Application migration method, device, electronic device, storage medium and program product
By establishing a connection between a business blockchain network and an authoritative blockchain network in the blockchain network, using remote proof and smart contract mechanisms, negotiating the migration of keys and migrating the confidential computing environment, the problem of migration of confidential computing environments between blockchain nodes is solved, and efficient blockchain service performance and reliability are achieved.
Patent Information
- Application Number
- CN202411329393.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-09-24
AI Technical Summary
In a blockchain network, how to effectively migrate a confidential computing environment between various blockchain nodes, especially when there is a trusted execution environment based on confidential computing, migration becomes a difficult point.
By establishing a connection between the business blockchain network and the authoritative blockchain network, remote proof and smart contract mechanisms are used to achieve migration key negotiation and data migration between the source node and the target node. The specific steps include sending remote proof to an authoritative blockchain network for on-chain storage, verifying remote proof, negotiating the migration key, and using the migration key to migrate the confidential computing environment, etc.
It realizes the effective migration of confidential computing environments between various blockchain nodes in the blockchain network, solves the difficulties in the migration of confidential computing environments, and improves the performance and reliability of blockchain services.
Smart Images

Figure CN118869359B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular to an application migration method, and also to an application migration device, an electronic device, a computer-readable storage medium, and a computer program product. Background Art
[0002] Confidential computing is a computing model that uses firmware and software on trusted hardware to build an encrypted, isolated, and provable computing environment to ensure the confidentiality and integrity of data, code integrity, and confidentiality of the computing process. Confidential computing usually runs in a trusted execution environment, and a secure area is built in the central processing unit through software and hardware methods to ensure that the programs and data loaded inside are protected in terms of confidentiality and integrity.
[0003] In the field of blockchain, in order to achieve load balancing between blockchain nodes, improve resource utilization, increase fault tolerance, and provide network scalability, the support of blockchain node migration technology is needed. Therefore, studying blockchain node migration technology is of great significance for building high-performance blockchain services. However, when a trusted execution environment based on confidential computing exists in a blockchain node, the migration of confidential computing becomes a difficult point in blockchain node migration.
[0004] Therefore, how to achieve effective migration of confidential computing environments between various blockchain nodes within a blockchain network is an urgent problem to be solved by technicians in this field. Summary of the invention
[0005] An object of the present invention is to provide an application migration method, which can realize the effective migration of confidential computing environment between various blockchain nodes within a blockchain network; another object of the present invention is to provide an application migration device, an electronic device, a computer-readable storage medium and a computer program product, all of which have the above-mentioned beneficial effects.
[0006] In a first aspect, the present invention provides an application migration method, which is applied to a source node to which an application to be migrated belongs, wherein the source node and the target node are deployed in a business blockchain network, and the method comprises:
[0007] Sending the first remote proof to the authoritative blockchain network for on-chain storage, and controlling the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage;
[0008] Obtaining the second remote proof from the authoritative blockchain network for verification, obtaining a first verification result, and determining a second verification result of the target node for the first remote proof;
[0009] When both the first verification result and the second verification result are verified to be passed, negotiating with the target node to determine the migration key;
[0010] The migration key is used to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node.
[0011] The first remote proof is sent to the authoritative blockchain network for on-chain storage, including:
[0012] Using a source controller to collect the remote attestation of the source confidential computing environment and the remote attestation of the source controller, and generate the first remote attestation;
[0013] Sending the first remote proof to the authoritative blockchain network to verify the first remote proof using a first smart contract in the authoritative blockchain network;
[0014] When the verification is successful, the first remote proof and the verification result of the first remote proof are saved to the authoritative blockchain network to achieve on-chain storage.
[0015] Wherein, the first remote attestation includes an environment execution code reference value and a hardware signature;
[0016] Accordingly, sending the first remote proof to the authoritative blockchain network to verify the first remote proof using the first smart contract in the authoritative blockchain network includes:
[0017] The first remote attestation is sent to the authoritative blockchain network, so that the authoritative blockchain network verifies the environment execution code reference value using the pre-stored reference value in the first smart contract, and verifies the hardware signature using the remote attestation service in the first smart contract.
[0018] Among them, controlling the target node to send the second remote proof to the authoritative blockchain network for on-chain storage through the business blockchain network includes:
[0019] A first migration transaction is initiated to the business blockchain network using a source controller, so that the business blockchain network initiates a second migration transaction to the target node using a second smart contract, so that the target node can create a target controller, a target confidential computing environment, and a target non-confidential computing environment, and use the target controller to collect the second remote proof and send it to the authoritative blockchain network for on-chain storage.
[0020] The application migration method further includes:
[0021] The first migration transaction and the second migration transaction are stored on the chain by using a second smart contract in the business blockchain network through a preset consensus algorithm.
[0022] Wherein, using the migration key to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node includes:
[0023] Determine a confidential session key, a non-confidential session key, an encrypted session key, and a non-encrypted session key according to the migration key;
[0024] encrypting the source confidential computing environment using the confidential session key and then migrating it to the target node;
[0025] Encrypting the source non-confidential computing environment using the non-confidential session key and then migrating it to the target node;
[0026] Using the non-encrypted session key, the source static non-encrypted data and the source static encrypted data are encrypted and then migrated to the target node;
[0027] The encryption key of the source static encrypted data is encrypted using the encryption session key and then migrated to the target node.
[0028] The step of encrypting the source confidential computing environment by using the confidential session key and then migrating the encrypted environment to the target node includes:
[0029] Using a preset migration tool in the source controller to collect first process information and memory information of the application to be migrated in the source confidential computing environment;
[0030] Based on a preset migration library in the source non-confidential computing environment, the first process information and the memory information are encrypted using the confidential session key and then migrated to the target node.
[0031] Wherein, using a preset migration tool in the source controller to collect memory information of the application to be migrated in the source confidential computing environment includes:
[0032] Parsing a preset dynamic library corresponding to the source confidential computing environment to obtain storage information of each data segment in the trusted memory;
[0033] Obtaining virtual memory space layout information of the source confidential computing environment in a preset file corresponding to the source confidential computing environment;
[0034] The memory information is generated using the storage information of each of the data segments and the virtual memory space layout information.
[0035] Wherein, based on the preset migration library in the source non-confidential computing environment, encrypting the second process information and the memory information using the confidential session key and then migrating them to the target node includes:
[0036] Executing a target function based on a preset migration library in the source non-confidential computing environment to encrypt the second process information and the memory information using the confidential session key to obtain encrypted information;
[0037] The encrypted information is exported to the source non-confidential computing environment and migrated from the source non-confidential computing environment to the target node.
[0038] The step of encrypting the source non-confidential computing environment using the non-confidential session key and then migrating the environment to the target node includes:
[0039] Using a preset migration tool in the source controller to collect second process information of the application to be migrated in the source non-confidential computing environment;
[0040] The second process information is encrypted using the non-confidential session key and then migrated to the target node.
[0041] Wherein, using the migration key to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node also includes:
[0042] Using the source controller to establish a migration smart contract, and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction;
[0043] During the third migration transaction, the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node are migrated to the target node using the migration key.
[0044] The step of establishing a migration smart contract using the source controller and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network so that the target node responds to the third migration transaction includes:
[0045] Using the source controller to establish a first hash time lock, and establishing a migration smart contract based on the first hash time lock;
[0046] Initiate a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction and establishes a second hash time lock, so that the authoritative blockchain network verifies the application migration result according to the first hash time lock and the second hash time lock.
[0047] Among them, when the application migration result is that the application migration is successful, the source node is marked as an unavailable node by the authoritative blockchain network, and the target node is marked as an available node by the authoritative blockchain network.
[0048] Among them, when the authoritative blockchain network receives the hash information of the second hash time lock within a preset time, and the hash value of the hash information is consistent with the hash value of the second hash time lock, the application migration result is that the application migration is successful.
[0049] The first remote proof is sent to the authoritative blockchain network for on-chain storage, including:
[0050] When the local load reaches a preset load threshold, the first remote proof is sent to the authoritative blockchain network for on-chain storage.
[0051] The first remote proof is sent to the authoritative blockchain network for on-chain storage, including:
[0052] When a system upgrade instruction is received, the first remote proof is sent to the authoritative blockchain network for on-chain storage.
[0053] In a second aspect, the present invention further discloses an application migration device, which is applied to a source node to which an application to be migrated belongs, wherein the source node and the target node are deployed in a business blockchain network, and the device comprises:
[0054] A sending module, used to send the first remote proof to the authoritative blockchain network for on-chain storage, and control the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage;
[0055] A verification module, configured to obtain the second remote proof from the authoritative blockchain network for verification, obtain a first verification result, and determine a second verification result of the target node for the first remote proof;
[0056] A negotiation module, configured to negotiate with the target node to determine a migration key when both the first verification result and the second verification result are verified to be passed;
[0057] A migration module is used to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key.
[0058] In a third aspect, the present invention further discloses an electronic device, comprising:
[0059] Memory for storing computer programs;
[0060] A processor is used to implement the steps of any one of the application migration methods described above when executing the computer program.
[0061] In a fourth aspect, the present invention further discloses a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of any one of the application migration methods described above are implemented.
[0062] In a fifth aspect, the present invention further discloses a computer program product, including a computer program / instruction, which implements the steps of any one of the application migration methods described above when executed by a processor.
[0063] The present invention provides an application migration method, which is applied to a source node to which an application to be migrated belongs, and the source node and the target node are deployed in a business blockchain network. The method includes: sending a first remote certificate to an authoritative blockchain network for on-chain storage, and controlling the target node through the business blockchain network to send a second remote certificate to the authoritative blockchain network for on-chain storage; obtaining the second remote certificate from the authoritative blockchain network for verification, obtaining a first verification result, and determining the second verification result of the target node for the first remote certificate; when the first verification result and the second verification result are both verified to pass, negotiating with the target node to determine a migration key; and using the migration key to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node.
[0064] By applying the technical solution provided in the present invention, an authoritative blockchain network is created to connect with the business blockchain network, so as to help the business blockchain network realize application migration between internal blockchain nodes, thereby realizing effective migration of confidential computing environment between various blockchain nodes. For source nodes and target nodes in the business blockchain network that need to perform application migration, both can send their own remote certificates to the authoritative blockchain network for chain storage, and verify each other's remote certificates. After the verification of both parties is passed, the migration key negotiated between the two parties is used to migrate the relevant data information on the source node to the target node. In this process, effective migration of confidential computing environment between various blockchain nodes in the blockchain network is realized.
[0065] The application migration device, electronic device, computer-readable storage medium and computer program product provided by the present invention also have the above-mentioned technical effects, and the present invention will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the prior art and the embodiments of the present invention, the following briefly introduces the drawings required for describing the prior art and the embodiments of the present invention. Of course, the drawings related to the embodiments of the present invention described below are only part of the embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without creative work, and the obtained other drawings also belong to the protection scope of the present invention.
[0067] Figure 1 A schematic diagram of a flow chart of an application migration method provided by an embodiment of the present invention;
[0068] Figure 2 A schematic diagram of the structure of an application migration system provided by an embodiment of the present invention;
[0069] Figure 3 A timing diagram of an application migration method provided by an embodiment of the present invention;
[0070] Figure 4 A schematic diagram of the structure of an application migration device provided by an embodiment of the present invention;
[0071] Figure 5 The present invention is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0072] The core of the present invention is to provide an application migration method, which can realize the effective migration of confidential computing environment between various blockchain nodes within a blockchain network; another core of the present invention is to provide an application migration device, electronic device, computer-readable storage medium and computer program product, all of which have the above-mentioned beneficial effects.
[0073] In order to describe the technical solutions in the embodiments of the present invention more clearly and completely, the technical solutions in the embodiments of the present invention will be introduced below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0074] An embodiment of the present invention provides an application migration method.
[0075] It should be noted that the application migration method provided in the embodiment of the present invention can be applied to any blockchain node in the business blockchain network. When a blockchain node needs to perform application migration, the blockchain node is called the source node, and the blockchain node that receives the migration information on the source node is the target node. The target node can be any available blockchain node in the business blockchain network except the source node. In addition, the business blockchain network is connected to the authoritative blockchain network, which is used to assist any two blockchain nodes in the business blockchain network to complete the application migration operation.
[0076] On this basis, please refer to Figure 1 , Figure 1 A schematic flow chart of an application migration method provided in an embodiment of the present invention is provided. The application migration method is applied to the above-mentioned source node and may include the following S101 to S104.
[0077] S101: Send the first remote certificate to the authoritative blockchain network for on-chain storage, and control the target node through the business blockchain network to send the second remote certificate to the authoritative blockchain network for on-chain storage.
[0078] This step aims to achieve on-chain storage of remote proofs of the source node and the target node. The remote proofs of the source node and the target node are sent to the authoritative blockchain network for on-chain storage, so that the authoritative blockchain network can verify the two, and the two can also verify each other, thereby achieving application migration between the source node and the target node.
[0079] Among them, the first remote attestation is the remote attestation of the source node, and the second remote attestation is the remote attestation of the target node. The content mainly refers to the information used to prove the identity of the corresponding blockchain node. For example, it may include but is not limited to confidential computing environment attribute information, environment execution code reference value, hardware (hardware in various nodes) signature, etc.
[0080] In one embodiment of the present invention, sending the first remote proof to the authoritative blockchain network for on-chain storage may include:
[0081] Using the source controller to collect the remote attestation of the source confidential computing environment and the remote attestation of the source controller, and generate a first remote attestation;
[0082] Sending the first remote proof to the authoritative blockchain network to verify the first remote proof using a first smart contract in the authoritative blockchain network;
[0083] When the verification is successful, the first remote proof and the verification result of the first remote proof are saved to the authoritative blockchain network to achieve on-chain storage.
[0084] It is understandable that, in order to ensure information security, the authoritative blockchain network can first verify the legitimacy of the remote proof before storing it on the chain to ensure the security and legitimacy of the blockchain node corresponding to the remote proof. Taking the first remote proof of the source node as an example, after the authoritative blockchain network verifies the first remote proof, it can save the first remote proof and its verification result to the authoritative blockchain network to realize the on-chain storage of the remote proof of the source node; the verification process can be implemented using the smart contract in the authoritative blockchain network (i.e., the above-mentioned first smart contract). Among them, the first remote proof can include the remote proof of the confidential computing environment in the source node (i.e., the above-mentioned source confidential computing environment) and the remote proof of the source controller itself, which is used to prove that each confidential computing component in the source node (including the source controller) runs in a real confidential computing environment. The two types of remote certificates can be collected using the source controller deployed in the source node. Of course, the on-chain storage of the second remote proof of the target node can also be implemented based on this operation process, which will not be repeated here.
[0085] Among them, the first remote attestation includes an environment execution code reference value and a hardware signature; accordingly, sending the first remote attestation to the authoritative blockchain network to verify the first remote attestation using the first smart contract in the authoritative blockchain network can include: sending the first remote attestation to the authoritative blockchain network so that the authoritative blockchain network verifies the environment execution code reference value using the pre-stored reference value in the first smart contract, and verifies the hardware signature using the remote attestation service in the first smart contract.
[0086] As described above, the first remote attestation may include the environment execution code reference value and hardware signature of the source controller. In this way, the authoritative blockchain network can use the pre-stored reference value in the first smart contract to verify the environment execution code reference value, and use the remote attestation service (provided by the hardware manufacturer) in the first smart contract to verify the hardware signature. Obviously, when the pre-stored reference value is consistent with the environment execution code reference value and the hardware signature is legal, the first remote attestation verification can be considered to have passed.
[0087] In one embodiment of the present invention, controlling the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage may include:
[0088] A first migration transaction is initiated to the business blockchain network using the source controller, so that the business blockchain network initiates a second migration transaction to the target node using the second smart contract, so that the target node can create a target controller, a target confidential computing environment, and a target non-confidential computing environment, and use the target controller to collect the second remote proof and send it to the authoritative blockchain network for on-chain storage.
[0089] It is understandable that the target node, as a migration node of the source node, can store the second remote certificate on the chain in response to the first remote certificate on the chain of the source node. Specifically, in the process of sending the first remote certificate to the authoritative blockchain network for on-chain storage, the source node can use its own source controller to initiate a first migration transaction to the business blockchain network, so that it can initiate a second migration transaction to the target node through the business blockchain network. In this way, the target node can respond to the second migration transaction to start creating a target controller, a target confidential computing environment, a target non-confidential computing environment, etc., and use the target controller to collect the second remote certificate to send to the authoritative blockchain network for on-chain storage. Of course, the on-chain storage process of the second remote certificate can refer to the on-chain storage process of the first remote certificate mentioned above, and will not be repeated here.
[0090] Furthermore, the application migration method may also include: using the second smart contract in the business blockchain network to store the first migration transaction and the second migration transaction on the chain through a preset consensus algorithm. In this embodiment, in order to facilitate subsequent problem tracing, the second smart contract in the business blockchain network may also be called to store the first migration transaction and the second migration transaction on the chain. This process may be implemented based on a preset consensus algorithm, such as the Practical Byzantine Fault Tolerance (PBFT) algorithm.
[0091] In one embodiment of the present invention, sending the first remote proof to the authoritative blockchain network for on-chain storage may include: when the local load reaches a preset load threshold, sending the first remote proof to the authoritative blockchain network for on-chain storage.
[0092] In one embodiment of the present invention, sending the first remote proof to the authoritative blockchain network for on-chain storage may include: when a system upgrade instruction is received, sending the first remote proof to the authoritative blockchain network for on-chain storage.
[0093] The above two embodiments provide two different methods for triggering application migration. Specifically, when the load of a blockchain node is too high, or its own system needs to be upgraded and cannot continue to process business, it can be used as a source node to trigger the application migration process.
[0094] S102: Obtain a second remote certificate from the authoritative blockchain network for verification, obtain the first verification result, and determine the second verification result of the target node for the first remote certificate.
[0095] This step aims to verify the legitimacy of the remote proofs between the source node and the target node, so as to realize the application migration between the two nodes when both verifications are passed. In the implementation process, the source node can obtain the second remote proof of the target node from the authoritative blockchain network for verification, and the target node can obtain the first remote proof of the source node from the authoritative blockchain network for verification, and obtain the corresponding verification results, namely the first verification result and the second verification result mentioned above.
[0096] S103: When both the first verification result and the second verification result are verified to be passed, negotiate with the target node to determine the migration key.
[0097] This step aims to achieve mutual authentication between the source node and the target node through negotiation of migration keys, so as to realize application migration using the negotiated migration key. It is understood that the migration key is used to realize encryption processing of the migrated content during the migration process, so as to effectively ensure the security of the migration information. It is understood that the migration key can be one or more, and when the number is not unique, different migration keys can be used to encrypt different migration information.
[0098] S104: Use the migration key to migrate the source confidential computing environment, source non-confidential computing environment, source static encrypted data, and source static non-encrypted data in the source node to the target node.
[0099] This step aims to achieve application migration based on the migration key, that is, using the migration key to encrypt the source confidential computing environment, source non-confidential computing environment, source static encrypted data, and source static non-encrypted data in the source node, and then migrate them to the target node. At this point, the application migration between the source node and the target node is completed.
[0100] In one embodiment of the present invention, migrating a source confidential computing environment, a source non-confidential computing environment, a source static encrypted data, and a source static non-encrypted data in a source node to a target node using a migration key may include:
[0101] Determine a confidential session key, a non-confidential session key, an encrypted session key, and a non-encrypted session key according to the migration key;
[0102] The source confidential computing environment is encrypted using a confidential session key and then migrated to the target node;
[0103] Encrypting the source non-confidential computing environment using a non-confidential session key and then migrating it to the target node;
[0104] Using the non-encrypted session key, the source static non-encrypted data and the source static encrypted data are encrypted and then migrated to the target node;
[0105] The encryption key of the source static encrypted data is encrypted using the encryption session key and then migrated to the target node.
[0106] As mentioned above, the number of migration keys can be multiple, for example, it can include confidential session keys, non-confidential session keys, encrypted session keys, and non-encrypted session keys. Different session keys are used to encrypt different migration information, namely the above-mentioned source confidential computing environment, source non-confidential computing environment, source static encrypted data and its encryption key, source static non-encrypted data, etc.
[0107] In one embodiment of the present invention, encrypting the source confidential computing environment using the confidential session key and then migrating it to the target node may include:
[0108] Using a preset migration tool in the source controller to collect first process information and memory information of the application to be migrated in the source confidential computing environment;
[0109] Based on a preset migration library in a source non-confidential computing environment, the first process information and memory information are encrypted using a confidential session key and then migrated to a target node.
[0110] Specifically, the encrypted migration for the source confidential computing environment mainly includes the first process information and memory information in the source confidential computing environment. This process can be implemented based on the preset migration tool deployed in the source controller and the preset migration library deployed in the source non-confidential computing environment. In one possible implementation, the preset migration tool can be CRIU (Checkpoint / Restore In Userspace, a software tool running on the Linux operating system), which can be used to implement the checkpoint / restore function in the user space.
[0111] Among them, using the preset migration tool in the source controller to collect the memory information of the application to be migrated in the source confidential computing environment can include: parsing the preset dynamic library corresponding to the source confidential computing environment to obtain the storage information of each data segment in the trusted memory; obtaining the virtual memory space layout information of the source confidential computing environment in the preset file corresponding to the source confidential computing environment; using the storage information of each data segment and the virtual memory space layout information to generate memory information. In other words, the memory information of the application to be migrated in the source confidential computing environment mainly includes the storage information of each data segment in the trusted memory corresponding to the source confidential computing environment (including but not limited to the base address, size, offset information of each data segment, etc.) and the virtual memory space layout information of the source confidential computing environment, which can be obtained in the corresponding dynamic library and file library respectively. In a possible implementation method, the preset dynamic library can be specifically the userxxx.so dynamic library, and the preset file can be specifically the / proc / $(pid) / maps file.
[0112] Among them, based on the preset migration library in the source non-confidential computing environment, the second process information and memory information are encrypted using the confidential session key and then migrated to the target node, which may include: executing the target function based on the preset migration library in the source non-confidential computing environment to encrypt the second process information and memory information using the confidential session key to obtain encrypted information; exporting the encrypted information to the source non-confidential computing environment, and migrating from the source non-confidential computing environment to the target node. In other words, the migration of the source confidential computing environment is achieved through the source non-confidential computing environment. In one possible implementation, the target function may specifically be an ECALL function.
[0113] In one embodiment of the present invention, encrypting the source non-confidential computing environment using the non-confidential session key and then migrating it to the target node may include:
[0114] Using a preset migration tool in the source controller to collect second process information of the application to be migrated in the source non-confidential computing environment;
[0115] The second process information is encrypted using a non-confidential session key and then migrated to the target node.
[0116] Specifically, the encrypted migration for the source non-confidential computing environment mainly includes the second process information in the source non-confidential computing environment, and this process can be implemented based on the preset migration tool deployed in the source controller. In a possible implementation, the above two types of process information (first process information and second process information) may include but are not limited to process control blocks, processor contexts, process memory status information, open files and other resource information.
[0117] It can be seen that the application migration method provided in the embodiment of the present invention creates an authoritative blockchain network and connects it with the business blockchain network to help the business blockchain network realize application migration between internal blockchain nodes, thereby realizing effective migration of the confidential computing environment between various blockchain nodes. For the source nodes and target nodes in the business blockchain network that need to perform application migration, both can send their own remote certificates to the authoritative blockchain network for chain storage, and verify each other's remote certificates. After the verification of both parties is passed, the migration key negotiated between the two parties is used to migrate the relevant data information on the source node to the target node. In this process, the effective migration of the confidential computing environment between various blockchain nodes in the blockchain network is realized.
[0118] Based on the above embodiments:
[0119] In one embodiment of the present invention, migrating a source confidential computing environment, a source non-confidential computing environment, a source static encrypted data, and a source static non-encrypted data in a source node to a target node using a migration key may include:
[0120] Using the source controller to establish a migration smart contract, and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction;
[0121] During the third migration transaction, the source confidential computing environment, source non-confidential computing environment, source static encrypted data, and source static non-encrypted data in the source node are migrated to the target node using the migration key.
[0122] It is understandable that the migration process of various types of migration information in the source node responds to the initiation of the third migration transaction process. Specifically, the source node can use its own source controller to establish a migration smart contract and initiate the third migration transaction corresponding to the migration smart contract to the authoritative blockchain network. As a result, the target node can respond to the third migration transaction and enter the third migration transaction process, thereby completing the application migration in the third migration transaction process.
[0123] Among them, using the source controller to establish a migration smart contract, and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network so that the target node responds to the third migration transaction, can include: using the source controller to establish a first hash time lock, and establishing a migration smart contract based on the first hash time lock; initiating the third migration transaction corresponding to the migration smart contract to the authoritative blockchain network so that the target node responds to the third migration transaction and establishes a second hash time lock, so that the authoritative blockchain network verifies the application migration result according to the first hash time lock and the second hash time lock.
[0124] The embodiment of the present invention realizes the verification of the application migration result by creating a hash time lock, and can effectively prevent the fork attack and rollback attack in the blockchain node migration process. Specifically, during the third migration process, the source node and the target node can respectively establish a hash time lock (i.e., the first hash time lock and the second hash time lock mentioned above), so that the authoritative blockchain network can verify the application migration result according to the execution result of the hash time lock. Obviously, when the hash time lock is executed successfully, the application migration is successful; when the hash time lock fails to execute, the application migration fails.
[0125] Among them, hash time lock includes hash lock and time lock. Time lock means that the transaction parties agree that submission is valid only within a certain time, and the commitment scheme will be invalid if it exceeds the time limit; hash lock means that for a hash value H, if the original image R is provided so that Hash (R) = H, the commitment is valid, otherwise it will be invalid. Therefore, when the authoritative blockchain network can receive the hash information (i.e., the original image R) of the second hash time lock within the preset time (i.e., the agreed time), and the hash value of the hash information (Hash (R)) is consistent with the hash value (H) of the second hash time lock, it can be determined that the application migration result is successful.
[0126] Furthermore, when the application migration result is successful, the source node is marked as an unavailable node by the authoritative blockchain network, and the target node is marked as an available node by the authoritative blockchain network. In other words, after the application migration is successful, the authoritative blockchain network can control the source node to stop running and control the target node to start running, so as to effectively ensure the normal operation of the node business.
[0127] An embodiment of the present invention provides another application migration method.
[0128] In this embodiment, when the operating environment where the blockchain node is located is overloaded, the corresponding blockchain node needs to be migrated to an operating environment with a lower load; or when the environment where the blockchain node is located needs to perform system upgrades and other operations, the corresponding blockchain node needs to be migrated to other operating environments. Through blockchain node migration, the blockchain service level agreement can be effectively met, and the upgradeability, patching and other maintainability requirements of confidential components in the blockchain can be achieved.
[0129] Please refer to Figure 2 , Figure 2 A structural diagram of an application migration system provided in an embodiment of the present invention, wherein the application migration system mainly includes a business blockchain network and an authoritative blockchain network, wherein the business blockchain network includes a plurality of blockchain nodes, each of which can be used as a source blockchain node or a target blockchain node (source node and target node), and the source blockchain node can be migrated to the target blockchain node within the business blockchain network.
[0130] like Figure 2 As shown, the source blockchain node includes a source migration controller, multiple source migration non-confidential computing environments, multiple source migration confidential computing environments, static encrypted data and static non-encrypted data corresponding to the source blockchain node; wherein, the source migration controller includes the CRIU tool, and each source migration non-confidential computing environment includes a migration library that assists the source migration confidential computing environment in migration. It can be understood that each source blockchain node may contain multiple running components, and therefore includes multiple source migration non-confidential computing environments and multiple source migration confidential computing environments, and the number of each source migration non-confidential computing environment is the same as the number of source migration confidential computing environments, and each source migration non-confidential computing environment corresponds to a source migration confidential computing environment. During the migration process, the main implementation is to migrate the source migration non-confidential computing environment and the source migration confidential computing environment in the source blockchain node to the target blockchain node for operation, and stop the source blockchain node, and import the static encrypted data and static non-encrypted data owned by the source blockchain node into the target blockchain node.
[0131] In addition, the authoritative blockchain network is mainly responsible for uploading the remote proof information of the confidential computing environment (source migration controller, source migration confidential computing environment, target migration controller, target migration confidential computing environment) to the chain, and is responsible for providing remote proof information of any blockchain node to other blockchain nodes, as well as running the migration smart contract, establishing the migration hash time lock, etc.
[0132] Based on this, please refer to Figure 3 , Figure 3 A timing diagram of an application migration method provided by an embodiment of the present invention, the implementation process of which is as follows:
[0133] 1. The source blockchain node uses the source migration controller to collect all remote attestation information of the source migration confidential computing environment and the remote attestation information of the source migration controller, mainly including various environmental attribute information, reference values of the environment execution code, and hardware signatures, etc., and sends the remote attestation information to the authoritative blockchain network, calling the remote attestation smart contract in the authoritative blockchain network to initiate the first attestation transaction, proving that all confidential computing components in the source blockchain node are running in a real confidential computing environment, and storing the verification results on the chain.
[0134] The implementation process of remote attestation is as follows: the authoritative blockchain network initiates a remote attestation challenge to all confidential computing components in the source blockchain node through the first attestation transaction, and sends random numbers to all confidential computing components. All confidential computing components in the source blockchain node generate remote attestation information in the trusted execution environment and send the remote attestation information to the remote attestation smart contract. The remote attestation smart contract compares the environmental code reference values of all confidential computing components with the reference values pre-stored on the authoritative blockchain network, and verifies the hardware signature of the remote attestation information through the remote attestation service provided by the hardware manufacturer. If the reference values are equal and the signature is legal, it can be proved that all confidential computing components in the source blockchain node are running in a real confidential computing environment.
[0135] 2. The source blockchain node uses the source migration controller to initiate the first migration transaction on the business blockchain, calls the migration smart contract on the business blockchain, and at the same time, the first migration transaction of the source blockchain node is uploaded to the chain through a consensus algorithm (such as the PBFT algorithm) and recorded in the business blockchain.
[0136] 3. The migration smart contract initiates the second migration transaction based on the first migration transaction, creates a target migration controller on the target blockchain node, and simultaneously uploads the second migration transaction of the target blockchain node to the blockchain through the consensus algorithm and records it in the business blockchain. In addition, the target migration controller creates the same number of target migration non-confidential computing environments and target migration confidential computing environments.
[0137] 4. The target blockchain node uses the target migration controller to collect the remote attestation information of all target migration confidential computing environments and its own remote attestation information, and sends the remote attestation information to the authoritative blockchain network, calling the remote attestation smart contract in the authoritative blockchain network to initiate a second attestation transaction to prove that all confidential computing components in the target blockchain node are running in a real confidential computing environment, and the verification results are stored on the chain.
[0138] 5. The source migration controller obtains the remote attestation information of the target migration controller and the target migration confidential computing environment through the remote attestation smart contract of the authoritative blockchain network to verify that it is running in a real confidential computing environment.
[0139] 6. The target migration controller obtains the remote attestation information of the source migration controller and the source migration confidential computing environment through the remote attestation smart contract of the authoritative blockchain network to verify that it is running in a real confidential computing environment.
[0140] 7. The source migration controller and the target migration controller negotiate with each other to determine the migration policy evaluation, migration transport key and multiple migration confidential session keys, multiple migration non-confidential session keys, static data session key, and static encrypted data key session keys.
[0141] Among them, the migration transmission key is responsible for the secure communication between the source migration controller and the target migration controller. Multiple migration confidential session keys correspond to the number of migration confidential computing environments, and are responsible for establishing secure data transmission between the source migration confidential computing environment and the target migration confidential computing environment. Multiple migration non-confidential session keys correspond to the number of migration non-confidential computing environments, and are responsible for establishing secure data transmission between the source migration non-confidential computing environment and the target migration non-confidential computing environment. The static data session key is responsible for establishing the transmission of static encrypted data and static non-encrypted data between the source migration non-confidential computing environment and the target migration non-confidential computing environment. The session key of the static encrypted data key is responsible for encrypting and transmitting the static encrypted data key, and the process is: the static encrypted data key is decrypted by the hardware sealing key of the corresponding source migration confidential computing environment, and then encrypted and transmitted to the corresponding target migration confidential computing environment using the session key of the static encrypted data key; the target migration confidential computing environment decrypts to obtain the static encrypted data key, and the static encrypted data key is sealed by the hardware sealing key of the target migration confidential computing environment to achieve two-layer key management. It can be understood that the two-layer key management mechanism can effectively solve the problem that the confidential computing sealing key cannot be migrated.
[0142] 8. The source migration controller initiates the smart contract for blockchain node migration in the authoritative blockchain network, initiates the third migration transaction, and establishes a migration hash time lock. Among them, the hash time lock can effectively prevent fork attacks and rollback attacks during blockchain node migration. When establishing the hash time lock, the source migration controller sets the original image R (also known as the hint number) and notifies the target migration controller and the smart contract for blockchain node migration of the hash value H=Hash(R) and the threshold time T of the hash time lock.
[0143] 9. The target migration controller responds to the third migration transaction of the blockchain node migration in the authoritative blockchain network, receives the hash value H, and establishes a hash time lock.
[0144] 10. The source migration controller uses the migration tool CRIU to collect the process-related status information of the source migration non-confidential computing environment, and then uses multiple migration non-confidential session keys to dynamically migrate the process-related status information in the source migration non-confidential computing environment to the target migration non-confidential computing environment. The transmission of the process-related status information of the source non-confidential computing environment includes resources such as process control blocks, processor contexts, process memory status information, and open files. Further, the target non-confidential computing environment can be restored using CRIU.
[0145] 11. The source migration controller uses the migration tool CRIU and the migration library to collect the process-related status information and memory information of the source migration confidential computing environment, and then uses the migration confidential session key to encrypt the process-related status information and memory information in the source migration confidential computing environment, and migrates it to the target migration confidential computing environment. As a result, the target migration confidential computing environment can use the migration confidential session key to decrypt and restore the corresponding confidential computing environment. Among them, the process status information may include resources such as process control blocks, processor contexts, process memory status information, and open files.
[0146] Among them, the migration library in the source migration non-confidential computing environment can effectively solve the problem that the trusted memory of process-level applications cannot be migrated:
[0147] (1) The userxxx.so file dynamic library compiled by the user records the composition of each data segment of the active migration confidential computing environment. When the confidential computing environment program is loaded and run, the confidential computing environment loader can parse the dynamic library to obtain the base address, size, offset information, etc. of each data segment in the trusted area.
[0148] (2) The resources that need to be saved in the confidential computing environment are mainly memory pages, which can be obtained through the / proc file system. Open the pid folder corresponding to the confidential computing environment process and view the / proc / $(pid) / maps file to obtain the mapping of the source migration confidential computing environment in the process virtual memory address space, and then obtain the virtual memory space layout information.
[0149] (3) The migration library migrates the process-related status information and memory information of the source migration confidential computing environment based on the base address, size, offset information, etc. of each data segment in the confidential computing environment and the virtual memory space layout information. Specifically, the migration library can encrypt the process-related status information and memory information using the migration confidential session key by executing the ECALL function, and then export it from the source migration confidential computing environment to the source migration non-confidential computing environment, and transmit it to the target migration confidential computing environment with the help of the source migration controller. In this way, the problem of the inability to migrate the trusted memory of process-level applications is effectively solved.
[0150] (4) During the recovery process of the target migration confidential computing environment, the memory layout of the target migration confidential computing environment must be consistent with the source migration confidential computing environment, thereby ensuring the legitimacy of some pointer variables in the program so that they can continue to be used after recovery. First, when creating the target migration confidential computing environment, the target migration controller prohibits the randomization function of the base address of the target migration confidential computing environment; then the migration library uses the ECALL function to transfer the encrypted data to the target migration confidential computing environment, decrypts it with the migration confidential session key, and finally copies it to the corresponding virtual memory address.
[0151] 12. The source migration controller uses the static data session key to encrypt and transmit the static encrypted data and static non-encrypted data in the source blockchain node to the target blockchain node.
[0152] 13. The source blockchain node stops running: In response to the hash time lock smart contract in the authoritative blockchain network, after the source blockchain node sends the original image R of the hash time lock to the target migration controller, the authoritative blockchain network marks the remote proof information of the source blockchain node as unavailable.
[0153] 14. The target blockchain node starts running: In response to the hash time lock smart contract in the authoritative blockchain network, the target migration controller obtains the original image R of the hash time lock, and the authoritative blockchain network marks it as the currently executable blockchain node and updates its corresponding remote proof information. During this process, the authoritative blockchain network will perform hash time lock verification: the target migration controller sends the original image R to the authoritative blockchain network, and the authoritative blockchain network checks whether the target migration controller sends the original image R within the threshold time T of the hash time lock, and verifies whether Hash (R) is equal to H. If both pass, the hash time lock is executed successfully and the migration is determined to be successful.
[0154] It can be seen that the application migration method provided by the embodiment of the present invention has the following advantages:
[0155] (1) To address the fork attack during the blockchain node migration process, a hash time lock algorithm is proposed based on the supervision mechanism of the authoritative blockchain, which ensures that the node can only run on the target node after migration.
[0156] (2) To prevent rollback attacks during blockchain node migration, the migration transaction on-chain mechanism based on the authoritative blockchain ensures that the target node can only run the latest sealed data of the blockchain node.
[0157] (3) To address the problem that confidential computing sealing keys cannot be migrated, a two-layer sealing mechanism is proposed to achieve the migration of confidential computing sealing keys.
[0158] (4) Controlled migration, that is, migration can only be carried out with the authorization of the computer owner, and the source migration confidential computing environment must be migrated to the correct target computer, that is, it can only be migrated to the node controlled by the blockchain system, and the business blockchain and the authoritative blockchain must work together at the same time.
[0159] (5) To address the problem that the trusted memory of process-level applications cannot be migrated, a migration library is built in a non-confidential computing environment to implement assisted migration.
[0160] An embodiment of the present invention provides an application migration device.
[0161] Please refer to Figure 4 , Figure 4 This is a schematic diagram of the structure of an application migration device provided by the present invention, which is applied to a source node to which the application to be migrated belongs, and the source node and the target node are deployed in a business blockchain network, and may include:
[0162] Sending module 1, used to send the first remote proof to the authoritative blockchain network for on-chain storage, and control the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage;
[0163] Verification module 2, used to obtain a second remote proof from the authoritative blockchain network for verification, obtain the first verification result, and determine the second verification result of the target node for the first remote proof;
[0164] Negotiation module 3, used for negotiating with the target node to determine the migration key when the first verification result and the second verification result are both verified to be passed;
[0165] The migration module 4 is used to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key.
[0166] It can be seen that the application migration device provided in the embodiment of the present invention creates an authoritative blockchain network and connects it to the business blockchain network, so as to help the business blockchain network realize application migration between internal blockchain nodes, thereby realizing effective migration of confidential computing environment between various blockchain nodes. For source nodes and target nodes in the business blockchain network that need to perform application migration, both can send their own remote certificates to the authoritative blockchain network for chain storage, and verify each other's remote certificates. After the verification of both parties is passed, the migration key negotiated between the two parties is used to migrate the relevant data information on the source node to the target node. In this process, effective migration of confidential computing environment between various blockchain nodes in the blockchain network is realized.
[0167] In one embodiment of the present invention, the sending module 1 may include:
[0168] A collecting unit, configured to collect the remote attestation of the source confidential computing environment and the remote attestation of the source controller by using the source controller, and generate a first remote attestation;
[0169] A verification unit, configured to send the first remote proof to an authoritative blockchain network, so as to verify the first remote proof using a first smart contract in the authoritative blockchain network;
[0170] The storage unit is used to save the first remote proof and the verification result of the first remote proof to the authoritative blockchain network after the verification is passed, so as to realize on-chain storage.
[0171] In one embodiment of the present invention, the first remote attestation may include an environment execution code reference value and a hardware signature; accordingly, the above-mentioned verification unit may be specifically used to send the first remote attestation to an authoritative blockchain network, so that the authoritative blockchain network uses the pre-stored reference value in the first smart contract to verify the environment execution code reference value, and uses the remote attestation service in the first smart contract to verify the hardware signature.
[0172] In one embodiment of the present invention, the above-mentioned sending module 1 can be specifically used to use the source controller to initiate a first migration transaction to the business blockchain network, so that the business blockchain network uses the second smart contract to initiate a second migration transaction to the target node, so that the target node can create a target controller, a target confidential computing environment, and a target non-confidential computing environment, and use the target controller to collect the second remote proof and send it to the authoritative blockchain network for chain storage.
[0173] In one embodiment of the present invention, the sending module 1 can also be used to utilize a second smart contract in the business blockchain network to store the first migration transaction and the second migration transaction on the chain through a preset consensus algorithm.
[0174] In one embodiment of the present invention, the migration module 4 may include:
[0175] a determination unit, configured to determine a confidential session key, a non-confidential session key, an encrypted session key, and a non-encrypted session key according to the migration key;
[0176] A first migration unit, configured to encrypt a source confidential computing environment using a confidential session key and then migrate the encrypted environment to a target node;
[0177] A second migration unit, configured to encrypt the source non-confidential computing environment using a non-confidential session key and then migrate the encrypted environment to a target node;
[0178] A third migration unit is used to encrypt the source static non-encrypted data and the source static encrypted data using the non-encrypted session key and then migrate them to the target node;
[0179] The fourth migration unit is used to encrypt the encryption key of the source static encrypted data by using the encryption session key and then migrate the encryption key to the target node.
[0180] In one embodiment of the present invention, the first migration unit may include:
[0181] A first collecting subunit is used to collect first process information and memory information of the application to be migrated in the source confidential computing environment by using a preset migration tool in the source controller;
[0182] The first migration subunit is used to encrypt the first process information and memory information based on a preset migration library in a source non-confidential computing environment using a confidential session key and then migrate them to a target node.
[0183] In one embodiment of the present invention, the above-mentioned first collection sub-unit can be specifically used to parse the preset dynamic library corresponding to the source confidential computing environment to obtain the storage information of each data segment in the trusted memory; obtain the virtual memory space layout information of the source confidential computing environment in the preset file corresponding to the source confidential computing environment; and generate memory information using the storage information of each data segment and the virtual memory space layout information.
[0184] In one embodiment of the present invention, the above-mentioned first migration sub-unit can be specifically used to execute the target function based on the preset migration library in the source non-confidential computing environment, so as to encrypt the second process information and memory information using the confidential session key to obtain encrypted information; export the encrypted information to the source non-confidential computing environment, and migrate it from the source non-confidential computing environment to the target node.
[0185] In one embodiment of the present invention, the second migration unit may include:
[0186] A second collecting subunit is used to collect second process information of the application to be migrated in the source non-confidential computing environment by using a preset migration tool in the source controller;
[0187] The second migration subunit is used to encrypt the second process information using the non-confidential session key and then migrate it to the target node.
[0188] In one embodiment of the present invention, the migration module 4 may include:
[0189] An initiating unit, configured to establish a migration smart contract using a source controller, and initiate a third migration transaction corresponding to the migration smart contract to an authoritative blockchain network, so that a target node responds to the third migration transaction;
[0190] The migration unit is used to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key during the third migration transaction.
[0191] In one embodiment of the present invention, the above-mentioned initiating unit can be specifically used to use the source controller to establish a first hash time lock, and establish a migration smart contract based on the first hash time lock; initiate a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction and establishes a second hash time lock, so that the authoritative blockchain network verifies the application migration result according to the first hash time lock and the second hash time lock.
[0192] In one embodiment of the present invention, when the application migration result is that the application migration is successful, the source node is marked as an unavailable node by the authoritative blockchain network, and the target node is marked as an available node by the authoritative blockchain network.
[0193] In one embodiment of the present invention, when the authoritative blockchain network receives the hash information of the second hash time lock within a preset time, and the hash value of the hash information is consistent with the hash value of the second hash time lock, the application migration result is that the application migration is successful.
[0194] In one embodiment of the present invention, the above-mentioned sending module 1 can be specifically used to send the first remote proof to the authoritative blockchain network for on-chain storage when the local load reaches a preset load threshold.
[0195] In one embodiment of the present invention, the above-mentioned sending module 1 can be specifically used to send the first remote proof to the authoritative blockchain network for on-chain storage when a system upgrade instruction is received.
[0196] For an introduction to the device provided in the embodiment of the present invention, please refer to the above method embodiment, and the present invention will not be elaborated here.
[0197] An embodiment of the present invention provides an electronic device.
[0198] Please refer to Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided by the present invention, and the electronic device may include:
[0199] A memory 11, used for storing computer programs;
[0200] The processor 10 can implement the steps of any one of the above-mentioned application migration methods when executing a computer program.
[0201] like Figure 5 , which is a schematic diagram of the composition structure of an electronic device, the electronic device may include: a processor 10, a memory 11, a communication interface 12 and a communication bus 13. The processor 10, the memory 11 and the communication interface 12 all communicate with each other through the communication bus 13.
[0202] In the embodiment of the present invention, the processor 10 may be a central processing unit (CPU), an application specific integrated circuit, a digital signal processor, a field programmable gate array or other programmable logic devices.
[0203] The processor 10 may call a program stored in the memory 11. Specifically, the processor 10 may execute operations in the embodiment of the application migration method.
[0204] The memory 11 is used to store one or more programs, which may include program codes, and the program codes include computer operation instructions. In the embodiment of the present invention, the memory 11 at least stores programs for implementing the following functions:
[0205] Send the first remote proof to the authoritative blockchain network for on-chain storage, and control the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage;
[0206] Obtain a second remote proof from the authoritative blockchain network for verification, obtain the first verification result, and determine the second verification result of the target node for the first remote proof;
[0207] When the first verification result and the second verification result are both verified to be passed, negotiating with the target node to determine the migration key;
[0208] The source confidential computing environment, source non-confidential computing environment, source static encrypted data, and source static non-encrypted data in the source node are migrated to the target node using the migration key.
[0209] In a possible implementation, the memory 11 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function, etc.; the data storage area may store data created during use.
[0210] In addition, the memory 11 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device or other volatile solid-state storage device.
[0211] The communication interface 12 may be an interface of a communication module, and is used to connect to other devices or systems.
[0212] Of course, it should be noted that Figure 5 The structure shown does not constitute a limitation on the electronic device in the embodiment of the present invention. In actual applications, the electronic device may include Figure 5 More or fewer components than shown, or combinations of certain components.
[0213] An embodiment of the present invention provides a computer-readable storage medium.
[0214] The computer-readable storage medium provided in the embodiment of the present invention stores a computer program, and when the computer program is executed by a processor, the steps of any one of the above-mentioned application migration methods can be implemented.
[0215] Among them, the computer-readable storage medium can be any available medium that can be stored in a computer or a data storage device such as a server or data center that includes one or more available media integrated. For example, it can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape, etc.), an optical medium (such as a DVD) or a semiconductor medium (such as a solid-state hard disk) and other media that can store computer program codes.
[0216] For an introduction to the computer-readable storage medium provided in an embodiment of the present invention, please refer to the above method embodiment, and the present invention will not elaborate on it here.
[0217] An embodiment of the present invention provides a computer program product.
[0218] The computer program product provided by the embodiment of the present invention includes a computer program / instruction. When the computer program / instruction is executed by a processor, the steps of any one of the above-mentioned application migration methods can be implemented.
[0219] Specifically, in the above embodiments, all or part of them can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of them can be implemented in the form of a computer program product.
[0220] Among them, the computer program product may include one or more computer programs / instructions, and when the computer program / instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention may be generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, computer instructions may be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line, etc.) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0221] For an introduction to the computer program product provided by the embodiment of the present invention, please refer to the above method embodiment, and the present invention will not be elaborated here.
[0222] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0223] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0224] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0225] The technical solution provided by the present invention is described in detail above. Specific examples are used herein to illustrate the principle and implementation of the present invention, and the description of the above embodiments is only used to help understand the method of the present invention and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principle of the present invention, the present invention can also be improved and modified, and these improvements and modifications also fall within the scope of protection of the present invention.
Claims
1. An application migration method, characterized in that: Applied to a source node to which the application to be migrated belongs, the source node and the target node are deployed in a business blockchain network, the business blockchain network is connected to an authoritative blockchain network, and the method includes: Sending the first remote proof to the authoritative blockchain network for on-chain storage, and controlling the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage; Obtaining the second remote proof from the authoritative blockchain network for verification, obtaining a first verification result, and determining a second verification result of the target node for the first remote proof; the second verification result is obtained by the target node obtaining the first remote proof from the authoritative blockchain network for verification; When both the first verification result and the second verification result are verified to be passed, negotiating with the target node to determine the migration key; Migrating the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key; Among them, sending the first remote proof to the authoritative blockchain network for on-chain storage includes: using the source controller to collect the remote proof of the source confidential computing environment and the remote proof of the source controller to generate the first remote proof; sending the first remote proof to the authoritative blockchain network to verify the first remote proof using the first smart contract in the authoritative blockchain network; when the verification is passed, saving the first remote proof and the verification result of the first remote proof to the authoritative blockchain network to achieve on-chain storage; Controlling the target node to send the second remote proof to the authoritative blockchain network for on-chain storage through the business blockchain network includes: using the source controller to initiate a first migration transaction to the business blockchain network, so that the business blockchain network uses a second smart contract to initiate a second migration transaction to the target node, so that the target node can create a target controller, a target confidential computing environment, and a target non-confidential computing environment, and using the target controller to collect the second remote proof and send it to the authoritative blockchain network for on-chain storage.
2. The application migration method according to claim 1, characterized in that: The first remote attestation includes an environment execution code reference value and a hardware signature; Accordingly, sending the first remote proof to the authoritative blockchain network to verify the first remote proof using the first smart contract in the authoritative blockchain network includes: The first remote attestation is sent to the authoritative blockchain network, so that the authoritative blockchain network verifies the environment execution code reference value using the pre-stored reference value in the first smart contract, and verifies the hardware signature using the remote attestation service in the first smart contract.
3. The application migration method according to claim 1, characterized in that: Also includes: The first migration transaction and the second migration transaction are stored on the chain by using a second smart contract in the business blockchain network through a preset consensus algorithm.
4. The application migration method according to claim 1, characterized in that: Migrating the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key includes: Determine a confidential session key, a non-confidential session key, an encrypted session key, and a non-encrypted session key according to the migration key; encrypting the source confidential computing environment using the confidential session key and then migrating it to the target node; Encrypting the source non-confidential computing environment using the non-confidential session key and then migrating it to the target node; Using the non-encrypted session key, the source static non-encrypted data and the source static encrypted data are encrypted and then migrated to the target node; The encryption key of the source static encrypted data is encrypted using the encryption session key and then migrated to the target node.
5. The application migration method according to claim 4, characterized in that: Encrypting the source confidential computing environment using the confidential session key and then migrating it to the target node includes: Using a preset migration tool in the source controller to collect first process information and memory information of the application to be migrated in the source confidential computing environment; Based on a preset migration library in the source non-confidential computing environment, the first process information and the memory information are encrypted using the confidential session key and then migrated to the target node.
6. The application migration method according to claim 5, characterized in that: Using a preset migration tool in the source controller to collect memory information of the application to be migrated in the source confidential computing environment includes: Parsing a preset dynamic library corresponding to the source confidential computing environment to obtain storage information of each data segment in the trusted memory; Obtaining virtual memory space layout information of the source confidential computing environment in a preset file corresponding to the source confidential computing environment; The memory information is generated using the storage information of each of the data segments and the virtual memory space layout information.
7. The application migration method according to claim 5, characterized in that: Based on a preset migration library in the source non-confidential computing environment, encrypting the first process information and the memory information using the confidential session key and then migrating them to the target node includes: Executing a target function based on a preset migration library in the source non-confidential computing environment to encrypt the first process information and the memory information using the confidential session key to obtain encrypted information; The encrypted information is exported to the source non-confidential computing environment and migrated from the source non-confidential computing environment to the target node.
8. The application migration method according to claim 4, characterized in that: Encrypting the source non-confidential computing environment using the non-confidential session key and then migrating it to the target node includes: Using a preset migration tool in the source controller to collect second process information of the application to be migrated in the source non-confidential computing environment; The second process information is encrypted using the non-confidential session key and then migrated to the target node.
9. The application migration method according to claim 1, characterized in that: Migrating the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key includes: Using the source controller to establish a migration smart contract, and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction; During the third migration transaction, the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node are migrated to the target node using the migration key.
10. The application migration method according to claim 9, characterized in that: Using the source controller to establish a migration smart contract, and initiating a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction, including: Using the source controller to establish a first hash time lock, and establishing a migration smart contract based on the first hash time lock; Initiate a third migration transaction corresponding to the migration smart contract to the authoritative blockchain network, so that the target node responds to the third migration transaction and establishes a second hash time lock, so that the authoritative blockchain network verifies the application migration result according to the first hash time lock and the second hash time lock.
11. The application migration method according to claim 10, characterized in that: When the application migration result is that the application migration is successful, the source node is marked as an unavailable node by the authoritative blockchain network, and the target node is marked as an available node by the authoritative blockchain network.
12. The application migration method according to claim 10, characterized in that: When the authoritative blockchain network receives the hash information of the second hash time lock within a preset time, and the hash value of the hash information is consistent with the hash value of the second hash time lock, the application migration result is that the application migration is successful.
13. The application migration method according to claim 1, characterized in that: Send the first remote proof to the authoritative blockchain network for on-chain storage, including: When the local load reaches a preset load threshold, the first remote proof is sent to the authoritative blockchain network for on-chain storage.
14. The application migration method according to claim 1, characterized in that: Send the first remote proof to the authoritative blockchain network for on-chain storage, including: When a system upgrade instruction is received, the first remote proof is sent to the authoritative blockchain network for on-chain storage.
15. An application migration device, characterized in that: Applied to the source node to which the application to be migrated belongs, the source node and the target node are deployed in a business blockchain network, the business blockchain network is connected to the authoritative blockchain network, and the device includes: A sending module, used to send the first remote proof to the authoritative blockchain network for on-chain storage, and control the target node through the business blockchain network to send the second remote proof to the authoritative blockchain network for on-chain storage; A verification module, configured to obtain the second remote proof from the authoritative blockchain network for verification, obtain a first verification result, and determine a second verification result of the target node for the first remote proof; the second verification result is obtained by the target node obtaining the first remote proof from the authoritative blockchain network for verification; A negotiation module, configured to negotiate with the target node to determine a migration key when both the first verification result and the second verification result are verified to be passed; A migration module, used to migrate the source confidential computing environment, the source non-confidential computing environment, the source static encrypted data, and the source static non-encrypted data in the source node to the target node using the migration key; The sending module is specifically used to collect the remote proof of the source confidential computing environment and the remote proof of the source controller by using the source controller to generate the first remote proof; send the first remote proof to the authoritative blockchain network to verify the first remote proof by using the first smart contract in the authoritative blockchain network; when the verification is passed, save the first remote proof and the verification result of the first remote proof to the authoritative blockchain network to realize on-chain storage; as well as, A first migration transaction is initiated to the business blockchain network using a source controller, so that the business blockchain network initiates a second migration transaction to the target node using a second smart contract, so that the target node can create a target controller, a target confidential computing environment, and a target non-confidential computing environment, and use the target controller to collect the second remote proof and send it to the authoritative blockchain network for on-chain storage.
16. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the application migration method as described in any one of claims 1 to 14 when executing the computer program.
17. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the application migration method according to any one of claims 1 to 14 are implemented.
18. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the application migration method according to any one of claims 1 to 14 are implemented.
Citation Information
Patent Citations
Virtual machine migration method and device
CN115904612A
Remote attestation method, device and equipment and readable storage medium
CN116112187A