Confidential calculation method and device of application program, electronic equipment and storage medium
By setting up middleware between the application and the computing system and pre-creating REE and TEE containers, the limitations of confidential computing schemes caused by the lack of middleware in the prior art are solved, and the confidential computing power and data security of a wider Java application are achieved.
Patent Information
- Application Number
- CN202510431573.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The lack of effective middleware between the application layer and the hardware layer in the prior art has resulted in confidential computing solutions that can only be used in a few security software and in-depth customization scenarios and cannot be widely applicable to business applications.
It provides a confidential computing method for an application. By setting up middleware between the application and the computing system, pre-creating REE containers and TEE containers, and secretly marking the code during the compilation stage of the application, determining confidential codes and non-confidential codes, and deploying them to REE and TEE environments respectively.
It improves the application scope of confidential computing and makes it suitable for any Java application, enhances the security of Java application data in transmission, processing and storage, reduces TEE resource waste, and reduces operational costs.
Smart Images

Figure CN119939639A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology. Specifically, the present application relates to a confidential computing method, device, electronic device, computer-readable storage medium and computer program product for an application. Background Art
[0002] With the rapid development of cloud computing and big data, data security and privacy protection have become increasingly important issues. Confidential computing technology provides a secure computing environment for programs and data through hardware isolation, which is a new secure computing model.
[0003] In related technologies, applications need to reconstruct their business logic for the Trusted Execution Environment (TEE) and Rich Execution Environment (REE) before they can run in the confidential computing platform. Summary of the invention
[0004] The embodiments of the present application provide a confidential computing method, device, electronic device, computer-readable storage medium, and computer program product for an application program, which can solve the above-mentioned problems of the prior art. The technical solution is as follows: According to one aspect of an embodiment of the present application, a confidential computing method for an application is provided, which is applied to a middleware between an application and a computing system, wherein the middleware pre-creates a REE container and a TEE container, and the TEE container is communicatively connected with the confidential computing hardware of the computing system, and the method includes: receiving the encrypted data to be processed sent by the application through a pre-established encrypted data channel; Calling the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed; If it is determined that the data to be processed is of the first confidentiality level, performing business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, wherein the first Java archive file includes non-confidential code in the application program; If the confidentiality level of the data to be processed is the second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, business processing is performed on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result, and the second Java archive file includes the confidential code in the application.
[0005] According to another aspect of an embodiment of the present application, a confidential computing device for an application is provided, which is applied to a middleware between an application and a computing system, wherein the middleware pre-creates a REE container and a TEE container, and the TEE container is communicatively connected with the confidential computing hardware of the computing system, and the device includes: A data receiving module, used for receiving encrypted data to be processed sent by an application through a pre-established encrypted data channel; A decryption module, used to call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed, so as to obtain the data to be processed; A first processing module is configured to, if it is determined that the data to be processed is of a first confidentiality level, perform business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, wherein the first Java archive file includes non-confidential code in the application program; The second processing module is used to perform business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result if the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level. The second Java archive file includes the confidential code in the application.
[0006] According to another aspect of an embodiment of the present application, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to implement the steps of the confidential computing method of the above-mentioned application.
[0007] According to another aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the confidential computing method of the above-mentioned application are implemented.
[0008] According to one aspect of an embodiment of the present application, a computer program product is provided, including a computer program, which implements the steps of the confidential computing method of the above-mentioned application when the computer program is executed by a processor.
[0009] The beneficial effects of the technical solution provided by the embodiment of the present application are: The present application sets a middleware between the application and the computing system. When the application needs to perform confidential computing, the data to be processed will not be directly transmitted to the confidential computing hardware, thereby avoiding the need to customize the application in advance to adapt to the confidential computing hardware. The middleware of the embodiment of the present application receives the encrypted data to be processed transmitted by the encrypted data channel pre-established with the application, thereby ensuring that the data is complete during the process of being transmitted to the outside of the application. Furthermore, the middleware of the present application pre-creates the REE container and the TEE container, and the present application also needs to mark the application code as confidential during the compilation stage of the application, and determine the confidential code and the non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked, while the non-confidential code is the code that does not need to be specially protected against the risk of leakage. The embodiment of the present application includes the first J in the REE container ava archive file, the first Java archive file includes the non-confidential code in the application, and the second Java archive file is included in the TEE container, the second archive file includes the confidential code in the application, so that the confidential code skills can be securely accessed, but the internal logic is invisible. Furthermore, if the data to be processed is of the first confidentiality level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is of the higher second confidentiality level, it is necessary to use the second Java archive file in the TEE container for processing. The embodiment of the present application firstly improves the application scope of confidential computing and is applicable to any Java application. Secondly, it enhances the security of Java application data during transmission, processing and storage. Thirdly, through the hardware separation and request scheduling of the REE container and the TEE container, the waste of TEE resources is reduced and the operating cost is reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in describing the embodiments of the present application.
[0011] Figure 1 A flowchart of a confidential computing method for an application provided in an embodiment of the present application; Figure 2 A schematic diagram of a process for encrypting and protecting the code of an application program provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of a confidential computing device for an application provided in an embodiment of the present application; Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0012] The embodiments of the present application are described below in conjunction with the drawings in the present application. It should be understood that the implementation methods described below in conjunction with the drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions of the embodiments of the present application.
[0013] It will be understood by those skilled in the art that, unless specifically stated, the singular forms "one", "an" and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application refer to that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation as other features, information, data, steps, operations, elements, components and / or combinations thereof supported by the technical field. It should be understood that when we call an element "connected" or "coupled" to another element, the one element can be directly connected or coupled to the other element, or it can refer to that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used here may include wireless connection or wireless coupling. The term "and / or" used here indicates at least one of the items defined by the term, for example, "A and / or B" can be implemented as "A", or as "B", or as "A and B".
[0014] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0015] First, several terms involved in this application are introduced and explained: Java Virtual Machine (JVM) is a fictional computer that is implemented by simulating various computer functions on an actual computer. After the introduction of the Java language virtual machine, the Java language does not need to be recompiled when running on different platforms. The Java language uses the Java virtual machine to shield information related to specific platforms, so that the Java language compiler only needs to generate code (bytecode) that runs on the Java virtual machine, and can run on multiple platforms without modification.
[0016] Secure Sockets Layer (SSL) is a network security protocol used to establish an encrypted connection between the client and the server to ensure the security and integrity of data transmission. The SSL protocol completes the encryption algorithm, communication key negotiation and server authentication before the application layer protocol communication, thereby ensuring the privacy of communication.
[0017] Due to the different design ideas and implementation methods of the TEE environment of each processor architecture, the SDK interfaces of each company are very different and the development process is complicated, resulting in high difficulty in developing confidential computing applications, poor portability, and ecological isolation. In addition, applications running in the TEE environment need to be specially designed to ensure that they can be executed in an isolated and secure environment, while protecting the data in use from unauthorized access.
[0018] The existing confidential computing hardware technologies mainly include Intel SGX, TrustZone, Loongson SE, Feiteng TEE, Hygon CSV, Kunpeng TEE, etc. The confidential computing implementation solutions provided by each chip manufacturer are different and completely incompatible, making it difficult for business applications to run compatibly on different hardware platforms.
[0019] The embodiments of the present application found that the relevant confidential computing technology lacks an effective middleware between the application layer and the hardware layer to coordinate and manage computing tasks, resulting in the relevant confidential computing solutions being able to be used only in a few security software and deeply customized scenarios, such as key management and privacy computing, and cannot be applied to applications for a wider range of businesses.
[0020] The embodiments of the present application enable general Java applications (i.e., Java applications that have not been reconstructed and developed according to the REE or TEE environment of the confidential computing structure) to run on the middleware provided in the embodiments of the present application. The middleware can automatically separate the data logic that needs to be securely protected in the application, and can run in the confidential computing environment and on different confidential computing platforms, so that general Java applications can use the secure operating environment of confidential computing, providing a more secure solution for a wider range of business applications.
[0021] The confidential computing method, device, electronic device, computer-readable storage medium and computer program product for the application provided in this application are intended to solve the above technical problems in the prior art.
[0022] The middleware provided in the embodiment of the present application is committed to using confidential computing technology to provide a new security solution for Java applications, and Java applications will not be aware of the existence of confidential computing. Developers do not need to learn confidential computing technology, and there is no need to migrate existing applications.
[0023] The embodiment of the present application adapts to confidential computing technology through the transformation of the middleware itself, uses existing Java development specifications to mark the data and code logic that need to be protected, and automatically generates Java code deployed in the TEE environment and REE environment based on the markings. Then, through real-time configuration, it determines which business logic will run in the confidential computing environment, reducing the security investment of Java applications, avoiding the reconstruction of Java applications to integrate confidential computing technology, shielding the technical difficulties of TEE, assisting in the construction of a confidential computing ecosystem, and focusing on improving the security of the Java application itself.
[0024] The following describes several exemplary embodiments to illustrate the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application. It should be noted that the following embodiments can refer to, draw on or combine with each other, and the same terms, similar features and similar implementation steps in different embodiments will not be described repeatedly.
[0025] The embodiment of the present application performs a security upgrade on the application middleware based on confidential computing hardware and confidential computing SDK API technology to meet the ability of Java applications to use the TEE environment and enhance the security protection of user data and code logic.
[0026] The resources that business applications need to protect are divided into two parts: code and data. The embodiment of the present application will design the code and data separately from the development stage and the user request stage.
[0027] 1. Regarding code protection, the functions of the middleware include: 1.1 Confidential Dictionary Used to register whether the fields in the database table are confidential. In Java applications, data is passed through interface parameters. In theory, when the data elements expressed by the interface parameters are mapped to database fields or other storage forms, it is necessary to register and maintain the confidential dictionary. In actual application, it is necessary to register the interface parameters of the external service interface of the business application and the confidential fields in the database.
[0028] 1.2 Confidentiality Level Marking In the development stage, the embodiment of the present application marks whether the interface parameters are confidential and the confidentiality level. This step is a supplement to the confidentiality dictionary which can only mark the confidentiality level of the field. The embodiment of the present application provides two marking methods: 1) Use the @Confidential annotation to mark when coding; 2) For the existing interface parameters of the application, you can configure them through the confidential.xml configuration file during compilation and packaging, indicating the confidentiality level of the code's interface method, implementation class, method input and output parameters.
[0029] 1.3 Confidential compilation In the code compilation stage, the embodiment of the present application dynamically inserts @Confidential annotations into the fields registered in the confidential dictionary and the interface parameters marked in the confidential.xml configuration file, so as to uniformly process the received interface parameters by the subsequent service methods.
[0030] The embodiment of the present application encrypts and compiles the code marked by the confidentiality level marking process, and encrypts it using the derived key of the key management in the TEE environment, ensuring that the encrypted code can only be deployed and run on designated confidential computing hardware resources.
[0031] After the code of the embodiment of the present application is compiled, two data packages with the suffix ".jar" (also called Java archive files, Java archive files, etc.) are output, one is the Java archive file of the TEE environment, and the other is the Java archive file of the REE environment. For ease of use, the embodiment of the present application provides a confidential-compile Maven plugin, which is compiled and packaged through normal Maven commands.
[0032] 1.4 Confidential Application Deployment The purpose of this step is to deploy the Java archive files of the confidentially compiled TEE and REE environments to the actual running TEE and REE environments respectively. The embodiment of the present application deploys the Java archive files to the TEE and REE environments through the SDK API corresponding to the confidential computing architecture.
[0033] Before deploying the Java archive file, the embodiment of the present application needs to check whether the TEE and REE environments of the middleware are normal. If the TEE and REE environments have not been created, the TEE and REE environments need to be initialized first. The embodiment of the present application uses SDKAPI to create the TEE and REE environments, install the TEE JVM and REE JVM, and then install the middleware provided by the embodiment of the present application.
[0034] The middleware provided in the embodiment of the present application will install a streamlined application container in the TEE JVM, install all the functions in the JakartaEE international specification in the REE JVM, and initialize the communication between the REE container and the TEE container through the SDK API. After the initialization of the environment is completed, the application deployment command deploys the TEE application package to the application container of the TEE JVM, and the REE application package to the application container of the REE JVM. It should be noted that there will be no confidential code in the REE environment of the embodiment of the present application, and there will only be confidential code in the TEE environment. The confidential code can provide secure access to the outside, but the internal logic is not visible.
[0035] 2. Code protection process: 2.1 Code Development During the code development phase, developers use the Java programming interface specifications to separate the interface from the implementation. This step is the key to confidentiality protection and the only thing that developers need to pay attention to. Usually, Java code development follows the specifications of separating the interface from the implementation.
[0036] 2.2 Confidentiality Mark The security personnel mark the data to be processed generated by the application as confidential. In the embodiment of the present application, the confidentiality level of the data to be processed is divided into three levels: public (non-confidential level), first confidentiality level, and second confidentiality level: Data to be processed with a confidentiality level of public is not protected and runs in the REE environment; The data to be processed at the first confidentiality level will determine the display or processing method of the code based on user information, environmental information and other conditions, and run in the TEE environment, but all exist in ciphertext form. Only when used can the plaintext be obtained through confidential encapsulation for memory calculation; The data to be processed at the second confidentiality level exists in ciphertext in the REE environment and is only calculated in memory in the TEE environment.
[0037] 2.3 Compile and package The operation and maintenance personnel compile and package the code through the tools provided by the middleware of the embodiment of the present application, generate the first Java archive file of the REE environment and the second Java archive file of the TEE environment, and then encrypt them using the derived key provided by the SDK API of the confidential computing architecture to prevent the Java archive file from being spread and used after it is released from the warehouse. The Java archive file encrypted with the derived key can only run on the host of the corresponding SDK API.
[0038] 2.4 Deployment The operation and maintenance personnel deploy the Java archive file through the interface or command line command provided by the middleware. The embodiment of the present application provides that the middleware performs corresponding deployment operations and environment preparations according to the configuration information in the Java archive file, and finally deploys the first Java archive file of the REE environment into the REE application container, and the second Java archive file of the TEE environment into the TEE application container.
[0039] It should be noted that the first Java archive file deployed into the REE application container will be decrypted by the TEE environment before entering the TEE application container and will run in the TEE application container in plain text. This part of the logic is not visible to the outside world.
[0040] 3. Regarding data protection, the functions of the middleware include: 3.1 Feature Recognition The purpose of feature recognition is to ensure that the input information is consistent with the protected object. The feature recognition of the embodiment of the present application can include biometric recognition, image recognition, document recognition, etc. Key data is entered into the system through feature recognition instead of manual entry to reduce risks. Every time a user logs into the application system, he logs in through one of the above features to ensure that the person logging in is himself.
[0041] 3.2 Secure Channel The secure channel is the security guarantee of data during the communication process. The SSL encrypted channel is used for data transmission to ensure the security of data during transmission. The signature certificate used by SSL is a certificate derived from the confidential computing key management, which ensures that the data must be transmitted back to the corresponding confidential computing host, further protecting the scope of data use.
[0042] 3.3 Confidential Gateway The confidential gateway of the embodiment of the present application includes functions such as data processing, trusted calling, and certificate generation.
[0043] Data processing: The confidentiality gateway makes confidentiality judgments and marks the incoming input parameters (data to be processed) according to the confidentiality dictionary and confidentiality mark code, and performs secondary encryption on the data to be processed at different confidentiality levels. The returned request data is encrypted according to the configuration to ensure the security of data output.
[0044] Trusted call: When calling the code in the second Java archive file of the TEE environment in the REE environment, it is necessary to call it through the confidential gateway. The confidential gateway uniformly adapts to various confidential computing hardware, integrates the SDK API, and performs API operations on the TEE environment.
[0045] Certificate generation: responsible for generating SSL communication certificates.
[0046] 3.4 Confidentiality Mark When a user logs into the application system for the first time, the system generates a confidential token based on the user information collected by feature recognition and the key derived from confidential computing key management. The token is returned to the user client so that it can be brought into the system when requested. The confidential token contains information such as the user, client, server environment and time, and is only valid within a specified time period and within the scope of a specified client and server.
[0047] 3.5 Confidential Packaging The first confidentiality level of the data to be processed is encapsulated, and the data proxy is obtained after encapsulation. The REE environment stores the ciphertext. Only when the in-memory operation is involved will the second Java archive file in the TEE environment be called to obtain the plaintext for calculation. Otherwise, it exists in ciphertext. The data is limited to display and processing in the memory or specific memory, and the data decryption is still performed in the TEE environment.
[0048] 4. Data protection process The data protection process of the embodiment of the present application involves the client, security channel, confidentiality gateway, data processing, data storage and other links.
[0049] The data processing stage has different processing methods for different confidentiality levels: For non-confidential data, the embodiment of the present application processes it in the REE container, and the data is ciphertext only in the secure channel and is plaintext in other places; For data of the first confidentiality level, it is processed in the REE container. During processing, the confidentiality gateway needs to call the TEE container to obtain the decrypted data, that is, the plain text; For data of the second confidentiality level, it is sent to the TEE container for calculation through the confidential gateway, and the returned calculation results are also ciphertext data.
[0050] The overall process description of the embodiment of this application: 1) The client establishes a secure channel with the middleware; The client sends a connection request to the confidential gateway; Confidential Gateway: I. Determine the legitimacy of the client: Check whether the client's IP meets the requirements; II. Generate a derived key and SSL certificate for confidential computing: Generate an SSL certificate using the derived key and return it to the client for encrypted data transmission by the client; Client: Checks the certificate, generates a decryption key based on the SSL certificate and sends it to the server; Server: Receives the decryption key and returns a confirmation message to the client.
[0051] 2) The client initiates a processing request, which includes the address of the page; i. Confidential gateway: forwards the request to the REE container to obtain page information; ii. Confidential gateway: According to the page elements and confidential dictionary, the confidential field elements on the page are encapsulated with confidential controls. If the field elements are at the first confidentiality level, the encryption controls are encapsulated; if the field elements are at the second confidentiality level, the feature recognition controls are encapsulated. The page is returned to the client. Client: i. Display page; ii. The data of the first confidentiality level is input by the user in the page input box, and the data of the second confidentiality level is collected through the feature recognition control; The middleware of the embodiment of the present application performs the following operations: i. Confidential gateway: Checks whether the data of the first confidentiality level is encrypted and whether the confidential data is collected from the feature control. If so, it is sent to the REE container for processing.
[0052] ii. REE environment: For the first confidentiality level of data to be processed, it is sent to the TEE environment for decryption through the confidentiality gateway, and the decrypted data is obtained for business processing in the REE environment. After the processing is completed, it is encrypted again through the TEE environment; For the data to be processed at the second confidentiality level, it is sent to the TEE environment through the confidential gateway for decryption processing, business processing and encryption processing in sequence to obtain the calculation results; it should be noted that for the data at the first confidentiality level, if there is a need for storage, it is necessary to check whether the data is encrypted before storing it.
[0053] iii. Confidential Gateway: Identifies the confidentiality level of the business processing results returned by the REE environment and encapsulates confidentiality or feature identification controls.
[0054] Client: Display data. Business processing results at the first confidentiality level are displayed after authorization and decryption. Business processing results at the second confidentiality level can only be displayed through feature recognition controls. The middleware of the embodiment of the present application can provide an end-to-end confidential computing security solution for the coding, compilation, packaging, deployment, operation, communication of applications, and the request, transmission, processing, and storage of data. The existing confidential computing technology lacks an effective middleware between the application layer and the hardware layer to coordinate and manage computing tasks, resulting in the existing confidential computing solutions being only suitable for a small number of applications and must be used in deeply customized scenarios (such as key management and privacy computing). The embodiment of the present application can be generally applicable to various conventional applications.
[0055] In an embodiment of the present application, a confidential computing method for an application is provided, which is applied to a middleware between an application and a computing system. The middleware pre-creates a rich execution environment (REE) container and a trusted execution environment (TEE) container. The TEE container is connected to the confidential computing hardware of the computing system. Figure 1 As shown, the method includes: S101. Receive encrypted data to be processed sent by an application through a pre-established encrypted data channel.
[0056] An encrypted data channel is pre-established between the middleware and the application in the embodiment of the present application, so that the application sends all data to be processed through the encrypted data channel and encrypts the data when sending to prevent data leakage.
[0057] S102. Call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed.
[0058] After the encrypted data to be processed is received by the middleware, the TEE container first calls the confidential computing hardware to decrypt the encrypted data to be processed and obtain the data to be processed.
[0059] S103a: If it is determined that the data to be processed is at the first confidentiality level, business processing is performed on the data to be processed through the first Java archive file pre-stored in the REE container to obtain a business processing result.
[0060] The embodiment of the present application pre-classifies the data to be processed into two confidentiality levels, where the lower confidentiality level is called the first confidentiality level, and the present application also classifies the application code into confidential code and non-confidential code. The non-confidential code is processed into a first Java archive file and deployed in the REE container. Thus, the data of the first confidentiality level is processed by the first Java archive file in the REE container to obtain a business processing result.
[0061] It is understandable that, since the first Java archive file is located in the REE container, after the TEE container decrypts and obtains the data to be processed, it also needs to send the data to be processed to the REE container.
[0062] S103b. If the confidentiality level of the data to be processed is the second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, business processing is performed on the data to be processed according to the second Java archive file pre-stored in the TEE container to obtain a business processing result.
[0063] If it is determined that the confidentiality registration of the data to be processed is the second confidentiality level, the business processing of the data to be processed continues in the TEE container through the pre-stored second Java archive file to obtain the business processing result. The second Java archive file of the embodiment of the present application includes the confidential code in the application.
[0064] The present application sets a middleware between the application and the computing system. When the application needs to perform confidential computing, the data to be processed will not be directly transmitted to the confidential computing hardware, thereby avoiding the need to customize the application in advance to adapt to the confidential computing hardware. The middleware of the embodiment of the present application receives the encrypted data to be processed transmitted by the encrypted data channel pre-established with the application, thereby ensuring that the data is complete during the process of being transmitted to the outside of the application. Furthermore, the middleware of the present application pre-creates the REE container and the TEE container, and the present application also needs to mark the application code as confidential during the compilation stage of the application, and determine the confidential code and the non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked, while the non-confidential code is the code that does not need to be specially protected against the risk of leakage. The embodiment of the present application includes the first J in the REE container ava archive file, the first Java archive file includes the non-confidential code in the application, and the second Java archive file is included in the TEE container, the second archive file includes the confidential code in the application, so that the confidential code skills can be securely accessed, but the internal logic is invisible. Furthermore, if the data to be processed is of the first confidentiality level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is of the higher second confidentiality level, it is necessary to use the second Java archive file in the TEE container for processing. The embodiment of the present application firstly improves the application scope of confidential computing and is applicable to any Java application. Secondly, it enhances the security of Java application data during transmission, processing and storage. Thirdly, through the hardware separation and request scheduling of the REE container and the TEE container, the waste of TEE resources is reduced and the operating cost is reduced.
[0065] Based on the above embodiments, as an optional embodiment, the present application obtains a business processing result, and then further includes: The business processing result is encrypted by calling confidential computing hardware through the TEE container, and the encrypted business processing result is returned to the application through the encrypted data channel.
[0066] That is to say, no matter whether the processing results of the data to be processed are obtained through the first Java archive file or the second Java archive file, the embodiment of the present application will finally call the confidential computing hardware through the TEE container to encrypt the business processing results, and then return the encrypted business processing results to the application through the encrypted data channel between the middleware and the application.
[0067] Based on the above embodiments, as an optional embodiment, the data to be processed is the data input into the target input box displayed by the application.
[0068] The application of the embodiment of the present application displays at least one target input box on the operation interface. When the operator performs input operation on the target input box, the input data will be used as the data to be processed. In addition, there are two types of target input boxes in the present application, one target input box pre-encapsulates the first control, and the other target input box pre-encapsulates the second control. Furthermore, a non-target input box can also be displayed in the operation interface. The non-confidential level of the data to be processed is input by the operator in the non-target input box, and the non-target input port does not need to encapsulate the above-mentioned first control and second control.
[0069] In some embodiments, input data associated with a field that is not registered in the confidential dictionary belongs to non-confidential data, and correspondingly, input data associated with a field that is registered in the confidential dictionary belongs to confidential data.
[0070] Furthermore, the embodiment of the present application determines the confidentiality level of the data to be processed, including: If it is determined that the data to be processed is collected by the first control pre-packaged in the target input box, then determining that the data to be processed is at the first confidentiality level; If it is determined that the data to be processed is collected by the second control pre-packaged in the target input box, then it is determined that the data to be processed is at the second confidentiality level.
[0071] This application determines the confidentiality level of the data to be processed by determining which type of controls pre-packaged in the target input box collected the data to be processed.
[0072] Based on the above embodiments, as an optional embodiment, the data to be processed is collected by the application in the following manner: A first input box is displayed, and an operator of the application is prompted to input information to be verified required for authorization verification. In response to the input operation of the information to be verified, the first control is called to verify the information to be verified. If the verification passes, the operator is prompted to input data in the first input box; in response to the data input operation, the input data is used as the data to be processed.
[0073] The target input box of the embodiment of the present application includes a first input box, and the first control is encapsulated in the first input box. When displaying the first input box, the application also needs to prompt the operator of the application to perform an authorization check first. Only after the authorization check is passed, the operator has the authority to input the data to be processed. In response to the operator's input operation of the information to be verified, the first control can be called to verify the information to be verified. If the verification passes, the operator is prompted to enter data in the first input box; in response to the data input operation, the input data is used as the data to be processed.
[0074] In some embodiments, the information to be verified may be a password preset by an operator.
[0075] In some embodiments, the data to be processed may be collected by the application program in the following ways: A second input box is displayed, and the operator is prompted to perform feature authentication. In response to the characteristics of the operator being collected, the second control is called to authenticate the characteristics. If the feature authentication passes, the operator is prompted to enter data in the second input box. In response to the data input operation, the input data is used as the data to be processed.
[0076] The target input box of the embodiment of the present application also includes a second input box, which encapsulates a second control. The second control is used for feature authentication. Therefore, when the present application displays the second input box, it further prompts the operator to perform feature authentication. The feature authentication method of the present application can be fingerprint authentication, iris authentication, voiceprint authentication, etc., which are based on biometric authentication. If the feature authentication is passed, the operator is prompted to enter data in the second input box; by further responding to the data input operation, the input data is used as the data to be processed.
[0077] The embodiment of the present application displays two target input boxes and prompts the operator to provide authentication information accordingly. The control encapsulated by the target input box is further authenticated. Only after the authentication is passed can the data to be processed be entered in the target input box.
[0078] Based on the above embodiments, as an optional embodiment, returning the business processing result to the application includes: If the data to be processed is of the first confidentiality level, instructing the operator of the application to input the information to be verified required for authorization verification, and in response to the input operation of the information to be verified, calling the first control to verify the information to be verified, and if the verification passes, displaying the business processing result in the application; If the data to be processed is at the second confidentiality level, the operator is instructed to perform feature authentication. In response to collecting the operator's features, the second control is called to verify the information to be verified. If the feature authentication passes, the business processing result is displayed in the application.
[0079] Based on the above embodiments, as an optional embodiment, the receiving of the encrypted data to be processed sent by the application through the pre-established encrypted data channel also includes: Receiving an access request sent by the application, wherein the access request includes an IP address; If it is determined that the IP address is correct, a derived key is generated; Generate a signature certificate for the encrypted data channel according to the derived key, and send the application so that the application encrypts and transmits the data to be processed according to the signature certificate; Receive a decryption key generated by the application according to the signing certificate.
[0080] The embodiment of the present application also provides a solution for building an encrypted channel. Specifically, the application first needs to send an access request to the middleware, and the access request includes an IP address. If the middleware determines that the IP address is correct, it will generate a derived key and generate a signature certificate for the encrypted data channel based on the derived key. The middleware returns the signature certificate to the application, and the application can subsequently encrypt and transmit the data to be processed based on the signature certificate. After receiving the signature certificate, the application will also generate a decryption key, and the middleware receives the decryption key sent by the application.
[0081] In some embodiments, the TEE environment encrypts the confidential code using a derived key so that the encrypted code can only run on the TEE environment.
[0082] Based on the above embodiments, as an optional embodiment, the embodiment of the present application also includes: Constructing a confidential dictionary during the development phase of the application and marking the code as confidential, wherein the confidential dictionary includes interface parameters of the service interface of the application at the second encryption level and the fields at the second encryption level in the database table; During the compilation phase of the application, the marked confidential code is encrypted and compiled using the derived key of the key management in the TEE environment to obtain a second Java archive file, and the non-confidential code is non-encrypted and compiled to obtain a first Java archive file; The first Java archive file is stored in a REE application container, and the second Java archive file is stored in a TEE application container.
[0083] See also Figure 2 , which exemplarily shows a schematic diagram of the process of encrypting and protecting the code of an application program in an embodiment of the present application. The code encryption protection process of this solution is a systematic and sophisticated process, which aims to ensure the security of the code during the development, deployment and operation stages. The entire process is divided into three stages, each of which plays a vital role. The following is a detailed description of these three stages: Phase 1: Development phase confidentiality mark During the development phase, developers need to identify and mark those parts of the code that contain sensitive information or critical logic. These are the code segments that need special protection. This process usually involves the following steps: Code review: Developers first need to conduct a comprehensive review of the entire code base to identify which parts contain trade secrets, algorithm logic, key management, or other sensitive information; Confidential marking: Once these sensitive code segments are identified, developers will use specific tags or comments to mark them for subsequent processing. These tags can be simple comments or specific code tags for automatic identification during the compilation stage; Documentation: To ensure that all team members understand which code is protected, developers also need to write corresponding documentation to record which code segments have been marked as confidential.
[0084] Phase 2: Compile, package, encrypt and deploy After completing the confidentiality mark, the code enters the compilation and packaging stage. The main task of this stage is to convert the code into an executable format, encrypt it with a derived key, and finally deploy it to the trusted execution environment (TEE). The specific steps are as follows: Compilation and packaging: Use appropriate compilers and packaging tools to convert source code into executable or library files. During this process, the compilation tool will identify code segments that were previously marked as confidential.
[0085] Derived key generation: Based on the master key or other security mechanisms, derived keys are generated for encrypting specific code segments. The generation and management of these keys should follow strict security standards.
[0086] Code encryption: Use the generated derived key to encrypt the code segments marked as confidential. The encrypted code segments cannot be directly read or tampered with even if they are extracted without authorization; Deploy to TEE environment: The encrypted code package is deployed to the TEE environment. TEE is a hardware-level security environment that ensures that the code cannot be accessed or tampered with externally during runtime.
[0087] Phase 3: TEE environment decryption and operation In a TEE environment, the encrypted code segments need to be decrypted and executed at runtime. This process ensures that the sensitive parts of the code are still protected when it runs in an untrusted environment. The specific steps are as follows: Decryption key management: Decryption keys are securely stored and managed within the TEE environment. Decryption keys are only visible and used within the TEE, ensuring that external attackers cannot obtain them.
[0088] Code decryption: When an encrypted code segment needs to be executed, TEE uses the internally stored decryption key to decrypt the code. The decryption process is completed inside TEE, ensuring that the code cannot be accessed externally within a short period of time after decryption.
[0089] Code execution: The decrypted code segment is securely executed in the TEE environment. Since TEE provides hardware-level isolation and protection, the encrypted code segment can remain secure even if the operating system or other software layers are attacked.
[0090] Monitoring and logging: To ensure the security and traceability of code operation, the TEE environment should also have monitoring and logging functions. These functions can record the execution of code, abnormal events, etc. for subsequent analysis and auditing.
[0091] In summary, the code encryption protection process of this solution ensures the security of the entire life cycle of the code from development to deployment to operation through three closely connected stages.
[0092] The embodiment of the present application provides a confidential computing device for an application, which is applied to a middleware between an application and a computing system. The middleware pre-creates a REE container and a TEE container. The TEE container is communicatively connected with the confidential computing hardware of the computing system. The device includes: Figure 3 As shown, the confidential computing device of the application may include: a data receiving module 301, a decryption module 302, a first processing module 303 and a second processing module 304, wherein: The data receiving module 301 is used to receive the encrypted data to be processed sent by the application through the pre-established encrypted data channel; A decryption module 302 is used to call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed; A first processing module 303 is configured to, if it is determined that the data to be processed is of a first confidentiality level, perform business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, wherein the first Java archive file includes non-confidential code in the application program; The second processing module 304 is used to perform business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result if the confidentiality level of the data to be processed is a second confidentiality level, which is higher than the first confidentiality level. The second Java archive file includes the confidential code in the application.
[0093] The device of the embodiments of the present application can execute the method provided by the embodiments of the present application, and the implementation principles are similar. The actions performed by each module in the device of each embodiment of the present application correspond to the steps in the method of each embodiment of the present application. For the detailed functional description of each module of the device, please refer to the description in the corresponding method shown in the previous text, which will not be repeated here.
[0094] An electronic device is provided in an embodiment of the present application, including a memory, a processor and a computer program stored in the memory, and the processor executes the above-mentioned computer program to implement the steps of the confidential computing method of the application. Compared with the related art, the following can be achieved: the present application sets a middleware between the application and the computing system. When the application needs to perform confidential computing, the data to be processed will not be directly transmitted to the confidential computing hardware, thereby avoiding the need to customize the application in advance to adapt to the confidential computing hardware. The middleware of the embodiment of the present application receives the encrypted data to be processed transmitted through an encrypted data channel pre-established with the application, thereby ensuring that the data is complete during the process of being transmitted to the outside of the application. Furthermore, the middleware of the present application pre-creates REE containers and TEE containers, and the present application also needs to mark the code of the application as confidential during the compilation stage of the application, and determine the confidential code and non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked. Non-confidential code is code that does not require special precautions against the risk of leakage. The embodiment of the present application includes a first Java archive file in the REE container, and the first Java archive file includes the non-confidential code in the application. The TEE container includes a second Java archive file, and the second archive file includes the confidential code in the application, so that the confidential code can be securely accessed, but the internal logic is not visible. Furthermore, if the data to be processed is at a first confidentiality level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is at a higher second confidentiality level, it is necessary to use the second Java archive file in the TEE container for processing. The embodiment of the present application firstly improves the application scope of confidential computing and is applicable to any Java application. Secondly, it enhances the security of Java application data during transmission, processing and storage. Finally, through the hardware separation and request scheduling of the REE container and the TEE container, the waste of TEE resources is reduced and the operating cost is reduced.
[0095] In an alternative embodiment, an electronic device is provided, such as Figure 4 As shown, Figure 4 The electronic device 4000 shown includes: a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, such as through a bus 4002. Optionally, the electronic device 4000 may also include a transceiver 4004, which may be used for data interaction between the electronic device and other electronic devices, such as data transmission and / or data reception. It should be noted that in actual applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of the present application.
[0096] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It may implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of this application. Processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0097] The bus 4002 may include a path for transmitting information between the above components. The bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 4002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus 4002 is represented by only one thick line in the figure, but it does not mean that there is only one bus or one type of bus.
[0098] The memory 4003 may be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compressed optical disk, laser disk, optical disk, digital versatile disk, Blu-ray disk, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, without limitation herein.
[0099] The memory 4003 is used to store the computer program for executing the embodiment of the present application, and the execution is controlled by the processor 4001. The processor 4001 is used to execute the computer program stored in the memory 4003 to implement the steps shown in the above method embodiment.
[0100] An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps and corresponding contents of the aforementioned method embodiment can be implemented.
[0101] The embodiment of the present application also provides a computer program product, including a computer program, which can implement the steps and corresponding contents of the aforementioned method embodiment when executed by a processor.
[0102] The terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than that shown or described in the drawings.
[0103] It should be understood that, although each operation step is indicated by arrows in the flowchart of the embodiment of the present application, the implementation order of these steps is not limited to the order indicated by the arrows. Unless clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be performed in other orders according to demand. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on actual implementation scenarios. Some or all of these sub-steps or stages may be executed at the same time, and each sub-step or stage in these sub-steps or stages may also be executed at different times respectively. In different scenarios of execution time, the execution order of these sub-steps or stages may be flexibly configured according to demand, and the embodiment of the present application does not limit this.
[0104] The above is only an optional implementation method for some implementation scenarios of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of the present application, other similar implementation methods based on the technical ideas of the present application are also within the protection scope of the embodiments of the present application.
Claims
1. A confidential computing method for an application, characterized in that: A middleware is applied between an application and a computing system, wherein the middleware pre-creates a rich execution environment (REE) container and a trusted execution environment (TEE) container, wherein the TEE container is communicatively connected with confidential computing hardware of the computing system, and the method comprises: receiving the encrypted data to be processed sent by the application through a pre-established encrypted data channel; Calling the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed; If it is determined that the data to be processed is of the first confidentiality level, performing business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, wherein the first Java archive file includes non-confidential code in the application program; If the confidentiality level of the data to be processed is the second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, business processing is performed on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result, and the second Java archive file includes the confidential code in the application.
2. The method according to claim 1, characterized in that The obtaining of the business processing result further includes: The business processing result is encrypted by calling confidential computing hardware through the TEE container, and the encrypted business processing result is returned to the application through the encrypted data channel.
3. The method according to claim 2, characterized in that The data to be processed is the data input into the target input box displayed by the application; Determining the confidentiality level of the data to be processed includes: If it is determined that the data to be processed is collected by the first control pre-packaged in the target input box, then determining that the data to be processed is at the first confidentiality level; If it is determined that the data to be processed is collected by the second control pre-packaged in the target input box, then the data to be processed is determined to be at the second confidentiality level; The application includes at least one target input box, and each target input box pre-encapsulates the first control or the second control.
4. The method according to claim 3, characterized in that The data to be processed is collected by the application in the following ways: Displaying a first input box, and prompting an operator of the application to input information to be verified required for authorization verification, in response to the input operation of the information to be verified, calling the first control to verify the information to be verified, and if the verification passes, prompting the operator to input data in the first input box; in response to the data input operation, using the input data as the data to be processed; or A second input box is displayed, and the operator is prompted to perform feature authentication. In response to the characteristics of the operator being collected, the second control is called to authenticate the characteristics. If the feature authentication passes, the operator is prompted to enter data in the second input box. In response to the data input operation, the input data is used as the data to be processed.
5. The method according to claim 3 or 4, characterized in that: The returning the business processing result to the application program includes: If the data to be processed is of the first confidentiality level, instructing the operator of the application to input the information to be verified required for authorization verification, and in response to the input operation of the information to be verified, calling the first control to verify the information to be verified, and if the verification passes, displaying the business processing result in the application; If the data to be processed is at the second confidentiality level, the operator is instructed to perform feature authentication. In response to collecting the operator's features, the second control is called to verify the information to be verified. If the feature authentication passes, the business processing result is displayed in the application.
6. The method according to claim 1, characterized in that The receiving application sends encrypted data to be processed through a pre-established encrypted data channel, and also includes: Receiving an access request sent by the application, wherein the access request includes an IP address; If it is determined that the IP address is correct, a derived key is generated; Generate a signature certificate for the encrypted data channel according to the derived key, and send the application so that the application encrypts and transmits the data to be processed according to the signature certificate; Receive a decryption key generated by the application according to the signing certificate.
7. The method according to claim 1, characterized in that Also includes: Constructing a confidential dictionary during the development phase of the application and marking the code as confidential, wherein the confidential dictionary includes interface parameters of the service interface of the application at the second encryption level and the fields at the second encryption level in the database table; During the compilation phase of the application, the marked confidential code is encrypted and compiled using the derived key of the key management in the TEE environment to obtain a second Java archive file, and the non-confidential code is non-encrypted and compiled to obtain a first Java archive file; The first Java archive file is stored in a REE application container, and the second Java archive file is stored in a TEE application container.
8. A confidential computing device for an application, characterized in that: A middleware applied between an application and a computing system, wherein the middleware pre-creates a REE container and a TEE container, wherein the TEE container is communicatively connected with confidential computing hardware of the computing system, and the device comprises: A data receiving module, used for receiving encrypted data to be processed sent by an application through a pre-established encrypted data channel; A decryption module, used to call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed, so as to obtain the data to be processed; A first processing module is configured to, if it is determined that the data to be processed is of a first confidentiality level, perform business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, wherein the first Java archive file includes non-confidential code in the application program; The second processing module is used to perform business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result if the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level. The second Java archive file includes the confidential code in the application.
9. An electronic device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the confidential computing method of the application program described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the confidential computing method of the application program described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Data encryption method and device and electronic device
CN108959941A
Data processing method, proxy device and related equipment
CN117708822A
Intelligent contract virtual machine system and intelligent contract execution method
CN118797721A
Federal learning model privacy protection method based on TEE
CN118862147A
Application designed to create environmental information
CN119547070A