Computer device, operation method thereof, and security chip
By decoupling security chips from processing chips in computer devices and employing access control and communication protection mechanisms, the problem of the trust chain in trusted execution environments depending on the trustworthiness of processing chip manufacturers has been solved, achieving higher trustworthiness and multi-chip compatibility, and promoting the application and standardization of confidential computing.
Patent Information
- Application Number
- CN202410971135.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-19
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2042-09-19
AI Technical Summary
In existing confidential computing solutions, the trust chain of the trusted execution environment depends on the trustworthiness of the processing chip manufacturer, which limits the level of trust and makes it difficult to achieve interoperability between chips from different manufacturers, thus restricting large-scale applications.
By separating the security chip from the processing chip, the security chip runs a root of trust and ensures the security of the root of trust through access control and communication protection mechanisms, which is independent of the trustworthiness of the processing chip manufacturer, thus achieving decoupling of the trusted execution environment.
It improves the credibility of confidential computing, eliminates distrust of chip manufacturers, enhances the compatibility of computing devices with various chips, and promotes the development of large-scale confidential computing application scenarios and the standardization of the security ecosystem.
Smart Images

Figure CN119066658B_ABST
Abstract
Description
[0001] This application is a divisional application. The original application has the application number 202211139911.3 and the original application date is September 19, 2022. The entire contents of the original application are incorporated herein by reference. Technical Field
[0002] This application relates to the field of confidential computing technology, and in particular to a computer device and its operating method, and a security chip. Background Technology
[0003] With the rapid development of computer technology, data security has received increasing attention. Current data security protection strategies typically apply to data stored statically or in the process of network transmission. However, data security remains at risk when it is being used. Therefore, protecting data that is currently in use is an urgent problem to be solved.
[0004] Currently, confidential computing technology can be used to protect data in use. Within the Confidential Computing Consortium (CCC), confidential computing is defined as: a technology that protects data in use by performing computations within a hardware-based trusted execution environment (TEE). Because the computation takes place within a TEE, the data involved in the computation can be protected. The key to confidential computing's ability to protect the security of data in use lies in the trust chain that relies on the TEE, which in turn depends on the root of trust within the processing chip performing the computation.
[0005] However, the trustworthiness of the root of trust is limited by the trustworthiness of the chip manufacturer, which in turn affects the trustworthiness of confidential computing. Summary of the Invention
[0006] This application provides a computer device and its operating method, as well as a security chip. This application frees the trustworthiness of the root of trust in the security chip from the trustworthiness of the processing chip manufacturer, thus breaking free from the current limitation of the trusted execution environment construction being confined to the processing chip manufacturer, and thereby improving the trustworthiness of confidential computing. The technical solution provided by this application is as follows:
[0007] In a first aspect, this application provides a computer device. The computer device includes: a processing chip and a security chip; the security chip is used to run a root of trust, and to start the processing chip and perform trusted control over the processing chip based on the root of trust; the processing chip includes a trusted execution environment, which is built based on the root of trust and is used to perform confidential computations.
[0008] In the computer device provided in this application, the security chip and the processing chip are set up separately, achieving decoupling between the two. The security chip's security can be guaranteed and endorsed by the security chip manufacturer. In this way, the trustworthiness of the root of trust in the security chip is no longer subject to the trustworthiness of the processing chip manufacturer, breaking free from the current situation where the construction of a trusted execution environment is limited by the processing chip manufacturer. This improves the trustworthiness of confidential computing and eliminates user distrust of the processing chip manufacturer. Because the security chip and the processing chip are decoupled, the security chip can interface with different types of processing chips, improving the overall computer device's compatibility with various chips. This is conducive to promoting the development of large-scale confidential computing applications and advancing the standardization process of the confidential computing security ecosystem.
[0009] Optionally, the trusted root may include one or more of the following: a boot root, a metric root, and a cryptographic root. The boot root is used to securely boot the processing chip. The metric root is used to prove the secure and trustworthy operating status of the computer device to a remote user, i.e., to achieve remote authentication. The cryptographic root is used to encrypt the memory space of the trusted execution environment to ensure that data is not leaked in plaintext in memory.
[0010] In one implementation, the security chip is specifically used to obtain the firmware image used by the boot processing chip using a root of trust, and to boot the processing chip using the firmware image after the processing chip is powered on.
[0011] After placing the root of trust outside the processing chip, a critical issue is how to maintain the security and trustworthiness of the root of trust itself and the communication between the root of trust and the processing chip. To address this, this application proposes several security mechanisms while implementing the externalization of the root of trust. In one possible implementation, access control mechanisms and / or communication protection mechanisms can be set up in the computer device to ensure the security and trustworthiness of the root of trust, as well as the security and trustworthiness of the communication between the security chip and the processing chip. The access control mechanism and the communication protection mechanism are described below.
[0012] In one implementation of the access control mechanism, the processing chip includes a first access control module. The first access control module receives access requests to the trusted root, forwards the access request to the security chip if the request has the necessary permissions, and rejects the access request if it does not. The security chip also responds to the access requests.
[0013] In another implementation of the access control mechanism, the security chip includes a second access control module. This second access control module receives access requests to the trusted root, responds to the access request if the request has the necessary permissions, and denies the access request if the request does not have the necessary permissions.
[0014] In another implementation of the access control mechanism, the processing chip includes a third access control module, and the security chip includes a fourth access control module. The third access control module is used to receive access requests to the trusted root, obtain the permission indication information of the access request, and forward the access request and its permission indication information to the security chip; the fourth access control module is used to respond to the access request when the permission indication information indicates that the access request has permission, and to deny the access request when the permission indication information indicates that the access request does not have permission.
[0015] Since the root of trust is the root of trust of the trusted execution environment, the trusted execution environment has a higher security level for the root of trust. The root of trust can be accessed by the trusted execution environment. Therefore, access requests from the trusted execution environment have access rights, while access requests from outside the trusted execution environment do not have access rights.
[0016] By authenticating access requests through access control mechanisms, we can ensure the validity of access from the trusted execution environment and block access from outside the trusted execution environment, thus ensuring the security and trustworthiness of the root of trust.
[0017] The communication protection mechanism is described below. In this application, the communication protection mechanism can be implemented through cooperation between a processing chip and a security chip. In one possible implementation of the communication protection mechanism, the processing chip includes a first communication protection module, and the security chip includes a second communication protection module, which is matched with the first communication protection module. In this case, the first and second communication protection modules jointly protect the communication between the security chip and the processing chip. For example, the first communication protection module performs a first communication protection measure on the communication content between the security chip and the processing chip; the second communication protection module performs a second communication protection measure on the communication content between the security chip and the processing chip, which is matched with the first communication protection measure. Alternatively, the second communication protection module performs a first communication protection measure on the communication content between the security chip and the processing chip; the first communication protection module performs a second communication protection measure on the communication content between the security chip and the processing chip, which is matched with the first communication protection measure.
[0018] When implementing the communication protection mechanism, the first and second communication protection modules can use one or more strategies to ensure the security of communication between the security chip and the processing chip. In one implementation, the first and second communication protection modules are specifically used to protect the communication between the security chip and the processing chip based on a key strategy, thereby ensuring the confidentiality of the communication between the security chip and the processing chip.
[0019] Optionally, the first communication protection module and the second communication protection module are further used to protect the communication between the security chip and the processing chip based on at least one of the signature strategy and the timestamp strategy, so as to ensure the integrity of the communication between the security chip and the processing chip and prevent the communication content between the security chip and the processing chip from being forged and tampered with.
[0020] Optionally, the security chip is also used in the remote verification process. The security chip can implement the remote verification process using metric roots. In one implementation, the security chip is also used to receive metric values generated by the processing chip during startup, receive security verification requests for the trusted execution environment, generate a metric report based on the metric values, and feed back the metric report based on the security verification request.
[0021] Optionally, the computer device also includes a memory chip, and the processing chip includes a memory encryption module. The security chip is then further used to encrypt the memory. The security chip can use a cryptographic root to implement a remote authentication process. In one possible implementation, the security chip is also used to generate a key using a trusted root and provide the key to the memory encryption module; the memory encryption module is used to encrypt memory data using the key and provide the encrypted memory data to the memory chip, and / or, to obtain encrypted memory data from the memory chip and decrypt the encrypted memory data using the key; the memory chip is used to store the encrypted memory data, and / or, to provide the encrypted memory data to the memory encryption module.
[0022] Secondly, this application provides a method for operating a computer device. The computer device includes a processing chip and a security chip. The method for operating the computer device includes: the security chip running a root of trust, and starting the processing chip and performing trusted control on the processing chip based on the root of trust; the processing chip constructing a trusted execution environment based on the root of trust, the trusted execution environment being used to perform confidential computation.
[0023] Optionally, the security chip boots the processing chip based on a trusted root, including: the security chip using the trusted root to obtain the firmware image used by the boot processing chip; and the security chip using the firmware image to boot the processing chip after the processing chip is powered on.
[0024] Optionally, a trusted root may include one or more of the following: a startup root, a metric root, and a cryptographic root.
[0025] Optionally, the processing chip includes a first access control module, and the operation method of the computer device further includes: the first access control module receiving an access request to the trusted root, forwarding the access request to the security chip when the access request has access rights, and rejecting the access request when the access request does not have access rights; and the security chip responding to the access request.
[0026] Optionally, the security chip includes a second access control module, and the operation method of the computer device further includes: the second access control module receiving an access request to the trusted root, responding to the access request when the access request has access rights, and rejecting the access request when the access request does not have access rights.
[0027] Optionally, the processing chip includes a third access control module, and the security chip includes a fourth access control module. The operation method of the computer device further includes: the third access control module receiving an access request to the trusted root, obtaining permission indication information of the access request, and forwarding the access request and its permission indication information to the security chip; the fourth access control module responding to the access request when the permission indication information indicates that the access request has access rights, and rejecting the access request when the permission indication information indicates that the access request does not have access rights.
[0028] Optionally, access requests from the trusted execution environment have access rights, while access requests from outside the trusted execution environment do not.
[0029] Optionally, the processing chip includes a first communication protection module, and the security chip includes a second communication protection module, which is matched with the first communication protection module. The operation method of the computer device further includes: the first communication protection module and the second communication protection module jointly protect the communication between the security chip and the processing chip.
[0030] Optionally, both the first and second communication protection modules are based on a key strategy to protect the communication between the security chip and the processing chip.
[0031] Optionally, both the first communication protection module and the second communication protection module protect the communication between the security chip and the processing chip based on at least one of a signature strategy and a timestamp strategy.
[0032] Optionally, the operation method of the computer device further includes: the security chip receiving a metric value generated by the processing chip during the startup process; the security chip receiving a security verification request for the trusted execution environment; the security chip generating a metric report based on the metric value, and feeding back the metric report based on the security verification request.
[0033] Optionally, the computer device further includes: a memory chip, and the processing chip includes a memory encryption module. The operation method of the computer device further includes: a security chip generating a key using a trusted root and providing the key to the memory encryption module; the memory encryption module encrypting memory data using the key and providing the encrypted memory data to the memory chip; and the memory chip storing the encrypted memory data.
[0034] Optionally, the computer device further includes: a memory chip, and the processing chip includes a memory encryption module. The operation method of the computer device further includes: a security chip generating a key using a trusted root and providing the key to the memory encryption module; the memory chip providing encrypted memory data to the memory encryption module; and the memory encryption module using the key to decrypt the encrypted memory data.
[0035] Thirdly, this application provides a security chip, which is the security chip in the first aspect of this application and any possible implementation thereof.
[0036] Fourthly, this application provides a computer device including a memory and a processor, the memory storing program instructions, and the processor executing the program instructions to perform the methods provided in the second aspect of this application and any possible implementation thereof.
[0037] Fifthly, this application provides a computer-readable storage medium that is a non-volatile computer-readable storage medium, the computer-readable storage medium including program instructions that, when executed on a container management device, cause the container management device to perform the methods provided in the second aspect of this application and any of its possible implementations.
[0038] Sixthly, this application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods provided in the second aspect of this application and any possible implementation thereof. Attached Figure Description
[0039] Figure 1 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application;
[0040] Figure 2 This is a schematic diagram of the structure of another computer device provided in an embodiment of this application;
[0041] Figure 3 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0042] Figure 4 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0043] Figure 5 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0044] Figure 6 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0045] Figure 7 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0046] Figure 8 This is a schematic diagram illustrating the secure boot process of a computer device according to an embodiment of this application;
[0047] Figure 9 This is a schematic diagram illustrating a process of remote authentication implemented by a computer device according to an embodiment of this application;
[0048] Figure 10 This is a schematic diagram illustrating the process of implementing memory encryption in a computer device according to an embodiment of this application;
[0049] Figure 11 This is a schematic diagram of the structure of another computer device provided in the embodiments of this application;
[0050] Figure 12 This is a flowchart illustrating a method for operating a computer device according to an embodiment of this application;
[0051] Figure 13 This is a flowchart of another method for operating a computer device provided in an embodiment of this application. Detailed Implementation
[0052] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0053] To facilitate understanding, some terms and technologies involved in the embodiments of this application will be briefly introduced below.
[0054] Confidential computing is a technology that uses hardware and software capabilities to build and run a trusted execution environment isolated from untrusted environments, ensuring its confidentiality, and performing computations within it to protect data in use. In the Consortium for Confidential Computing, confidential computing is defined as: a technology that protects data in use by performing computations within a hardware-based trusted execution environment.
[0055] Trusted control refers to the control operations performed on the object to be measured based on the results of trusted measurement; therefore, trusted control can also be called control. Specifically, when the measurement of the object passes, the object's original state can be maintained, or the operations expected to be performed before the trusted measurement can be executed. When the measurement of the object fails, security measures can be taken. For example, the computer can be reset, or the object can be restarted, to prevent the cause of the measurement failure from posing a security threat to the computer.
[0056] A root of trust (RoT) is a module composed of highly reliable hardware, firmware, and software whose behavior is always predictable. It is a component containing one or more specific security functions, such as measurement, storage, reporting, verification, or updating. The root of trust is the foundation upon which a system can guarantee security and trustworthiness. In existing confidential computing solutions, there are three main types of roots of trust: a boot root for secure boot, a reporting root for remote authentication, and an encryption root for memory encryption.
[0057] Metrics (or trusted metrics) is the process of verifying the security of an object being measured. The trusted metrics process generally includes two parts: computation and verification. Computation refers to using a predetermined algorithm to perform calculations on the software code or configuration files of the object being measured, such as calculating the hash value of the software code. Verification refers to comparing the computation result with a pre-stored benchmark for the object being measured. If the computation result matches the benchmark, the object being measured is determined to be secure; otherwise, it is not. Here, the object being measured is the subject on which the trusted metrics are performed, and the subject performing the trusted metrics operation on the object is the measurement subject.
[0058] The core root of trust for measurement (CRTM) is the executable code used to establish a trustworthy measurement root. Running this core root enables the establishment of a trustworthy measurement root. The core root of trust for measurement is the first piece of code executed after the trusted computing platform powers on.
[0059] The processing chip comprises a Trusted Execution Environment (TEE) and a Rich Execution Environment (REE). TEE and REE are concepts proposed by the Global Platform (GP) organization. They are derived from the existing hardware and software of a mobile terminal device by dividing it into two independent execution environments. The TEE has its own operating system and deploys secure applications. The REE cannot access the resources of the TEE without authorization. The TEE and REE isolate device resources through shared physical components and isolated execution via software scheduling within the hardware. In one implementation, the processing chip can be a processor, such as a central processing unit (CPU).
[0060] With the rapid development of computer technology, data security has received increasing attention. Furthermore, in recent years, with the rapid development of cloud computing, more and more critical services and high-value data have been migrated to the cloud. As computing moves from on-premises deployments to public clouds and the edge, data protection becomes more complex. Current data security protection strategies typically apply to data stored at rest or data in transit over a network. However, data security remains at risk when it is being used. This is one of the most challenging aspects of data protection. Therefore, protecting data that is currently in use is an urgent problem to be solved.
[0061] A significant technological advancement in the security field is confidential computing. Confidential computing protects the security of data in use and has a wide range of applications, particularly in cloud computing. Common applications include enclave-based encrypted data analysis, copyright protection, genetic data processing, key protection, key management systems, privacy-preserving machine learning, and confidential databases. Other applications such as blockchain privacy computing, blockchain, trusted artificial intelligence (AI), and privacy edge computing can all be built upon confidential computing technology to better serve application scenarios. Confidential computing is an innovative data isolation and encryption technology that ensures security at the server chip hardware level. Even if privileged software such as the OS kernel, hypervisor, or even BIOS is compromised or malicious, sensitive data and code remain secure, ensuring the confidentiality and integrity of important application data and code. This provides a user-friendly, secure, and clustered trusted computing environment for critical business operations. Because the computation process takes place within a trusted execution environment, the data involved in the computation is protected. The key to confidential computing's ability to protect the security of data in use lies in the trust chain that relies on the trusted execution environment, which in turn depends on the root of trust within the processing chip executing the computation.
[0062] However, in current solutions for confidential computing, the trust chain of the trusted execution environment is built upon the root of trust embedded in the processing chip. This means the trustworthiness of the root of trust is dependent on the trustworthiness of the processing chip manufacturer, consequently affecting the trustworthiness of the confidential computing itself. Furthermore, this often results in existing confidential computing solutions being strongly tied to the processing chip provider, making them incompatible. Consequently, in some technical solutions, application development within the trusted execution environment of confidential computing requires approval and certification from the processing chip manufacturer. This limits the simultaneous use of chips from different manufacturers within a single system or cluster, hindering the development of large-scale confidential computing.
[0063] This application provides a computer device. Figure 1 This is a schematic diagram of a computer device 10 provided in an embodiment of this application. Figure 1As shown, the computer device 10 includes a processing chip 101 and a security chip 102. The security chip 102 is used to run a root of trust 1021, and to start the processing chip 101 and perform security control on the processing chip 101 based on the root of trust 1021. The processing chip 101 includes a trusted execution environment 1011, which is built based on the root of trust 1021 and is used to perform confidential computations. Since the trusted execution environment 1011 requires a chain of trust, and the chain of trust is built based on the root of trust 1021, it can be considered that the trusted execution environment 1011 is built based on the root of trust 1021.
[0064] In this computer device 10, the security chip 102 and the processing chip 101 are separately configured, achieving decoupling between them. The security of the security chip 102 can be guaranteed and endorsed by its manufacturer. In this way, the trustworthiness of the root of trust 1021 in the security chip 102 is no longer dependent on the trustworthiness of the processing chip 101 manufacturer, thus overcoming the limitation of the Trusted Execution Environment 1011 construction to the processing chip 101 manufacturer. This improves the trustworthiness of confidential computing and eliminates user distrust of the processing chip 101 manufacturer. Because the security chip 102 is decoupled from the processing chip 101, it can interface with different types of processing chips 101, improving the overall compatibility of the computer device 10 with various chips. This is beneficial for promoting the development of large-scale confidential computing applications and advancing the standardization process of the confidential computing security ecosystem.
[0065] After externalizing the root of trust 1021 outside the processing chip 101, a critical issue is how to continue to ensure the security and trustworthiness of the root of trust 1021 itself and the communication between the root of trust 1021 and the processing chip 101. To this end, embodiments of this application propose several security mechanisms while implementing the externalization of the root of trust 1021. In one possible implementation, an access control mechanism and / or a communication protection mechanism can be set in the computer device 10 to ensure the security and trustworthiness of the root of trust 1021, as well as the security and trustworthiness of the communication between the security chip and the processing chip 101. The access control mechanism and the communication protection mechanism are described below.
[0066] In this embodiment, the access control mechanism is implemented as follows: upon receiving an access request to the trusted root 1021, the access request is authenticated; access is allowed if the request has the necessary permissions, and denied if the request does not. Optionally, this access control mechanism can be implemented in the processing chip 101, the security chip 102, or through cooperation between the processing chip 101 and the security chip 102. The implementation processes for these three implementations are described below:
[0067] In the first implementation, the access control mechanism is implemented in the processing chip 101. For example... Figure 2 As shown, in one implementation, the processing chip 101 includes a first access control module 1012. The first access control module 1012 is used to receive access requests to the trusted root 1021. If the access request has the required access rights, it forwards the access request to the security chip 102; if the access request does not have the required access rights, it rejects the access request. At this time, since the access request forwarded by the first access control module 1012 to the security chip 102 has the required access rights, the security chip 102 is also used to receive access requests and respond to them.
[0068] In the second implementation, the access control mechanism is implemented in the security chip 102. For example... Figure 3 As shown, in one implementation, the security chip 102 includes a second access control module 1022. The second access control module 1022 is used to receive access requests to the trusted root 1021, respond to the access request if the request has the necessary access rights, and reject the access request if the request does not have the necessary access rights. The access requests received by the security chip 102 may be sent by the processing chip 101.
[0069] In the third implementation, the access control mechanism is implemented through the cooperation of processing chip 101 and security chip 102. For example... Figure 4 As shown, in one implementation, the processing chip 101 includes a third access control module 1013, and the security chip 102 includes a fourth access control module 1023. The third access control module 1013 receives access requests to the trusted root 1021, obtains access request permission indication information, and forwards the access request and its permission indication information to the security chip 102. The fourth access control module 1023 receives access requests and their access permissions; responds to the access request when the permission indication information indicates that the access request has access permissions; and denies the access request when the permission indication information indicates that the access request does not have access permissions.
[0070] Since the root of trust 1021 is the root of trust of the trusted execution environment 1011, the trusted execution environment 1011 has a higher security level for the root of trust 1021. The root of trust 1021 can be accessed by the trusted execution environment 1011. Therefore, access requests from the trusted execution environment 1011 have access rights, while access requests from outside the trusted execution environment 1011 do not. For example, taking the access control mechanism implemented through the processing chip 101 as an example... Figure 5As shown, when computer device 10 includes a trusted execution environment 1011 and a normal execution environment 1014, since the root of trust 1021 is the root of trust of the trusted execution environment 1011, it can only be accessed by the trusted execution environment 1011 with a higher security level. Any access request from the normal execution environment 1014, including access from the administrator level in the normal execution environment 1014, should not have access to the root of trust 1021. Therefore, all access requests from the trusted execution environment 1011 have access rights, and all access requests from the normal execution environment 1014 do not have access rights.
[0071] By authenticating access requests through an access control mechanism, the validity of access from the Trusted Execution Environment 1011 can be guaranteed, while access from outside the Trusted Execution Environment 1011 can be blocked, thus ensuring the security and trustworthiness of the Root of Trust 1021. This is particularly evident when the computer device 10 is deployed in the cloud. When the computer device 10 is deployed in the cloud, it is usually managed by a cloud administrator. Generally, the cloud administrator has high privileges, but it cannot be ruled out that the cloud administrator may compromise the security of the Root of Trust 1021. In this embodiment, access requests from the cloud administrator can be treated as access requests from the ordinary execution environment 1014. This access control mechanism can deny the cloud administrator's access to the Root of Trust 1021, thus effectively ensuring the security and trustworthiness of the Root of Trust 1021.
[0072] In one possible implementation, when implementing the access control mechanism, access permissions may or may not be carried in the access request. When access permissions are carried in the access request, the access permissions can be determined by the sender of the access request. For example, access permissions can be pre-set for each component in computer device 10 (such as computing resources, memory regions, and peripherals). When any component needs to send an access request, it can first read the access permissions set for it and send the access permissions in the access request. When the access request is not carried in the access request, access permissions can still be pre-set for each component in computer device 10. Any component can send its access permissions to components that need to authenticate their access requests. Alternatively, when the access request is not carried in the access request, the access permissions of all components can be recorded in a designated location in computer device 10. When it is necessary to obtain the access permissions for an access request, the access permissions for the access request can be obtained from that designated location based on the sender of the access request.
[0073] Furthermore, access permissions can also be represented using permission identifiers, with different values for the permission identifier indicating different access permissions. For example, when the permission identifier is assigned a value of 0, it can be determined that there is access permission to trusted root 1021, while when the permission identifier is assigned a value of 1, it can be determined that there is no access permission to trusted root 1021.
[0074] The communication protection mechanism is described below. In this embodiment, the communication protection mechanism can be implemented through the cooperation of processing chip 101 and security chip 102. In one implementation, such as... Figure 6 As shown, the processing chip 101 includes a first communication protection module 1015, and the security chip 102 includes a second communication protection module 1024. The second communication protection module 1024 is matched with the first communication protection module 1015. The first communication protection module 1015 and the second communication protection module 1024 are used to protect the communication between the security chip 102 and the processing chip 101. For example, the first communication protection module performs a first communication protection measure on the communication content between the security chip and the processing chip; the second communication protection module performs a second communication protection measure on the communication content between the security chip and the processing chip, and the second communication protection measure is matched with the first communication protection measure. Alternatively, the second communication protection module performs a first communication protection measure on the communication content between the security chip and the processing chip; the first communication protection module performs a second communication protection measure on the communication content between the security chip and the processing chip, and the second communication protection measure is matched with the first communication protection measure. The matching of the first communication protection module 1015 and the second communication protection module 1024 indicates that they can protect the communication between the processing chip 101 and the security chip 102 according to a pre-agreed encrypted communication protocol.
[0075] In implementing the communication protection mechanism, the first communication protection module 1015 and the second communication protection module 1024 can employ one or more strategies to ensure the security of communication between the security chip 102 and the processing chip 101. In one implementation, the first communication protection module 1015 and the second communication protection module 1024 can protect the communication between the security chip 102 and the processing chip 101 based on a key strategy to ensure the confidentiality of the communication. That is, during communication between the security chip 102 and the processing chip 101, one of the first communication protection modules 1015 and the second communication protection module 1024 can use an encryption key to encrypt the communication content, and the other of the first communication protection module 1015 and the second communication protection module 1024 can use a decryption key matching the encryption key to decrypt the communication content, thereby ensuring the security of the communication content during the communication process.
[0076] Optionally, the first communication protection module 1015 and the second communication protection module 1024 may also protect the communication between the security chip 102 and the processing chip 101 based on at least one of the signature strategy and the timestamp strategy, so as to ensure the integrity of the communication between the security chip 102 and the processing chip 101 and prevent the communication content between the security chip 102 and the processing chip 101 from being forged and tampered with.
[0077] When using a signature strategy, one of the first communication protection module 1015 and the second communication protection module 1024 can sign the communication content using certain methods, and the other of the first communication protection module 1015 and the second communication protection module 1024 can verify the signature. If the verification is successful, it is determined that the communication content has not been forged or tampered with. For example, when the processing chip 101 sends data to the security chip 102, the first communication protection module 1015 can use a hash algorithm to hash the data to be sent, and then use an asymmetric private key to encrypt the hash result to generate a signature. The second communication protection module 1024 can use the corresponding public key to verify the signature.
[0078] When using a timestamp strategy, one of the first communication protection module 1015 and the second communication protection module 1024 can add timestamps to the communication content in some way, and the other of the first communication protection module 1015 and the second communication protection module 1024 can verify the validity of the timestamp. When verifying the validity of the timestamp, it is determined that the communication content has not been forged or tampered with.
[0079] In one implementation, the first communication protection module 1015 and the second communication protection module 1024 can implement a communication protection mechanism through a transport layer security (TLS) protocol or a secure sockets layer (SSL) security protocol.
[0080] In this embodiment, the trusted root 1021 includes one or more of the following: a startup root 1021a, a metric root 1021b (also called a reporting root), and an encryption root 1021c (also called a storage root). The startup root 1021a is used to securely boot the processing chip 101. The metric root 1021b is used to prove the secure and trustworthy operating status of the computer device 10 to a remote user, i.e., to achieve remote authentication. The encryption root 1021c is used to encrypt the memory space of the trusted execution environment 1011 to ensure that data is not leaked in plaintext in memory.
[0081] For example, such as Figure 7As shown, the boot root 1021a, metric root 1021b, and encryption root 1021c all operate within the security chip 102, which is external to the processing chip 101. In this way, with the boot root 1021a, metric root 1021b, and encryption root 1021c all external to the processing chip 101, the security of these components can be guaranteed and endorsed by the manufacturer of the security chip 102, rather than being limited to the manufacturer of the processing chip 101. Furthermore, although... Figure 7 This illustration uses the example where the boot root 1021a, metric root 1021b, and encryption root 1021c all run within the security chip 102. However, it is possible that some of these components could also run outside the security chip 102 (e.g., within the processing chip 101). For example, boot root 1021a and metric root 1021b could run within the security chip 102, while encryption root 1021c could run within the processing chip 101. As those skilled in the art will recognize, the deployment method of boot root 1021a, metric root 1021b, and encryption root 1021c can be adjusted according to changing business requirements; this embodiment does not impose specific limitations on this.
[0082] The implementation processes of startup root 1021a, metric root 1021b, and encryption root 1021c are explained below:
[0083] During the process of booting the root 1021a secure boot processing chip 101, the security chip 102 is specifically used to obtain the firmware image used by the boot processing chip 101 using the boot root 1021a after power-on, and use the firmware image to boot the processing chip 101. In one implementation, such as Figure 8As shown, during the power-on process of computer device 10, security chip 102 first resets and powers on, then security chip 102 constructs a trusted root 1021 by running the trusted measurement root kernel. Then, it verifies the latest version of firmware image 1031 using boot root 1021a. If the latest version of firmware image 1031 passes verification, it is determined that the latest version of firmware image 1031 will be used to boot the processing chip 101. If the latest version of firmware image 1031 fails verification, it is determined that an older backup firmware image 1031 will be used to boot the processing chip 101, ensuring that computer device 10 can boot. Then, the system of computer device 10, including processing chip 101, is powered on, and the determined firmware image is used to boot the processing chip 101. For example, the secure boot system firmware 1016 is used, and then the integrity of the software of computer device 10 (such as the operating system of Trusted Execution Environment 1011 (TEE OS, also known as a secure operating system), the operating system of Ordinary Execution Environment 1014 (LibOS, also known as an ordinary operating system, such as the Linux kernel), virtual machine operating system, etc.) is verified. After verifying that the software has not been tampered with, the trusted system software is loaded, thereby realizing the boot of the entire computer device 10. Among them, the trusted measurement root core is the first line of code that runs after the security chip 102 is powered on, and it can be stored in the read-only memory (ROM) of the security chip 102. The firmware image 1031 can be stored in the flash memory (Flash) 103 of computer device 10. The verification of the firmware image is mainly to verify its integrity, to ensure that the confidential computing firmware has not been tampered with, and after confirming that the confidential computing firmware has not been tampered with, the trusted firmware is loaded. The firmware can be confidential computing firmware, such as the basic input / output system (BIOS), bootloader, ATF, etc. Furthermore, since a security application is deployed in the Trusted Execution Environment 1011, the secure boot process should extend to the integrity of each security application. Each time a security application (such as a user workload) is loaded, the computer device 10 also needs to verify the security application and load the trusted security application only after ensuring that it has not been tampered with. Additionally, the operation of booting the processing chip 101 using a defined firmware image can be performed by the boot module 1017 in the processing chip 101. The boot order of each component during the secure boot process is described in [details omitted]. Figure 8 The direction indicated by the bold black arrow in the middle.
[0084] The implementation of remote authentication using metric root 1021b includes: the security chip 102 receives the metric value generated by the processing chip 101 during startup; upon receiving a security verification request for the trusted execution environment 1011, it generates a metric report based on the metric value and feeds back the metric report based on the security verification request. In one implementation, such as... Figure 9 As shown, during the secure boot process of the root of trust 1021 secure boot processing chip 101, once the firmware or software at a certain level is confirmed to be secure, its measurement value is generated and sent to the security chip 102. Figure 9 (The dashed arrow indicates the direction of measurement value transmission). Security chip 102 can store measurement values generated at each stage of the startup process. During the subsequent operation of computer device 10, a remote user can verify the measurement values stored in trusted root 1021 at any time through cryptographic challenges to confirm the security and trustworthiness of the computer device 10's operating status. This triggers a remote verification process. In this process, measurement root 1021b, acting as the reporting root of computer device 10, can generate a measurement report for remote challenges based on the stored measurement values and provide this measurement report to the remote verification server. Figure 9 The dotted arrow indicates the direction of measurement report transmission. The remote server can verify the measurement report to ensure the security of the Trusted Execution Environment 1011.
[0085] When encrypting the memory space of the Trusted Execution Environment 1011, such as Figure 10 As shown, the computer device 10 also includes a memory chip 104, and the processing chip 101 includes a memory encryption module 1018. At this time, the security chip 102 is also used to generate a key using a trusted root 1021 and provide the key to the memory encryption module 1018 through an encryption channel. The memory encryption module 1018 is used to encrypt memory data using the key and provide the encrypted memory data to the memory chip 104, and / or to obtain encrypted memory data from the memory chip 104 and decrypt the encrypted memory data using the key. After decrypting the memory data, the memory encryption module 1018 can provide the decrypted memory data to the trusted execution environment 1011 so that the trusted execution environment 1011 can perform confidential calculations based on the data. Correspondingly, the memory chip 104 is used to receive and store encrypted memory data, and / or to provide encrypted memory data to the memory encryption module 1018. In this way, it can be ensured that the data remains in an encrypted state after leaving the processing chip 101.
[0086] Where the trusted root 1021 includes the encryption root 1021c, the key is generated from the encryption root 1021c. In one implementation, the memory encryption module can be a memory encryption engine (MEE), which is used to perform hardware encryption and decryption operations on the memory space that needs to be encrypted. For example, as... Figure 10 As shown, the memory chip 104 may include an encrypted memory area and a normal memory area, with the encrypted memory area being the memory space that needs to be encrypted. Furthermore, the Trusted Execution Environment 1011 can typically deploy one or more security applications, each corresponding to an encrypted area within the encrypted memory area. When multiple security applications are deployed in the Trusted Execution Environment 1011, the encryption root 1021c can generate different keys for different security applications. The memory encryption module can use the security application's own key to encrypt or decrypt the data used by that security application, ensuring the security of the data used by each security application. Figure 10 The dashed arrow indicates the direction of key transmission, and the dotted arrow indicates the direction of data transmission.
[0087] As can be seen from the above, in the computer device 10 provided in this application embodiment, the security chip 102 and the processing chip 101 are set separately, realizing the decoupling of the security chip 102 and the processing chip 101. The security of the security chip 102 can be guaranteed and endorsed by the manufacturer of the security chip 102. In this way, the trustworthiness of the root of trust 1021 in the security chip 102 is no longer subject to the trustworthiness of the processing chip 101 manufacturer, breaking away from the current situation where the construction of the trusted execution environment 1011 is limited by the processing chip 101 manufacturer, thereby improving the trustworthiness of confidential computing and eliminating users' distrust of the processing chip 101 manufacturer. Since the security chip 102 and the processing chip 101 are decoupled, the security chip 102 can interface with different types of processing chips 101, improving the compatibility of the entire computer device 10 with multiple chips, which is conducive to promoting the development of large-scale confidential computing application scenarios and promoting the standardization process of the confidential computing security ecosystem.
[0088] Figure 11 This is a schematic diagram of another computer device 10 provided in an embodiment of this application. Figure 11 As shown, the computer device 10 may further include: a memory 105, a communication interface 106, and a bus 107. The processing chip 101, security chip 102, memory 105, and communication interface 106 are interconnected via the bus 107.
[0089] The processing chip 101 may include a general-purpose processing chip 101 and / or a dedicated hardware chip. The general-purpose processing chip 101 may include a central processing unit (CPU), a microprocessor, or a graphics processing unit (GPU). The CPU may be a single-core processor or a multi-core processor. The dedicated hardware chip is a high-performance processing hardware module. The dedicated hardware chip includes at least one of a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a network processor (NP). The processing chip 101 may also be an integrated circuit chip with signal processing capabilities. In implementation, some or all of the functions implemented by the processing chip 101 in this application may be accomplished through integrated logic circuits in the hardware or through software instructions within the processing chip 101.
[0090] Memory 105 is used to store computer programs, including an operating system 105a and executable code (i.e., program instructions) 105b. Memory 105 may be, for example, a read-only memory or other type of static storage device capable of storing static information and instructions; a random access memory or other type of dynamic storage device capable of storing information and instructions; an electrically erasable programmable read-only memory; a read-only optical disc or other optical disc storage; an optical disc storage device (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.); a magnetic disk storage medium; or other magnetic storage device; or any other medium capable of carrying or storing desired executable code in the form of instructions or data structures and accessible by a computer, but not limited thereto. For example, memory 105 may be used to store output port queues, etc. Memory 105 may exist independently and be connected to processing chip 101 via bus 107. Alternatively, memory 105 and processing chip 101 may be integrated together. Memory 105 can store executable code. When the executable code stored in memory 105 is executed by processing chip 101, processing chip 101 performs some or all of the functions implemented in this application. For example, processing chip 101 performs confidential calculations. Memory 105 may also include other software modules and data required by the running process, such as an operating system.
[0091] The communication interface 106 uses a transceiver module, such as, but not limited to, a transceiver, to enable communication with other devices or communication networks. For example, the communication interface 106 can be any one or any combination of the following devices: network interfaces (such as Ethernet interfaces), wireless network cards, and other devices with network access capabilities.
[0092] Bus 107 can be of any type, used for interconnecting internal devices (e.g., memory 105, processing chip 101, communication interface 106) of computer device 10. For example, a system bus. This embodiment illustrates the interconnection of the aforementioned devices within computer device 10 via bus 107. Optionally, the devices within computer device 10 can also communicate with each other using other connection methods besides bus 107. For example, the devices within computer device 10 can be interconnected via internal logic interfaces.
[0093] Optionally, depending on the application requirements, the computer device 10 may also include flash memory 103 and memory chip 104, etc.
[0094] It should be noted that the aforementioned devices can be disposed on separate chips, or at least partially or entirely on the same chip. Whether to dispose of the devices independently on different chips or integrate them on one or more chips often depends on the needs of the product design. This application does not limit the specific implementation of the aforementioned devices. Furthermore, the descriptions of the processes corresponding to the various figures above each have their own emphasis; for parts of a process not described in detail in one figure, please refer to the relevant descriptions of other processes.
[0095] In the above embodiments, the functions implemented by each component of the computer device can be fully or partially implemented through software, hardware, firmware, or any combination thereof. When implemented using software, it can be fully or partially implemented in the form of a computer program product. The computer program product providing the program development platform includes one or more computer instructions. When these computer program instructions are loaded and executed on the computer device 10, they fully or partially implement the functions of the components of the computer device provided in this application embodiment, such as implementing the functions of a processing chip or a security chip.
[0096] Furthermore, computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium stores computer program instructions that provide a program development platform.
[0097] It should be understood that the above-described structure of the computer equipment is an exemplary description of the structure of the computer equipment provided in the embodiments of this application, and does not constitute a limitation on the structure of the computer equipment. As those skilled in the art will know, the structure of the computer equipment can be adjusted according to application requirements as business needs change, and the embodiments of this application do not list them one by one.
[0098] This application also provides a method for operating a computer device. The computer device includes a processing chip and a security chip. In one possible implementation, the computer device can be the computer device provided in the foregoing embodiments. For example, the computer device can be... Figures 1 to 11 Any of the computer devices shown. For example... Figure 12 As shown, the operation method of this computer device includes:
[0099] Step 1201: The security chip runs a root of trust and starts the processing chip and performs trusted control on the processing chip based on the root of trust.
[0100] In one possible implementation, the trusted root includes one or more of the following: a startup root, a metric root, and a cryptographic root.
[0101] Optionally, the implementation process of the security chip booting the processing chip based on the root of trust includes: the security chip using the root of trust to obtain the firmware image used by the boot processing chip; and the security chip using the firmware image to boot the processing chip after the processing chip is powered on.
[0102] Step 1202: The processing chip constructs a trusted execution environment based on the root of trust. The trusted execution environment is used to perform confidential computations.
[0103] After placing the root of trust outside the processing chip, a critical issue is how to maintain the security and trustworthiness of the root of trust itself and the communication between the root of trust and the processing chip. To address this, embodiments of this application propose several security mechanisms while implementing the externalization of the root of trust. In one possible implementation, access control mechanisms and / or communication protection mechanisms can be set in the computer device to ensure the security and trustworthiness of the root of trust, as well as the security and trustworthiness of the communication between the security chip and the processing chip. The access control mechanism and the communication protection mechanism are described below.
[0104] In one implementation of the access control mechanism, the processing chip includes a first access control module. For example... Figure 13 As shown, the operation method of this computer device may further include:
[0105] Step 1203: The first access control module receives an access request to the trusted root. If the access request has the right to access, it forwards the access request to the security chip. If the access request does not have the right to access, it rejects the access request.
[0106] Step 1204: The security chip responds to the access request.
[0107] In another implementation of the access control mechanism, the security chip includes a second access control module. The operation of the computer device may also include:
[0108] Step 1205: The second access control module receives access requests to the trusted root. If the access request has the necessary access rights, it responds to the access request; if the access request does not have the necessary access rights, it rejects the access request.
[0109] In another implementation of the access control mechanism, the processing chip includes a third access control module, and the security chip includes a fourth access control module. The operation of this computer device may also include:
[0110] Step 1206: The third access control module receives the access request to the trusted root, obtains the access permission indication information of the access request, and forwards the access request and its permission indication information to the security chip.
[0111] Step 1207: The fourth access control module responds to the access request when the permission indication information indicates that the access request has the right to access, and denies the access request when the permission indication information indicates that the access request does not have the right to access.
[0112] Access requests originating from the Trusted Execution Environment (TEE) have access permissions, while access requests originating from outside the TEE do not.
[0113] In one possible implementation of the communication protection mechanism, the processing chip includes a first communication protection module, and the security chip includes a second communication protection module, which is matched with the first communication protection module. In this case, the operation method of the computer device further includes: the first and second communication protection modules jointly protecting the communication between the security chip and the processing chip. For example, as... Figure 13 As shown, the operation method of the computer device further includes: step 1208, the first communication protection module performs a first communication protection measure on the communication content between the security chip and the processing chip; step 1209, the second communication protection module performs a second communication protection measure on the communication content between the security chip and the processing chip, the second communication protection measure matching the first communication protection measure. Alternatively, the operation method of the computer device further includes: the second communication protection module performing the first communication protection measure on the communication content between the security chip and the processing chip; the first communication protection module performing the second communication protection measure on the communication content between the security chip and the processing chip, the second communication protection measure matching the first communication protection measure.
[0114] Optionally, both the first and second communication protection modules protect the communication between the security chip and the processing chip based on a key strategy. For example, the first communication protection measure could be encryption, and the second could be decryption.
[0115] Furthermore, both the first and second communication protection modules protect the communication between the security chip and the processing chip based on at least one of a signature strategy and a timestamp strategy. For example, the first communication protection measure could be signing and adding a timestamp, while the second communication protection measure could be verifying both the signature and the timestamp.
[0116] It should be noted that this communication protection mechanism can be used in conjunction with access control mechanisms, and it can be used in conjunction with any implementation method of the access control mechanism. Figure 13 This is a schematic diagram illustrating the first implementation method that combines communication protection mechanisms and access control mechanisms.
[0117] Optionally, the operation of the computer device may also include a remote authentication process. For example... Figure 13 As shown, the operation method of this computer device may further include:
[0118] Step 1210: The security chip receives and processes the measurement values generated by the chip during startup.
[0119] Step 1211: The security chip receives a security verification request for the trusted execution environment.
[0120] Step 1212: The security chip generates a measurement report based on the measurement value and feeds back the measurement report based on the security verification request.
[0121] Optionally, the computer device also includes: a memory chip. The processing chip includes a memory encryption module. The operation of the computer device may also include a memory encryption / decryption process. For example... Figure 13 As shown, the operation method of this computer device may also include the following memory encryption process:
[0122] Step 1213: The security chip uses a trusted root to generate a key and provides the key to the memory encryption module.
[0123] Step 1214: The memory encryption module uses a key to encrypt the memory data and provides the encrypted memory data to the memory chip.
[0124] Step 1215: The memory chip stores encrypted memory data.
[0125] like Figure 13 As shown, the operation method of this computer device may also include the following memory decryption process:
[0126] Step 1213: The security chip uses a trusted root to generate a key and provides the key to the memory encryption module.
[0127] Step 1216: The memory chip provides encrypted memory data to the memory encryption module.
[0128] Step 1217: The memory encryption module uses a key to decrypt the encrypted memory data.
[0129] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the computer device operation method described above can be referred to the corresponding content in the foregoing embodiments, and will not be repeated here.
[0130] In summary, in the computer device operation method provided in this application embodiment, the security chip and the processing chip are set separately, achieving decoupling between the two. The security chip's security can be guaranteed and endorsed by the security chip manufacturer. In this way, the trustworthiness of the root of trust in the security chip is no longer subject to the trustworthiness of the processing chip manufacturer, breaking free from the current situation where the construction of the trusted execution environment is limited by the processing chip manufacturer. This improves the trustworthiness of confidential computing and eliminates user distrust of the processing chip manufacturer. Because the security chip and the processing chip are decoupled, the security chip can interface with different types of processing chips, improving the overall computer device's compatibility with various chips. This is conducive to promoting the development of large-scale confidential computing application scenarios and advancing the standardization process of the confidential computing security ecosystem.
[0131] This application also provides a security chip. This security chip is used to run a root of trust, and to start a processing chip and perform trusted control over the processing chip based on the root of trust.
[0132] In one implementation, the security chip is specifically used to obtain the firmware image used by the boot processing chip using a root of trust, and to boot the processing chip using the firmware image after the processing chip is powered on.
[0133] Optionally, a trusted root may include one or more of the following: a startup root, a metric root, and a cryptographic root.
[0134] Optionally, the security chip is also used to respond to access requests.
[0135] In one implementation, the computer device may include a security chip and a processing chip. The processing chip receives access requests to the trusted root, forwards the access request to the security chip if the request has the necessary permissions, and rejects the access request if it does not. In this case, the security chip receives an access request with the necessary permissions and can then respond to the access request.
[0136] In another implementation, the security chip includes a second access control module. This second access control module receives access requests to the trusted root, responds to the access request if the request has the necessary permissions, and rejects the access request if the request does not have the necessary permissions.
[0137] In another implementation, the processing chip includes a third access control module, and the security chip includes a fourth access control module. The third access control module is used to receive access requests to the trusted root, obtain permission indication information of the access request, and forward the access request and its permission indication information to the security chip; the fourth access control module is used to respond to the access request when the permission indication information indicates that the access request has permission, and to deny the access request when the permission indication information indicates that the access request does not have permission.
[0138] Access requests originating from the Trusted Execution Environment (TEE) have access permissions, while access requests originating from outside the TEE do not.
[0139] Optionally, the security chip can also implement a communication protection mechanism to protect its communication content. In one implementation, the processing chip includes a first communication protection module, and the security chip includes a second communication protection module. The second communication protection module is matched with the first communication protection module, and the first and second communication protection modules are used to jointly protect the communication between the security chip and the processing chip.
[0140] In one implementation, the first communication protection module and the second communication protection module are specifically used to protect the communication between the security chip and the processing chip based on a key policy.
[0141] Furthermore, the first communication protection module and the second communication protection module are specifically used to protect the communication between the security chip and the processing chip based on at least one of the signature strategy and the timestamp strategy.
[0142] Optionally, the security chip is also used to receive and process the metric values generated during the startup process, receive security verification requests for the trusted execution environment, generate a metric report based on the metric values, and provide feedback on the metric report based on the security verification requests.
[0143] Optionally, the computer device also includes a memory chip, and the processing chip includes a memory encryption module. The security chip is further configured to generate a key using a root of trust and provide the key to the memory encryption module; the memory encryption module is configured to encrypt memory data using the key and provide the encrypted memory data to the memory chip, and / or, obtain encrypted memory data from the memory chip and decrypt the encrypted memory data using the key; the memory chip is configured to store the encrypted memory data, and / or, provide the encrypted memory data to the memory encryption module.
[0144] Those skilled in the art will understand that, for the sake of convenience and brevity, the implementation process of the security chip described above can be referred to the corresponding content in the foregoing embodiments, and will not be repeated here.
[0145] In summary, the security chip provided in this application embodiment is separated from the processing chip, achieving decoupling between the two. The security chip's security can be guaranteed and endorsed by its manufacturer. This eliminates the dependence of the root of trust in the security chip on the trustworthiness of the processing chip manufacturer, thus overcoming the limitation of the trusted execution environment's construction to the processing chip manufacturer. This improves the trustworthiness of confidential computing and eliminates user distrust of the processing chip manufacturer. Because the security chip is decoupled from the processing chip, it can interface with different types of processing chips, improving the overall compatibility of the computer device with various chips. This is beneficial for promoting the development of large-scale confidential computing applications and advancing the standardization process of the confidential computing security ecosystem.
[0146] This application also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium. The computer-readable storage medium includes program instructions that, when executed on a computer device, cause the computer device to perform the computer device operation method provided in this application.
[0147] This application also provides a computer program product containing instructions, which, when run on a computer, causes the computer to execute the operating method of the computer device provided in this application.
[0148] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0149] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0150] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "at least one" refers to one or more, and the term "multiple" refers to two or more, unless otherwise expressly defined.
[0151] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0152] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
Claims
1. A computer device, characterized in that, The computer device includes: Security chip used to run the root of trust; The processing chip includes a trusted execution environment and a normal execution environment. The trusted execution environment is built based on the root of trust. The trusted execution environment is used to perform confidential computations on data. The trusted execution environment and the normal execution environment operate in isolation. The confidential computations are performed in the trusted execution environment to protect the data in use. The security chip is also used to start the processing chip based on the trusted root and to perform trusted control on the processing chip; The processing chip includes a first communication protection module, and the security chip includes a second communication protection module. The second communication protection module is matched with the first communication protection module, and the first communication protection module and the second communication protection module are used to jointly protect the communication between the security chip and the processing chip.
2. The computer device according to claim 1, characterized in that, The security chip is specifically used to obtain the firmware image used to start the processing chip using the root of trust, and to boot the processing chip using the firmware image after the processing chip is powered on.
3. The computer device according to claim 1, characterized in that, The trusted root includes one or more of the following: startup root, metric root, and encryption root.
4. The computer device according to claim 1, characterized in that, The processing chip includes a first access control module; The first access control module is used to receive access requests to the trusted root, and when the access request has access rights, forward the access request to the security chip, and when the access request does not have access rights, reject the access request. The security chip is also used to respond to the access request.
5. The computer device according to claim 1, characterized in that, The security chip includes a second access control module; The second access control module is used to receive access requests to the trusted root, respond to the access request when the access request has the right to access it, and reject the access request when the access request does not have the right to access it.
6. The computer device according to claim 1, characterized in that, The processing chip includes a third access control module, and the security chip includes a fourth access control module. The third access control module is used to receive access requests to the trusted root, obtain permission indication information of the access request, and forward the access request and its permission indication information to the security chip. The fourth access control module is used to respond to the access request when the permission indication information indicates that the access request has access rights, and to reject the access request when the permission indication information indicates that the access request does not have access rights.
7. The computer device according to any one of claims 4 to 6, characterized in that, Access requests originating from the trusted execution environment have access rights, while access requests originating from outside the trusted execution environment do not.
8. The computer device according to claim 1, characterized in that, The first communication protection module and the second communication protection module are specifically used to protect the communication between the security chip and the processing chip based on a key policy.
9. The computer device according to claim 8, characterized in that, The first communication protection module and the second communication protection module are further configured to protect the communication between the security chip and the processing chip based on at least one of a signature strategy and a timestamp strategy.
10. The computer device according to any one of claims 1 to 6, characterized in that, The security chip is also used to receive the metric value generated by the processing chip during startup, receive the security verification request for the trusted execution environment, generate a metric report based on the metric value, and feed back the metric report based on the security verification request.
11. The computer device according to any one of claims 1 to 6, characterized in that, The computer device also includes a memory chip, and the processing chip includes a memory encryption module; The security chip is also used to generate a key using the trusted root and provide the key to the memory encryption module. The memory encryption module is used to encrypt memory data using the key and provide encrypted memory data to the memory chip, and / or obtain encrypted memory data from the memory chip and decrypt the encrypted memory data using the key; The memory chip is used to store encrypted memory data and / or to provide encrypted memory data to the memory encryption module.
12. A method for operating a computer device, characterized in that, The method includes: The security chip of the computing device operates a root of trust. The security chip starts the processing chip of the computing device based on the root of trust and performs trusted control over the processing chip; The processing chip constructs a trusted execution environment based on the trusted root. The processing chip includes the trusted execution environment and a normal execution environment, which operate in isolation. The processing chip performs row-secret computations on the data through the trusted execution environment, and the confidential computations protect the data in use by performing computations in the trusted execution environment. The processing chip includes a first communication protection module, the security chip includes a second communication protection module, the second communication protection module is matched with the first communication protection module, and the method further includes: The first communication protection module and the second communication protection module work together to protect the communication between the security chip and the processing chip.
13. The method according to claim 12, characterized in that, The security chip starts the processing chip based on the root of trust, including: The security chip uses the root of trust to obtain the firmware image used to start the processing chip; After the processing chip is powered on, the security chip uses the firmware image to boot the processing chip.
14. The method according to claim 12, characterized in that, The trusted root includes one or more of the following: startup root, metric root, and encryption root.
15. The method according to claim 12, characterized in that, The processing chip includes a first access control module, and the method further includes: The first access control module receives an access request to the trusted root. If the access request has the right to access, it forwards the access request to the security chip. If the access request does not have the right to access, it rejects the access request. The security chip responds to the access request.
16. The method according to claim 12, characterized in that, The security chip includes a second access control module, and the method further includes: The second access control module receives access requests to the trusted root, responds to the access request if the access request has the necessary access rights, and rejects the access request if the access request does not have the necessary access rights.
17. The method according to claim 12, characterized in that, The processing chip includes a third access control module, the security chip includes a fourth access control module, and the method further includes: The third access control module receives an access request to the trusted root, obtains the permission indication information of the access request, and forwards the access request and its permission indication information to the security chip. The fourth access control module responds to the access request when the permission indication information indicates that the access request has access rights, and rejects the access request when the permission indication information indicates that the access request does not have access rights.
18. The method according to any one of claims 15 to 17, characterized in that, Access requests originating from the trusted execution environment have access rights, while access requests originating from outside the trusted execution environment do not.
19. The method according to claim 12, characterized in that, Both the first communication protection module and the second communication protection module are based on a key policy to protect the communication between the security chip and the processing chip.
20. The method according to claim 19, characterized in that, Both the first communication protection module and the second communication protection module protect the communication between the security chip and the processing chip based on at least one of a signature strategy and a timestamp strategy.
21. The method according to any one of claims 12 to 17, characterized in that, The method further includes: The security chip receives the measurement value generated by the processing chip during startup; The security chip receives a security verification request for the trusted execution environment; The security chip generates a measurement report based on the measurement value and feeds back the measurement report based on the security verification request.
22. The method according to any one of claims 12 to 17, characterized in that, The computer device further includes: a memory chip, the processing chip including a memory encryption module, and the method further includes: The security chip uses the trusted root to generate a key and provides the key to the memory encryption module. The memory encryption module uses the key to encrypt memory data and provides the encrypted memory data to the memory chip. The memory chip stores encrypted memory data.
23. The method according to any one of claims 12 to 17, characterized in that, The computer device further includes: a memory chip, the processing chip including a memory encryption module, and the method further includes: The security chip uses the trusted root to generate a key and provides the key to the memory encryption module. The memory chip provides encrypted memory data to the memory encryption module; The memory encryption module uses the key to decrypt the encrypted memory data.
24. A security chip, characterized in that, The security chip is any one of the security chips described in claims 1 to 11.
25. A computer-readable storage medium, characterized in that, Includes program instructions that, when executed on a computer device, cause the computer device to perform the method as described in any one of claims 12 to 23.
26. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 12 to 23.
Citation Information
Patent Citations
Java smart card based mobile trusted module
CN104243168A
Computer system, trusted function component and operation method
CN114692159A