave and digitally signs the hash value of the hosting declaration and the dataset. The storage enclave contacts the CA service node to verify the hosting declaration. After successful verification, the storage enclave seals the client node's hosting declaration and the corresponding dataset. Receive the managed declaration sent by the storage enclave and record the correspondence between the data storage of the client nodes and the storage enclave.
3. The privacy-preserving computation method based on TEE according to claim 1, characterized in that, In step 5, when the storage enclave extracts data according to the data requirements of the task agreement and the authorization policy in the hosting statement, it directly extracts datasets without an authorization policy; for datasets authorized by specific applications, it checks whether the calculation script in the task agreement is in the list of agreed applications. For datasets that require authorization, the system verifies whether the task agreement sent by the client node is consistent with the task agreement sent by the management node. If they are consistent, the corresponding dataset is extracted.
4. The privacy-preserving computation method based on TEE according to claim 1, characterized in that, When the computation enclave is in cluster mode, all computation enclaves form a tree structure. The storage enclave starts from the root node of the tree structure and performs remote verification of the computation enclaves of its upper-level nodes in turn.
5. The privacy-preserving computation method based on TEE according to claim 4, characterized in that, After mutual verification between computational enclaves in the tree structure, the upper-level computational enclave securely sends the key to the child computational enclave.
6. The privacy-preserving computation method based on TEE according to claim 4, characterized in that, In a tree structure, each communication between two computed enclaves requires an appended counter value for synchronization.
7. The privacy-preserving computation method based on TEE according to claim 1, characterized in that, After the enclave calculation is completed, log text and a random key are generated. The log text is then encrypted using the random key to obtain ciphertext. The random key is then split and sent to each storage enclave.
8. The privacy-preserving computation method based on TEE according to claim 7, characterized in that, The random key is split using mn secret sharing.
9. The privacy-preserving computation method based on TEE according to claim 7, characterized in that, When the number of participants exceeds a predetermined threshold, the enclave is calculated to recover the random key, and the locally sealed log ciphertext is desealed based on the random key.
10. A privacy-preserving computing system based on a TEE, characterized in that, The TEE-based privacy computing system is used to implement the TEE-based privacy computing method according to any one of claims 1-9, comprising: Client nodes are used to initiate business requests to management service nodes; The management service node is used to respond to service requests from client nodes, manage compute enclave nodes and storage enclave nodes, and is also responsible for issuing announcements and other coordination tasks. CA service nodes are used for authentication of client nodes. And for client nodes to verify the software running in compute enclave nodes and storage enclave nodes; Multiple storage enclave nodes are used for secure storage of client node data; Multiple compute enclave nodes are used for secure computation on client nodes.
Citation Information
Patent Citations
Credible data transmission method
CN109361668A
Indirection directories for cryptographic memory protection
CN110022199A