Network communication method, system, terminal and storage medium for a trusted device

By configuring different physical network cards for multiple SPUs sharing the same port and using load balancing, the method addresses port conflicts, improving system stability and security in SPU communication.

CN118842629BActive Publication Date: 2025-07-15SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410959951.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-17
Publication Date
2025-07-15
Estimated Expiration
2044-07-17

AI Technical Summary

Technical Problem

When multiple SPU applications bind the same port to communicate with external communication on a host, port conflicts are prone to occur.

Method used

By configuring the ports in a network card, multiple privacy computing units corresponding to the same port are bound to different physical network cards, and the request information is processed separately by physical and virtual network cards to determine the target privacy computing unit, and network traffic is optimized through load balancing and failover mechanisms.

Benefits of technology

It effectively resolves the problem of port conflict, realizes refined management of application networks, and enhances the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842629B_ABST
    Figure CN118842629B_ABST
Patent Text Reader

Abstract

The present invention discloses a network communication method, system, terminal and storage medium for a trusted device. When a request message sent by a client is received through a physical network card, a target privacy computing unit in the local machine is determined according to the physical network card address and port for receiving the request message. The local machine includes several privacy computing units. When the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses. When a request message sent by a client is received through a virtual network card, a target privacy computing unit in the local machine is determined according to the destination of the request message. The request message is sent to the target privacy computing unit. By configuring the network card for the port, the present invention binds multiple privacy computing applications corresponding to the same port to different physical network cards respectively, so as to perform refined management on the application network and solve the port conflict problem caused by binding different privacy computing applications to the same port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of trusted computing, and particularly relates to a network communication method, system, terminal and storage medium for trusted devices. Background Art

[0002] With the development of cloud computing and big data technologies, data security and privacy protection are particularly important, especially during data transmission and storage. The Secure Process Unit (SPU) is a physically isolated environment with its own operating system, memory, and CPU computing resources inside, but no physical network card, so data cannot flow out from the SPU side. In order to enable services inside the SPU to communicate with remote services, a gateway service is needed to forward network traffic.

[0003] Currently, multiple SPU applications on a single host may need to be mapped to the same port on the host. For example, when deploying a docker swarm cluster inside the SPU, nodes in the cluster communicate through fixed ports. However, when multiple SPUs use the same port on the host and each port is bound to only one network card, port conflicts are likely to occur.

[0004] Therefore, the prior art still needs to be improved and developed. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a network communication method, system, terminal and storage medium for trusted devices aiming at the above-mentioned defects of the prior art, aiming to solve the problem that multiple SPU applications on a single host bind to the same port on the host side to communicate with the outside, and each port is bound to only one network card, which is prone to port conflicts.

[0006] The technical solution adopted by the present invention to solve the problem is as follows:

[0007] In a first aspect, an embodiment of the present invention provides a network communication method for a trusted device, the method comprising:

[0008] When a request message sent by a client is received through a physical network card, determine a corresponding target privacy computing unit inside the local machine according to the physical network card address and port for receiving the request message, where the local machine includes several privacy computing units, and when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses;

[0009] When a request message sent by a client is received through a virtual network card, determine a corresponding target privacy computing unit inside the local machine according to the destination end corresponding to the request message;

[0010] Send the request information to the target privacy computing unit.

[0011] In one implementation, the determining the corresponding target privacy computing unit in the local machine according to the physical network card address and port for receiving the request information includes:

[0012] Determine the target privacy computing unit according to the physical network card address and port for receiving the request information and the pre-stored first binding information, where the first binding information is used to reflect the physical network card addresses and ports respectively corresponding to different privacy computing units in the local machine.

[0013] In one implementation, the virtual network card is used to implement communication between privacy computing units.

[0014] In one implementation, the sending the request information to the target privacy computing unit includes:

[0015] Send the request information to the network service of the target privacy computing unit through a pcie message, and the network service forwards the request information to the corresponding application through a tcp message.

[0016] In one implementation, the method further includes:

[0017] Obtain the real-time load status information respectively corresponding to each privacy computing unit in the local machine;

[0018] Allocate the currently received request information through a preset load balancer according to the real-time load status information of each privacy computing unit.

[0019] In one implementation, the method further includes:

[0020] For a faulty physical network card or virtual network card, switch the traffic to a preset backup network card.

[0021] In a second aspect, an embodiment of the present invention further provides a network communication system for a trusted device, and the system includes:

[0022] A client, where the client is a cross-host application program for sending request information or an application program corresponding to a privacy computing unit in the local machine;

[0023] The present device includes: several privacy computing units, wherein when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; and is used for: when receiving request information through a physical network card, determining the corresponding target privacy computing unit in the present device according to the physical network card address and port for receiving the request information; when receiving request information through a virtual network card, determining the corresponding target privacy computing unit in the present device according to the destination end corresponding to the request information; and sending the request information to the target privacy computing unit.

[0024] In one implementation, when the client is a cross-host application program and the request information is sent to the virtual network card of the present device, the request fails to be responded to.

[0025] In a third aspect, an embodiment of the present invention further provides a terminal, which includes a memory and more than one processor; the memory stores more than one program; the program includes instructions for executing the network communication method of the trusted device as described in any one of the above; and the processor is used for executing the program.

[0026] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which multiple instructions are stored, and the instructions are suitable for being loaded and executed by a processor to implement the steps of the network communication method of the trusted device as described in any one of the above.

[0027] The beneficial effects of the present invention: In the embodiments of the present invention, when receiving request information sent by a client through a physical network card, the corresponding target privacy computing unit in the present device is determined according to the physical network card address and port for receiving the request information, wherein the present device includes several privacy computing units, and when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; when receiving request information sent by a client through a virtual network card, the corresponding target privacy computing unit in the present device is determined according to the destination end corresponding to the request information; and the request information is sent to the target privacy computing unit. By configuring the network card for the ports, the present invention binds multiple privacy computing applications corresponding to the same port to different physical network cards respectively, effectively solving the port conflict problem caused by different privacy computing applications binding to the same port at the host end while realizing refined management of the application network. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for describing the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0029] Figure 1 It is a schematic flowchart of the network communication method of the trusted device provided by an embodiment of the present invention.

[0030] Figure 2 It is a schematic diagram of the interaction among an application, an SPU network service, a host network service, and a network card provided by an embodiment of the present invention.

[0031] Figure 3 It is a schematic flowchart of the cross-machine communication access process provided by an embodiment of the present invention.

[0032] Figure 4 It is a schematic diagram of the composition of the network communication system of the trusted device provided by an embodiment of the present invention.

[0033] Figure 5 It is a schematic block diagram of the terminal provided by an embodiment of the present invention. Detailed implementation manners

[0034] The present invention discloses a network communication method, system, terminal, and storage medium for a trusted device. To make the objectives, technical solutions, and effects of the present invention clearer and more definite, the following further describes the present invention in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention.

[0035] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "including" used in the specification of the present invention means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.

[0036] Those skilled in the art of the present technology can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.

[0037] With the development of cloud computing and big data technologies, data security and privacy protection are particularly important, especially during data transmission and storage. The Secure Process Unit (SPU) is a physically isolated environment with its own operating system, memory, and CPU computing resources inside, but without a physical network card, so data cannot flow out from the SPU side. To enable services inside the SPU to communicate with remote services, a gateway service is needed to forward network traffic.

[0038] Currently, multiple SPU applications on a single host may need to be mapped to the same port on the host. For example, when deploying a docker swarm cluster inside the SPU, the nodes in the cluster communicate through fixed ports. However, when multiple SPUs use the same port on the host and each port is bound to only one network card, port conflicts are likely to occur.

[0039] Aiming at the above-mentioned defects of the prior art, the present invention provides a network communication method for trusted devices. The method includes: when receiving request information sent by a client through a physical network card, determining a corresponding target privacy computing unit in the local machine according to the physical network card address and port for receiving the request information, where the local machine includes several privacy computing units, and when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; when receiving request information sent by a client through a virtual network card, determining a corresponding target privacy computing unit in the local machine according to the destination end corresponding to the request information; and sending the request information to the target privacy computing unit. By configuring the network card for the port, the present invention binds multiple privacy computing applications corresponding to the same port to different physical network cards respectively, effectively solving the port conflict problem caused by different privacy computing applications binding to the same port on the host side while realizing refined management of the application network.

[0040] As Figure 1 shown, the method includes:

[0041] Step S100, when receiving request information sent by a client through a physical network card, determining a corresponding target privacy computing unit in the local machine according to the physical network card address and port for receiving the request information, where the local machine includes several privacy computing units, and when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses.

[0042] Specifically, the application scenario of this embodiment is a scenario of one host with multiple SPU, that is, a host contains multiple SPU, and each SPU can be an application / server side, that is, SPU application / SPU server side. The SPU application cannot directly communicate with applications of other hosts. If the SPU application accesses externally, it needs to send data to the host side via the corresponding SPU network service, and the host side will send the data externally to the applications of other hosts. Similarly, if an application of another host accesses the SPU application of this machine, it first receives the access request sent by the application of another host through the host side, and then the host side confirms the target privacy unit corresponding to the access request, sends the access request to the corresponding SPU network service, and then the SPU network service forwards it to the corresponding SPU application. To solve the problem of port conflicts, this embodiment has made additional configurations for the host network service in advance. Through the multi-network card configuration of the host side, different applications are bound to different physical network cards. In particular, the corresponding relationships between ports and different physical network cards are set for multiple SPU corresponding to the same port, realizing isolation at the network level, ensuring that applications do not interfere with each other, enhancing the stability and security of the system, and solving the problem of port conflicts.

[0043] For example, as Figure 2 shown, the host service supports multiple applications listening on the same port at the host side by configuring different network cards. If the client requests the physical network card ip and port, the request will reach the host side, redirect the network packet, and then forward it to the corresponding SPU, achieving the purpose of cross-machine communication using the network of the host machine. In the scenario of cross-host communication, this embodiment allows multiple SPU applications to use the same port on the same host and distinguish traffic by binding to different physical network cards, effectively solving the problem of port conflicts.

[0044] In one implementation manner, the determining the corresponding target privacy computing unit in the machine according to the physical network card address and port of the received request information includes:

[0045] Determining the target privacy computing unit according to the physical network card address and port of the received request information and the pre-stored first binding information, where the first binding information is used to reflect the physical network card addresses and ports respectively corresponding to different privacy computing units in the machine.

[0046] Such as Figure 3As shown, the first binding information pre-stored in the host can be generated by the configuration information respectively pushed by each SPU network service. Specifically, each SPU network service reports its own configuration information, and the configuration information can reflect the port corresponding to the SPU network service and the physical network card bound to the port. The host network service receives the configuration information pushed by each SPU network service. For each SPU network service, according to the configuration information pushed by the SPU network service, the network card information is configured on the host side, including the physical network card IP address, so as to bind the port to the specified physical network card.

[0047] In one implementation, the method further includes:

[0048] For each privacy computing unit, according to the configuration information of the privacy computing unit, determine the requirements and priorities of the privacy computing unit;

[0049] According to the requirements and priorities of the privacy computing unit, determine the physical network card address bound to the port corresponding to the privacy computing unit.

[0050] Specifically, the method of performing multi-network card configuration on each SPU application is helpful for fine-grained control of traffic. The host system can automatically and reasonably allocate network resources, that is, physical network card addresses, according to the requirements and priorities of the SPU application, so as to better optimize network performance.

[0051] Step S200, when the request information sent by the client is received through the virtual network card, determine the corresponding target privacy computing unit in the host according to the destination end corresponding to the request information.

[0052] Specifically, in this embodiment, the communication between SPUs is implemented through the virtual network card. In other words, the user can limit the access range of the application according to the needs: if the physical network card is selected, cross-machine communication access is allowed; if the virtual network card is selected, only the communication between the SPUs on the same machine is allowed, so as to realize the fine-grained control of the application network traffic. In the scenario of communication between SPUs, when the SPU client requests the SPU server on the same host, the data reaches the host network service through the virtual network card on the host side and then is sent to the destination SPU.

[0053] In one implementation, the virtual network card is used to implement the communication between privacy computing units.

[0054] Specifically, the virtual network card in this embodiment is only used for communication between SPUs. If a cross-host client requests the virtual network card IP and port, the request will fail.

[0055] In one implementation, the communication between each privacy computing unit is implemented through one virtual network card.

[0056] In another implementation, communication between each privacy computing unit is achieved through more than one virtual network card.

[0057] Specifically, one or more of the requirements, functions, and communication frequencies of each SPU can be used to determine whether to use one or more virtual network cards to achieve communication between SPUs.

[0058] Step S300: Send the request information to the target privacy computing unit.

[0059] Specifically, each privacy computing unit on the local machine cannot directly communicate with an external client. Therefore, the request information sent by the external client needs to go through the host network service first. The host network service performs traffic redirection to determine the correct privacy computing unit corresponding to the request information, that is, the target privacy computing unit, and then forwards the request information to the target privacy computing unit to implement the access process of the external client to the privacy computing unit on the local machine.

[0060] For example, as Figure 2 shown, each application corresponds to a network driver, and the network driver corresponds to an SPU network service. An application can be an application program developed and run to complete certain specific tasks. In actual application, whether sending data out or receiving external data, the application needs to communicate with the host network service via the SPU network service and then communicate with the outside through the host network service.

[0061] In one implementation, the method further includes:

[0062] For each target physical network card, when inbound traffic is received, determine whether the access object corresponding to the inbound traffic has access permission;

[0063] If the access object does not have access permission, prohibit access

[0064] Specifically, in this embodiment, a physical network card with a security level higher than the level threshold can be used as a specific target physical network card, and the inbound and outbound traffic of the target physical network card is strictly monitored. In an actual communication scenario, strict security policies can be implemented for the traffic in and out of the target physical network card through network security group information and / or access control lists to prevent unauthorized access.

[0065] In one implementation, the sending the request information to the target privacy computing unit includes:

[0066] Send the request information to the network service of the target privacy computing unit through a pcie message, and the network service forwards the request information to the corresponding application through a tcp message.

[0067] Specifically, asFigure 2 As shown, each SPU application cannot directly communicate with the host network service and needs to forward data through the SPU network service. Each SPU network service communicates with the host network service through the PCIE channel. When the host network service needs to forward a request message, the request message is forwarded to the corresponding SPU network service through a pcie message as a carrier, and then the SPU network service forwards the request message to the corresponding SPU application through a tcp message as a carrier.

[0068] In one implementation, the method further includes:

[0069] Obtaining the real-time load status information corresponding to each privacy computing unit in the local machine;

[0070] According to the real-time load status information of each privacy computing unit, the currently received request message is allocated through a preset load balancer.

[0071] Specifically, in this embodiment, a load balancer can be deployed on the host side. By monitoring the real-time load status of each SPU, the currently received request message is intelligently allocated to a suitable SPU, so as to achieve load balancing among multiple SPUs and effectively improve the availability and response speed of the application.

[0072] In one implementation, the method further includes:

[0073] For a faulty physical network card or virtual network card, switch the traffic to a preset backup network card.

[0074] Specifically, in order to ensure the continuity and reliability of the service, a backup network card is preset in this embodiment. When a physical network card or virtual network card fails, the traffic can be quickly switched to the backup network card.

[0075] In one implementation, the method further includes:

[0076] For each privacy computing unit, when it is monitored that the privacy computing unit calls a connection function to initiate a connection to a remote service, hijack the input parameters of the connection function;

[0077] Modify the remote ip address in the input parameters to a preset ip address and modify the port in the input parameters to a local port;

[0078] Hijack the data packet sent by the privacy computing unit to the remote service through the modified connection function, encapsulate the data packet and send it to the PCIE channel, so that the host network sends the data packet to the remote service according to the corresponding pcie message.

[0079] This embodiment also provides a method for a privacy computing unit to access cross-machine applications. In order to make the applications in the SPU unaware of traffic forwarding, the destination address of the connection is redirected by hijacking system calls related to the network, thereby achieving traffic redirection. Specifically, the kprobe mechanism is used to hijack the input parameters of the connect system call in the kernel, and the target connection address is modified to a specified address, in cooperation with the network forwarding program to support accessing the external network in a network-free environment within the SPU. When an application needs to send data to a remote service, after the connect function is hijacked, the data packet will be sent to the port of the SPU network service. After the SPU network service receives the data packet, it encapsulates the data packet and sends it into the PCIe channel. The message in the PCIe channel will be received by the host network service. After the host network service unpacks the message, it establishes a connection with the remote service according to the remote IP address and port, and sends the data packet to the remote service, thus completing the data sending process.

[0080] For example, when an application calls the Connect system call to initiate a connection, the driver loaded in the SPU can hijack the input parameters of connect. The main function of the connect function is to initiate a connection request to the server, and the input parameters include the remote IP address and port of the connection. After the driver hijacks the input parameters, it modifies the IP address and port of the input parameters to the preset IP address (such as 127.0.0.1) and the local port. The user's application can establish a connection with the port of the SPU network service, but from the perspective of the application, it seems to establish a connection with the remote service.

[0081] In one implementation, before the privacy computing unit accesses the cross-machine application, it further includes:

[0082] Pre-add the access IP address and port of the privacy computing unit to the white list, and add a locally randomly listened port to the white list.

[0083] Specifically, before communication, the user adds the IP address and port that the application needs to access to the white list. At the same time, the SPU network service will listen on a random port locally and write this port into the white list. Strictly control the incoming and outgoing traffic through the white list.

[0084] Based on the above embodiment, the present invention also provides a network communication system for a trusted device, as Figure 4 shown, the system includes:

[0085] A client, which is a cross-host application program for sending request information or an application program corresponding to the privacy computing unit within the local machine;

[0086] The present device includes: a plurality of privacy computing units. When the ports corresponding to multiple privacy computing units are the same, the ports of the multiple privacy computing units respectively correspond to different physical network card addresses; and is used for: when receiving request information through a physical network card, determining a corresponding target privacy computing unit within the present device according to the physical network card address and port for receiving the request information; when receiving request information through a virtual network card, determining a corresponding target privacy computing unit within the present device according to the destination end corresponding to the request information; and sending the request information to the target privacy computing unit.

[0087] The foregoing explanation of the embodiments of the network communication method for a trusted device is also applicable to the network communication system of the trusted device in this embodiment, and will not be elaborated here.

[0088] In one implementation, when the client is a cross-host application program and the request information is sent to the virtual network card of the present device, the request fails to be responded to.

[0089] Specifically, the virtual network card in this embodiment is used to implement communication between SPU. Therefore, when a cross-host client requests the virtual network card IP and port, the request cannot be sent normally, and the client will be feedback that the request fails.

[0090] Based on the above embodiments, the present invention further provides a terminal, and its principle block diagram can be as Figure 5 shown. The terminal includes a processor, a memory, a network interface, and a display screen connected through a system bus. Among them, the processor of the terminal is used to provide computing and control capabilities. The memory of the terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the terminal is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it is used to implement the network communication method of a trusted device. The display screen of the terminal can be a liquid crystal display screen or an electronic ink display screen.

[0091] Those skilled in the art can understand that Figure 5 the principle block diagram shown in

[0092] is only a block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the terminal to which the solution of the present invention is applied. The specific terminal may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0093] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0094] In summary, the present invention discloses a network communication method, system, terminal, and storage medium for a trusted device. The method includes: when receiving a request message sent by a client through a physical network card, determining a corresponding target privacy computing unit in the local machine according to the physical network card address and port for receiving the request message, where the local machine includes several privacy computing units, and when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; when receiving a request message sent by a client through a virtual network card, determining a corresponding target privacy computing unit in the local machine according to the destination end corresponding to the request message; and sending the request message to the target privacy computing unit. By configuring the network card for the port, the present invention binds multiple privacy computing applications corresponding to the same port to different physical network cards respectively, effectively solving the port conflict problem caused by different privacy computing applications binding to the same port at the host end while realizing fine-grained management of the application network.

[0095] It should be understood that the application of the present invention is not limited to the above examples. For those of ordinary skill in the art, improvements or transformations can be made according to the above description, and all such improvements and transformations should fall within the protection scope of the appended claims of the present invention.

Claims

1. A network communication method for a trusted device, characterized in that, The method includes: When receiving request information sent by a client through a physical network card, determine a corresponding target privacy computing unit within the local machine according to the physical network card address and port for receiving the request information. Herein, the local machine includes several privacy computing units. When the ports of multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; When receiving request information sent by a client through a virtual network card, determine a corresponding target privacy computing unit within the local machine according to the destination of the request information; wherein, if a physical network card is selected, cross-machine communication access is allowed; if a virtual network card is selected, only communication between privacy computing units within the same machine is allowed; determine whether to use one or more virtual network cards to implement communication between privacy computing units through one or more of the requirements, functions, and communication frequencies of each privacy computing unit; Send the request information to the target privacy computing unit; The method further includes: Regard a physical network card with a security level higher than the level threshold as a specific target physical network card; For each target physical network card, when receiving inbound traffic, determine whether the access object corresponding to the inbound traffic has access permission; If the access object does not have access permission, prohibit access; The method further includes: For each privacy computing unit, when it is monitored that the privacy computing unit calls a connection function to initiate a connection to a remote service, use the kprobe mechanism to hijack the input parameters of the connect system call in the kernel; Modify the remote IP address in the input parameters to a preset IP address, and modify the port in the input parameters to a local port; Hijack the data packet sent by the privacy computing unit to the remote service through the modified connection function, encapsulate the data packet and send it to the pcie channel; the message of the pcie channel will be received by the host network service. After the host network service unpacks the message, establish a connection with the remote service according to the remote IP address and port, and send the data packet to the remote service.

2. The network communication method of the trusted device according to claim 1, characterized in that, The determining the corresponding target privacy computing unit within the local machine according to the physical network card address and port for receiving the request information includes: Determine the target privacy computing unit according to the physical network card address and port for receiving the request information and the pre-stored first binding information, wherein the first binding information is used to reflect the physical network card addresses and ports respectively corresponding to different privacy computing units within the local machine.

3. The network communication method of the trusted device according to claim 1, wherein The virtual network card is used to implement communication between privacy computing units.

4. The network communication method of the trusted device according to claim 1, characterized in that, The sending the request information to the target privacy computing unit includes: Send the request information to the network service of the target privacy computing unit through a pcie message, and the network service forwards the request information to the corresponding application through a tcp message.

5. The network communication method of a trusted device according to claim 1, characterized in that The method further includes: Obtain the real-time load status information respectively corresponding to each privacy computing unit within the local machine; Allocate the currently received request information through a preset load balancer according to the real-time load status information of each privacy computing unit.

6. The network communication method of a trusted device according to claim 1, wherein The method further includes: For a faulty physical network card or virtual network card, switch the traffic to a preset backup network card.

7. A network communication system for a trusted device, characterized in that, The system includes: A client, which is a cross-host application for sending request information or an application corresponding to a privacy computing unit within the local machine; The local machine, including: a plurality of privacy computing units. Wherein, when the ports corresponding to multiple privacy computing units are the same, the ports of these multiple privacy computing units respectively correspond to different physical network card addresses; and is used for: when receiving request information through a physical network card, determining the corresponding target privacy computing unit within the local machine according to the physical network card address and port for receiving the request information; when receiving request information through a virtual network card, determining the corresponding target privacy computing unit within the local machine according to the destination end corresponding to the request information; wherein, if a physical network card is selected, cross-machine communication access is allowed; if a virtual network card is selected, only communication between privacy computing units within the same machine is allowed; determining whether to use one or more virtual network cards to implement communication between privacy computing units according to one or more of the requirements, functions, and communication frequencies of each privacy computing unit; sending the request information to the target privacy computing unit; The system is further used for: Regarding a physical network card with a security level higher than the level threshold as a specific target physical network card; For each target physical network card, when receiving inbound traffic, determining whether the access object corresponding to the inbound traffic has access permission; If the access object does not have access permission, access is prohibited; The system is further used for: For each privacy computing unit, when it is monitored that the privacy computing unit calls a connection function to initiate a connection to a remote service, using the kprobe mechanism to hijack the input parameters of the connect system call in the kernel; Modifying the remote IP address in the input parameters to a preset IP address and modifying the port in the input parameters to a local port; Hijacking the data packet sent by the privacy computing unit to the remote service through the modified connection function, encapsulating the data packet and sending it to the PCIe channel; the message of the PCIe channel will be received by the host network service, and after the host network service unpacks the message, establishing a connection with the remote service according to the remote IP address and port, and sending the data packet to the remote service.

8. The network communication system of a trusted device according to claim 7, characterized in that, When the client is a cross-host application and sends the request information to the virtual network card of the local machine, the request fails to be responded to.

9. A terminal, characterized in that, The terminal includes a memory and more than one processor; the memory stores more than one program; the program includes instructions for executing the network communication method of the trusted device as described in any one of claims 1-6; the processor is used for executing the program.

10. A computer-readable storage medium having a plurality of instructions stored thereon, characterized in that, The instructions are suitable for being loaded and executed by the processor to implement the steps of the network communication method of the trusted device as described in any one of claims 1-6 above.