Confidential Computing Method, Device, Electronic Device and Storage Medium for Application Programs
A middleware solution for Java applications separates machine-critical and non-critical code, enabling secure data processing across various secure computing environments, addressing compatibility and complexity issues in machine-critical computing.
Patent Information
- Application Number
- CN202510431573.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The lack of effective middleware coordination and management between the application layer and the hardware layer of existing confidential computing technologies has resulted in confidential computing solutions that can only be used in a few scenarios where security software is deeply customized, making it difficult to apply to a wide range of business applications.
It provides a middleware that pre-creates REE containers and TEE containers, transmits the pending data through encrypted data channels, and secretly marks the application code during the compilation stage, separates confidential codes and non-confidential codes, uses REE and TEE containers for business processing, and adapts to confidential computing hardware.
It improves the application scope of confidential computing, enhances the security of Java application data in transmission, processing and storage, reduces TEE resource waste, and reduces operational costs, and is suitable for any Java application.
Smart Images

Figure CN119939639B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology. Specifically, this application relates to a confidential computing method, apparatus, electronic device, computer-readable storage medium, and computer program product for an application program. Background Art
[0002] With the rapid development of cloud computing and big data, data security and privacy protection have become increasingly important issues. Confidential computing technology provides a secure computing environment for programs and data through hardware isolation, which is a new secure computing mode.
[0003] In the related art, applications need to reconstruct the business logic for both the Trusted Execution Environment (TEE) and the Rich Execution Environment (REE) before they can run on a confidential computing platform. Summary of the Invention
[0004] Embodiments of this application provide a confidential computing method, apparatus, electronic device, computer-readable storage medium, and computer program product for an application program, which can solve the above problems of the prior art. The technical solutions are as follows:
[0005] According to one aspect of the embodiments of this application, a confidential computing method for an application program is provided, which is applied to a middleware between the application program and the computing system. The middleware pre-creates an REE container and a TEE container, and the TEE container is communicatively connected to the confidential computing hardware of the computing system. The method includes:
[0006] Receiving encrypted data to be processed sent by the application program through a pre-established encrypted data channel;
[0007] Invoking the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed;
[0008] If it is determined that the data to be processed is of a first confidentiality level, then performing business processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a business processing result, where the first Java archive file includes non-confidential code in the application program;
[0009] If the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, then performing business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container to obtain a business processing result, where the second Java archive file includes confidential code in the application program.
[0010] According to another aspect of the embodiments of the present application, a confidential computing device for an application is provided, which is applied to the middleware between the application and the computing system. The middleware pre-creates a REE container and a TEE container, and the TEE container is communicatively connected to the confidential computing hardware of the computing system. The device includes:
[0011] A data receiving module, configured to receive encrypted data to be processed sent by the application through a pre-established encrypted data channel;
[0012] A decryption module, configured to call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed, so as to obtain the data to be processed;
[0013] A first processing module, configured to, if it is determined that the data to be processed is of a first confidentiality level, perform business processing on the data to be processed through a first Java archive file pre-stored in the REE container, so as to obtain a business processing result, where the first Java archive file includes non-confidential code in the application;
[0014] A second processing module, configured to, if the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, perform business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container, so as to obtain a business processing result, where the second Java archive file includes confidential code in the application.
[0015] According to another aspect of the embodiments of the present application, an electronic device is provided. The electronic device includes a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the steps of the above-mentioned confidential computing method for an application.
[0016] According to still another aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned confidential computing method for an application are implemented.
[0017] According to one aspect of the embodiments of the present application, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps of the above-mentioned confidential computing method for an application are implemented.
[0018] The beneficial effects brought by the technical solutions provided by the embodiments of the present application are:
[0019] This application sets up middleware between the application and the computing system. When the application needs to perform confidential computing, the data to be processed is not directly transmitted to the confidential computing hardware, thus avoiding the need to customize the application in advance to adapt to the confidential computing hardware. The middleware in the embodiments of this application receives the encrypted data to be processed transmitted through the encrypted data channel pre-established with the application, thereby ensuring the integrity of the data during the process of being transmitted outside the application. Further, the middleware of this application pre-creates a REE container and a TEE container, and this application also needs to perform confidential marking on the code of the application during the compilation stage of the application to determine the confidential code and non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked, while the non-confidential code is the code that does not require special prevention of leakage risks. In the embodiments of this application, the REE container includes a first Java archive file, and the first Java archive file includes the non-confidential code in the application. The TEE container includes a second Java archive file, and the second archive file includes the confidential code in the application, so that the confidential code can be securely accessed, but the internal logic is invisible. Further, if the data to be processed is at the first confidential level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is at the higher second confidential level, the second Java archive file in the TEE container needs to be used for processing. The embodiments of this application firstly expand the application scope of confidential computing, which is applicable to any Java application. Secondly, it enhances the security of Java application data during transmission, processing, and storage. Thirdly, through the separation and request scheduling of the hardware of the REE container and the TEE container, it reduces the waste of TEE resources and lowers the operating cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for description in the embodiments of this application.
[0021] Figure 1 It is a schematic flowchart of a confidential computing method for an application provided by an embodiment of this application;
[0022] Figure 2 It is a schematic flowchart of encrypting and protecting the code of an application provided by an embodiment of this application;
[0023] Figure 3 It is a schematic structural diagram of a confidential computing device for an application provided by an embodiment of this application;
[0024] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] Embodiments of the present application will be described below with reference to the accompanying drawings in the present application. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions of the embodiments of the present application.
[0026] Those skilled in the art of the present technology can understand that, unless specifically stated, the singular forms "a", "an" and "the" used herein may also include the plural forms. It should be further understood that the terms "comprising" and "including" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation of other features, information, data, steps, operations, elements, components and / or their combinations supported by the art of the present technology. It should be understood that when we say an element is "connected" or "coupled" to another element, the one element can be directly connected or coupled to the other element, or it can mean that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein can include wireless connection or wireless coupling. The term "and / or" used herein indicates at least one of the items defined by the term, for example, "A and / or B" can be implemented as "A", or implemented as "B", or implemented as "A and B".
[0027] To make the objectives, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0028] First, several terms related to the present application will be introduced and explained:
[0029] Java Virtual Machine (JVM), the JVM is a fictional computer that is implemented by emulating various computer functions on an actual computer. After introducing the Java language virtual machine, the Java language does not need to be recompiled when running on different platforms. The Java language uses the Java virtual machine to shield the information related to the specific platform, so that the Java language compiler only needs to generate the code (bytecode) that runs on the Java virtual machine, and can run on multiple platforms without modification.
[0030] Secure Sockets Layer (SSL), is a network security protocol used to establish an encrypted connection between a client and a server to ensure the security and integrity of data transmission. The SSL protocol completes the negotiation of encryption algorithms, communication keys and server authentication before the application layer protocol communication, thus ensuring the privacy of communication.
[0031] Due to the different design concepts and implementation methods of the TEE environment for each processor architecture, the SDK interfaces of each company are very different and the development process is complex, resulting in high development difficulty, poor portability, and ecological isolation for developing confidential computing applications. In addition, the application programs running in the TEE environment need to be specially designed to ensure that they can execute in an isolated and secure environment while protecting the data in use from unauthorized access.
[0032] The existing hardware technologies for confidential computing mainly include Intel SGX, TrustZone, Loongson SE, Feiteng TEE, Haiguang CSV, Kunpeng TEE, etc. The confidential computing implementation solutions provided by each chip manufacturer are different and completely incompatible, making it very difficult for business applications to run compatibly on different hardware platforms.
[0033] The embodiments of this application find that there is a lack of an effective middleware between the application layer and the hardware layer to coordinate and manage computing tasks in the related confidential computing technology, resulting in the related confidential computing solutions can only be used in a few security software and deeply customized scenarios, such as key management and privacy computing, and cannot be applied to application programs with a wider range of businesses.
[0034] When a general Java application program (that is, a Java application program not reconstructed and developed according to the REE and TEE environments of the confidential computing structure) runs on the middleware provided by the embodiments of this application, the middleware can automatically split out the data logic that needs to be protected securely in the application program, and can run in the confidential computing environment, and can run on different confidential computing platforms, enabling general Java application programs to use the secure operating environment of confidential computing and providing a more secure solution for a wider range of business applications.
[0035] The confidential computing method, device, electronic device, computer-readable storage medium, and computer program product provided by this application are intended to solve the above technical problems in the prior art.
[0036] The middleware provided by the embodiments of this application is committed to using confidential computing technology to provide a new security solution for Java application programs, and the Java application programs will not perceive the existence of confidential computing. Developers do not need to learn confidential computing technology and are not involved in the work of migrating existing applications.
[0037] In the embodiments of the present application, the middleware itself is transformed to adapt to confidential computing technology. By using the existing Java development specifications, the data and code logic that need to be protected are marked, and the Java code deployed in the TEE environment and the REE environment is automatically generated according to the marks. Then, through real-time configuration, it is determined which business logics will run in the confidential computing environment, reducing the investment in security of Java applications, avoiding the refactoring of Java applications to integrate into confidential computing technology, shielding the technical difficulties of TEE technology, facilitating the construction of the confidential computing ecosystem, and particularly enhancing the security of Java applications themselves.
[0038] The technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application will be described below through the description of several exemplary embodiments. It should be noted that the following embodiments can be referred to, learned from, or combined with each other. For the same terms, similar features, and similar implementation steps in different embodiments, they will not be described repeatedly.
[0039] Based on confidential computing hardware and confidential computing SDK API technology, the embodiments of the present application perform security upgrades on the application middleware to meet the ability of Java applications to use the TEE environment and enhance the security protection of user data and code logic.
[0040] The resources that business applications need to protect are divided into two parts: code and data. The embodiments of the present application will design the code and data separately in the development stage and the user request stage.
[0041] 1. For the protection of code, the functions involved in the middleware include:
[0042] 1.1 Confidential dictionary
[0043] It is used to register whether the fields in the database table are confidential. In Java applications, data is passed through interface parameters. In theory, when the data elements expressed by the interface parameters are mapped to database fields or other storage forms, confidential dictionary registration and maintenance are required. In actual applications, it is necessary to register the interface parameters of the service interfaces external to the business application and the confidential fields in the database.
[0044] 1.2 Confidential level marking
[0045] In the development stage of the embodiments of the present application, it is marked whether the interface parameters are confidential and the confidential level. This step is a supplement to the fact that the confidential dictionary can only mark the confidential level of fields. The embodiments of the present application provide two marking methods:
[0046] 1) Marking is performed during coding through the @Confidential annotation;
[0047] 2) For the existing interface parameters of the application, they can be configured through the confidential.xml configuration file during compilation and packaging to specify the confidentiality levels of the interface methods, implementation classes, method input parameters, and output parameters of the code.
[0048] 1.3 Confidential Compilation
[0049] In the code compilation stage of the embodiments of the present application, the fields registered in the confidential dictionary and the interface parameters marked in the confidential.xml configuration file are dynamically inserted with the @Confidential annotation for unified processing of the interface parameters received by the later service methods.
[0050] The embodiments of the present application perform encrypted compilation on the code marked during the confidentiality level marking process, using the derived key of the key management in the TEE environment for encryption to ensure that the encrypted code can only be deployed and run on the specified confidential computing hardware resources.
[0051] After the code compilation of the embodiments of the present application, two data packets with the suffix ".jar" (also known as Java archive files, Java archive files, etc.) are output. One is the Java archive file in the TEE environment, and the other is the Java archive file in the REE environment. For convenience of use, the embodiments of the present application provide the maven plugin of confidential-compile, and perform compilation and packaging through normal maven commands.
[0052] 1.4 Confidential Application Deployment
[0053] The purpose of this step is to deploy the Java archive files in the TEE and REE environments compiled confidentially to the actual running TEE and REE environments respectively. The embodiments of the present application deploy the Java archive files to the TEE and REE environments through the SDK API corresponding to the confidential computing architecture.
[0054] Before deploying the Java archive files, the embodiments of the present application need to first check whether the TEE and REE environments of the middleware are normal. If the TEE and REE environments have not been created, the TEE and REE environments need to be initialized first. The embodiments of the present application use the SDK API to create the TEE and REE environments, install the TEE JVM and REE JVM, and then install the middleware provided by the embodiments of the present application.
[0055] The middleware provided by the embodiments of this application will install a lightweight application container in the TEE JVM, install all the functions in the Jakarta EE international specification in the REE JVM, and initialize the communication between the REE container and the TEE container through the SDK API. After the environment initialization is completed, the application deployment command deploys the TEE application package to the application container of the TEE JVM, and the REE application package to the application container of the REE JVM. It should be noted that there will be no confidential code in the REE environment of the embodiments of this application, and only confidential code in the TEE environment. The confidential code can provide secure access externally, but the internal logic is invisible.
[0056] 2. Code protection process:
[0057] 2.1 Code development
[0058] In the code development stage, developers use the interface specifications of Java programming to separate the interfaces and implementations. This step is the key to confidential protection and the only thing developers need to pay attention to. Usually, the development of Java code follows the specification of separating interfaces and implementations.
[0059] 2.2 Confidential marking
[0060] Security personnel perform confidential marking on the data to be processed generated by the application program. For the data to be processed in the embodiments of this application, the confidentiality levels are divided into three types: public (non-confidential level), first confidentiality level, and second confidentiality level:
[0061] The data to be processed with the confidentiality level of public is not protected and runs in the REE environment;
[0062] For the data to be processed with the first confidentiality level, it will judge the display or processing method of the code according to conditions such as user information and environmental information, and run in the TEE environment, but all exist in ciphertext form. Only when used, the plaintext is obtained through sealed packaging for in-memory calculation;
[0063] The data to be processed with the second confidentiality level exists in ciphertext in the REE environment and only performs in-memory calculation in the TEE environment.
[0064] 2.3 Compilation and packaging
[0065] The operation and maintenance personnel perform code compilation and packaging through the tools provided by the middleware of the embodiments of this application to generate the first Java archive file for the REE environment and the second Java archive file for the TEE environment. Then, the derived key provided by the SDK API of the confidential computing architecture is used for encryption to prevent the Java archive files from being spread and used after leaving the warehouse. The Java archive files encrypted with the derived key can only run on the host of the corresponding SDK API.
[0066] 2.4 Deployment
[0067] The operation and maintenance personnel deploy the Java archive file through the interface provided by the middleware or command-line commands. The embodiments of the present application provide that the middleware performs corresponding deployment operations and environment preparation according to the configuration information in the Java archive file, and finally deploys the first Java archive file of the REE environment into the REE application container, and deploys the second Java archive file of the TEE environment into the TEE application container.
[0068] It should be noted that the first Java archive file deployed into the REE application container will be decrypted by the TEE environment before entering the TEE application container and will run in the TEE application container in plain text. This part of the logic is invisible to the outside.
[0069] 3. For the protection of data, the functions involved in the middleware include:
[0070] 3.1 Feature Recognition
[0071] The purpose of feature recognition is to ensure that the input information is consistent with the protected object. The feature recognition in the embodiments of the present application may include biometric recognition, picture recognition, document recognition, etc. The key data is entered into the system through feature recognition instead of manual entry, reducing risks. Each time a user logs in to the application system, they log in through one of the above features to ensure that the person logging in is themselves.
[0072] 3.2 Secure Channel
[0073] The secure channel is the security guarantee for data during communication. An encrypted channel using SSL is used for data transmission to ensure the security of data during transmission. The signature certificate used by SSL is a certificate derived from the confidential computing key management, ensuring that the data must be transmitted back to the corresponding confidential computing host to further ensure the scope of data use.
[0074] 3.3 Confidential Gateway
[0075] The confidential gateway in the embodiments of the present application includes functions such as data processing, trusted invocation, and certificate generation.
[0076] Data Processing: The confidential gateway makes a confidentiality judgment and marks the incoming input parameters (data to be processed) according to the confidential dictionary and the code of the confidential mark, and performs secondary encryption on the data to be processed at different confidentiality levels. It makes an encryption judgment on the returned request data according to the configuration to ensure the security of data output.
[0077] Trusted call: When calling the code in the second Java archive file of the TEE environment in the REE environment, it is necessary to call it through the confidential gateway. The confidential gateway uniformly adapts to various confidential computing hardware, integrates the SDK API, and performs API operations on the TEE environment.
[0078] Certificate generation: responsible for generating SSL communication certificates.
[0079] 3.4 Confidentiality Mark
[0080] When a user logs into the application system for the first time, the system generates a confidential token based on the user information collected by feature recognition and the key derived from confidential computing key management. The token is returned to the user client so that it can be brought into the system when requested. The confidential token contains information such as the user, client, server environment and time, and is only valid within a specified time period and within the scope of a specified client and server.
[0081] 3.5 Confidential Packaging
[0082] The first confidentiality level of the data to be processed is encapsulated, and the data proxy is obtained after encapsulation. The REE environment stores the ciphertext. Only when the in-memory operation is involved will the second Java archive file in the TEE environment be called to obtain the plaintext for calculation. Otherwise, it exists in ciphertext. The data is limited to display and processing in the memory or specific memory, and the data decryption is still performed in the TEE environment.
[0083] 4. Data protection process
[0084] The data protection process of the embodiment of the present application involves the client, security channel, confidentiality gateway, data processing, data storage and other links.
[0085] The data processing stage has different processing methods for different confidentiality levels:
[0086] For non-confidential data, the embodiment of the present application processes it in the REE container, and the data is ciphertext only in the secure channel and is plaintext in other places;
[0087] For data of the first confidentiality level, it is processed in the REE container. During processing, the confidentiality gateway needs to call the TEE container to obtain the decrypted data, that is, the plain text;
[0088] For data of the second confidentiality level, it is sent to the TEE container for calculation through the confidential gateway, and the returned calculation results are also ciphertext data.
[0089] The overall process description of the embodiment of this application:
[0090] 1) The client establishes a secure channel with the middleware;
[0091] The client sends a connection request to the confidential gateway;
[0092] Confidential Gateway:
[0093] I. Determine the legitimacy of the client: Check whether the client's IP meets the requirements;
[0094] II. Generate a derived key and SSL certificate for confidential computing: Generate an SSL certificate using the derived key and return it to the client for encrypted data transmission by the client;
[0095] Client: Checks the certificate, generates a decryption key based on the SSL certificate and sends it to the server;
[0096] Server: Receives the decryption key and returns a confirmation message to the client.
[0097] 2) The client initiates a processing request, which includes the address of the page;
[0098] i. Confidential gateway: forwards the request to the REE container to obtain page information;
[0099] ii. Confidential gateway: According to the page elements and confidential dictionary, the confidential field elements on the page are encapsulated with confidential controls. If the field elements are at the first confidentiality level, the encryption controls are encapsulated; if the field elements are at the second confidentiality level, the feature recognition controls are encapsulated. The page is returned to the client.
[0100] Client:
[0101] i. Display page;
[0102] ii. The data of the first confidentiality level is input by the user in the page input box, and the data of the second confidentiality level is collected through the feature recognition control;
[0103] The middleware of the embodiment of the present application performs the following operations:
[0104] i. Confidential gateway: Checks whether the data of the first confidentiality level is encrypted and whether the confidential data is collected from the feature control. If so, it is sent to the REE container for processing.
[0105] ii. REE environment:
[0106] For the first confidentiality level of data to be processed, it is sent to the TEE environment for decryption through the confidentiality gateway, and the decrypted data is obtained for business processing in the REE environment. After the processing is completed, it is encrypted again through the TEE environment;
[0107] For the data to be processed at the second confidential level, it is sent to the TEE environment through the confidential gateway for decryption processing, service processing, and encryption processing in sequence to obtain the calculation result. It should be noted that for the data at the first confidential level, if there is a storage requirement, it is necessary to first check whether the data is encrypted before storing it.
[0108] iii. Confidential gateway: Identify the confidential level of the service processing result returned by the REE environment and encapsulate the confidential or feature recognition control.
[0109] Client: Display the data. The service processing result at the first confidential level is displayed after authorized decryption, and the service processing result at the second confidential level can only be displayed through the feature recognition control.
[0110] The middleware in the embodiments of the present application can provide an end-to-end confidential computing security solution for the encoding, compilation, packaging, deployment, operation, and communication of applications, and the request, transmission, processing, and storage of data. In view of the lack of an effective middleware between the application layer and the hardware layer in the existing confidential computing technology to coordinate and manage computing tasks, resulting in the existing confidential computing solutions being only suitable for a few applications and having to be used in deeply customized scenarios (such as key management and privacy computing), the embodiments of the present application can be generally applicable to various conventional applications.
[0111] In the embodiments of the present application, a confidential computing method for an application is provided, which is applied to the middleware between the application and the computing system. The middleware pre-creates a Rich Execution Environment (REE) container and a Trusted Execution Environment (TEE) container. The TEE container is communicatively connected to the confidential computing hardware of the computing system, as Figure 1 shown. The method includes:
[0112] S101. Receive the encrypted data to be processed sent by the application through a pre-established encrypted data channel.
[0113] An encrypted data channel is pre-established between the middleware and the application in the embodiments of the present application, so that the application sends all the data to be processed through the encrypted data channel and encrypts the data during transmission to prevent data leakage.
[0114] S102. Call the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed.
[0115] After the encrypted data to be processed is received by the middleware, the TEE container first calls the confidential computing hardware to decrypt the encrypted data to be processed to obtain the data to be processed.
[0116] S103a. If it is determined that the data to be processed is of the first confidentiality level, the data to be processed is processed for business using the first Java archive file pre-stored in the REE container to obtain a business processing result.
[0117] In the embodiment of the present application, the data to be processed is pre-divided into two confidentiality levels. The lower confidentiality level is called the first confidentiality level. And the code of the application program is also classified - confidential code and non-confidential code. The non-confidential code is deployed in the REE container by being processed into the first Java archive file. Thus, the data of the first confidentiality level is processed for business by the first Java archive file in the REE container to obtain a business processing result.
[0118] It can be understood that since the first Java archive file is located in the REE container, after the TEE container decrypts to obtain the data to be processed, it is also necessary to send the data to be processed to the REE container.
[0119] S103b. If the confidentiality level of the data to be processed is the second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, the data to be processed is processed for business according to the second Java archive file pre-stored in the TEE container to obtain a business processing result.
[0120] If it is determined that the confidentiality level of the data to be processed is the second confidentiality level, then the data to be processed is continuously processed for business in the TEE container using the pre-stored second Java archive file to obtain a business processing result. The second Java archive file in the embodiment of the present application includes the confidential code in the application program.
[0121] This application sets up middleware between the application and the computing system. When the application needs to perform confidential computing, the data to be processed is not directly transmitted to the confidential computing hardware, thus avoiding the need to customize the application in advance to adapt to the confidential computing hardware. The middleware in the embodiments of this application receives the encrypted data to be processed transmitted through the encrypted data channel pre-established with the application, thereby ensuring the integrity of the data during the process of being transmitted outside the application. Further, the middleware of this application pre-creates a REE container and a TEE container, and this application also needs to perform confidential marking on the code of the application during the compilation stage of the application to determine the confidential code and the non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked, while the non-confidential code is the code that does not require special protection against the risk of leakage. In the embodiments of this application, the REE container includes a first Java archive file, and the first Java archive file includes the non-confidential code in the application. The TEE container includes a second Java archive file, and the second archive file includes the confidential code in the application, enabling the confidential code to be securely accessed but the internal logic to be invisible. Further, if the data to be processed is at the first confidential level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is at the higher second confidential level, the second Java archive file in the TEE container needs to be used for processing. The embodiments of this application firstly expand the application scope of confidential computing, making it applicable to any Java application. Secondly, it enhances the security of Java application data during transmission, processing, and storage. Thirdly, through the separation and request scheduling of the hardware of the REE container and the TEE container, it reduces the waste of TEE resources and lowers the operating cost.
[0122] Based on the above embodiments, as an alternative embodiment, after this application obtains the business processing result, it further includes:
[0123] Calling the confidential computing hardware through the TEE container to encrypt the business processing result, and returning the encrypted business processing result to the application through the encrypted data channel.
[0124] That is to say, whether the processing result of the data to be processed is obtained through the first Java archive file or the second Java archive file in the embodiments of this application, finally, the confidential computing hardware will be called through the TEE container to encrypt the business processing result, and then the encrypted business processing result will be returned to the application through the encrypted data channel between the middleware and the application.
[0125] Based on the above embodiments, as an alternative embodiment, the data to be processed is the data input in the target input box displayed by the application.
[0126] The application program in the embodiment of the present application displays at least one target input box on the operation interface. Through the input operation on the target input box by the operator, the input data will all be used as the data to be processed. Moreover, there are two types of target input boxes in the present application. One type of target input box pre-packages the first control, and the other type of target input box pre-packages the second control. Further, non-target input boxes can also be displayed in the operation interface. The data to be processed at the non-confidential level is input by the operator in the non-target input box, and the first control and the second control mentioned above do not need to be pre-packaged in the non-target input box.
[0127] In some embodiments, the input data related to the fields not registered in the confidential dictionary belongs to non-confidential data. Correspondingly, the input data related to the fields registered in the confidential dictionary belongs to confidential data.
[0128] Further, the embodiment of the present application determines the confidentiality level of the data to be processed, including:
[0129] If it is determined that the data to be processed is collected by the first control pre-packaged in the target input box, it is determined that the data to be processed is at the first confidentiality level;
[0130] If it is determined that the data to be processed is collected by the second control pre-packaged in the target input box, it is determined that the data to be processed is at the second confidentiality level.
[0131] The present application determines the confidentiality level of the data to be processed by judging which type of control pre-packaged in the target input box the data to be processed is collected by.
[0132] On the basis of the above embodiments, as an optional embodiment, the data to be processed is collected by the application program in the following manner:
[0133] Display the first input box and prompt the operator of the application program to input the information to be verified required for authorization verification. In response to the input operation of the information to be verified, call the first control to verify the information to be verified. If the verification passes, prompt the operator to input data in the first input box. In response to the input operation of the data, use the input data as the data to be processed.
[0134] The target input box of the embodiment of the present application includes a first input box, and a first control is encapsulated in the first input box. When the application program displays the first input box, it also needs to prompt the operator of the application program to perform authorization verification first. Only after the authorization verification passes can the operator have the permission to input the data to be processed. By responding to the operator's input operation of the information to be verified, the first control can be called to verify the information to be verified. If the verification passes, the operator is prompted to input data in the first input box; in response to the input operation of the data, the input data is used as the data to be processed.
[0135] In some embodiments, the information to be verified may be a password preset by the operator.
[0136] In some embodiments, the data to be processed can also be collected by the application program in the following ways:
[0137] Display a second input box, and prompt the operator to perform feature authentication. In response to the collected feature of the operator, call the second control to authenticate the feature. If the feature authentication passes, prompt the operator to input data in the second input box; in response to the input operation of the data, the input data is used as the data to be processed.
[0138] The target input box of the embodiment of the present application further includes a second input box, and a second control is encapsulated in the second input box. The second control is used for feature authentication. Therefore, when the present application displays the second input box, it further prompts the operator to perform feature authentication. The feature authentication method of the present application can be fingerprint authentication, iris authentication, voiceprint authentication, etc., which are authentication methods based on biometric features. If the feature authentication passes, prompt the operator to input data in the second input box; by further responding to the input operation of the data, the input data is used as the data to be processed.
[0139] The embodiment of the present application displays two target input boxes, and correspondingly prompts the operator to provide the authentication information. Further, the controls encapsulated by the target input boxes are used for authentication. Only after the authentication passes can the data to be processed be input in the target input box.
[0140] On the basis of the above embodiments, as an alternative embodiment, the returning the service processing result to the application program includes:
[0141] If the data to be processed is of the first confidentiality level, instruct the operator of the application program to input the information to be verified required for authorization verification. In response to the input operation of the information to be verified, call the first control to verify the information to be verified. If the verification passes, display the service processing result in the application program;
[0142] If the data to be processed is of the second confidentiality level, the operator is instructed to perform feature authentication. In response to the acquisition of the operator's features, the second control is called to verify the information to be verified. If the feature authentication is passed, the service processing result is displayed in the application program.
[0143] Based on the above embodiments, as an alternative embodiment, before receiving the encrypted data to be processed sent by the application program through the pre-established encrypted data channel, it further includes:
[0144] Receiving an access request sent by the application program, the access request includes an IP address;
[0145] If it is determined that the IP address is correct, a derived secret key is generated;
[0146] A signature certificate for the encrypted data channel is generated according to the derived secret key and sent to the application program, so that the application program encrypts and transmits the data to be processed according to the signature certificate;
[0147] Receiving the decryption secret key generated by the application program according to the signature certificate.
[0148] The embodiment of the present application also provides a solution for constructing an encrypted channel. Specifically, first, the application program needs to send an access request to the middleware. The access request includes an IP address. If the middleware determines that the IP address is correct, a derived secret key will be generated, and a signature certificate for the encrypted data channel will be generated according to the derived secret key. The middleware returns the signature certificate to the application program, and the application program can then encrypt and transmit the data to be processed according to the signature certificate. After receiving the signature certificate, the application program will also generate a decryption secret key, and the middleware receives the decryption secret key sent by the application program.
[0149] In some embodiments, the TEE environment uses the derived secret key to encrypt the confidential code, so the encrypted code can only run on this TEE environment.
[0150] Based on the above embodiments, as an alternative embodiment, the embodiment of the present application further includes:
[0151] Construct a confidential dictionary during the development stage of the application program and perform confidential marking on the code. The confidential dictionary includes the interface parameters of the service interfaces of the second encryption level external to the application program and the fields of the second encryption level in the database table;
[0152] During the compilation stage of the application program, use the derived secret key of the secret key management in the TEE environment to encrypt and compile the marked confidential code to obtain a second Java archive file, and perform non-encrypted compilation on the non-confidential code to obtain a first Java archive file;
[0153] Store the first Java archive file in the REE application container and store the second Java archive file in the TEE application container.
[0154] Please refer to Figure 2 , which exemplarily shows a schematic flowchart of encrypting and protecting the code of an application in an embodiment of the present application. The code encryption protection process of this solution is a systematic and elaborate process, aiming to ensure the security of the code during the development, deployment, and operation phases. The entire process is divided into three phases, and each phase plays a crucial role. The following is a detailed description of these three phases:
[0155] Phase 1: Confidential Marking in the Development Phase
[0156] In the development phase, developers need to identify and mark the parts of the code that contain sensitive information or critical logic, which are the code segments that need to be specially protected. This process generally involves the following steps:
[0157] Code Review: Developers first need to conduct a comprehensive review of the entire codebase to identify which parts contain trade secrets, algorithmic logic, key management, or other sensitive information;
[0158] Confidential Marking: Once these sensitive code segments are identified, developers will use specific marks or annotations to label them for subsequent processing. These marks can be simple comments or specific code tags for automatic identification during the compilation phase;
[0159] Documentation: To ensure that all team members understand which code is protected, developers also need to write corresponding documentation to record which code segments have been marked as confidential.
[0160] Phase 2: Compilation, Packing, and Encrypted Deployment
[0161] After the confidential marking is completed, the code enters the compilation and packing phase. The main task of this phase is to convert the code into an executable format and perform encryption processing using the derived secret key, and finally deploy it to the Trusted Execution Environment (TEE). The specific steps are as follows:
[0162] Compilation and Packing: Use appropriate compilers and packing tools to convert the source code into an executable file or library file. During this process, the compilation tool will identify the code segments marked as confidential before.
[0163] Derived Secret Key Generation: Based on the master key or other security mechanisms, generate derived secret keys for encrypting specific code segments. The generation and management of these secret keys should follow strict security standards.
[0164] Code Encryption: Use the generated derived key to encrypt the code segments marked as confidential. The encrypted code segments cannot be directly read or tampered with even if extracted without authorization;
[0165] Deployment to the TEE Environment: The encrypted code package is deployed to the TEE environment. TEE is a hardware-level secure environment that can ensure that the code cannot be externally accessed or tampered with during runtime.
[0166] Phase 3: Decryption and Execution in the TEE Environment
[0167] In the TEE environment, the encrypted code segments need to be decrypted and executed during runtime. This process ensures that the sensitive parts of the code are still protected when running in an untrusted environment. The specific steps are as follows:
[0168] Decryption Key Management: Inside the TEE environment, the decryption key is securely stored and managed. The decryption key is only visible and used within the TEE, ensuring that external attackers cannot obtain it.
[0169] Code Decryption: When the encrypted code segments need to be executed, the TEE uses the internally stored decryption key to decrypt the code. The decryption process is completed within the TEE, ensuring that the code cannot be externally accessed during the short period after decryption.
[0170] Code Execution: The decrypted code segments are securely executed in the TEE environment. Since the TEE provides hardware-level isolation and protection, even if the operating system or other software layers are attacked, the encrypted code segments can remain secure.
[0171] Monitoring and Logging: To ensure the security and traceability of code execution, the TEE environment should also have monitoring and logging functions. These functions can record the execution status of the code, abnormal events, etc., for subsequent analysis and auditing.
[0172] In summary, the code encryption protection process of this solution ensures the security of the entire life cycle of the code from development to deployment and then to execution through three closely connected phases.
[0173] This application embodiment provides a confidential computing device for an application, which is applied to the middleware between the application and the computing system. The middleware pre-creates a REE container and a TEE container, and the TEE container is communicatively connected to the confidential computing hardware of the computing system. The device includes as Figure 3 shown, the confidential computing device of this application may include: a data receiving module 301, a decryption module 302, a first processing module 303, and a second processing module 304, where
[0174] A data receiving module 301, configured to receive encrypted data to be processed sent by an application through a pre-established encrypted data channel;
[0175] A decryption module 302, configured to call the confidential computing hardware by the TEE container to decrypt the encrypted data to be processed, so as to obtain the data to be processed;
[0176] A first processing module 303, configured to, if it is determined that the data to be processed is of a first confidentiality level, perform service processing on the data to be processed through a first Java archive file pre-stored in the REE container, so as to obtain a service processing result, where the first Java archive file includes non-confidential code in the application;
[0177] A second processing module 304, configured to, if the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, perform service processing on the data to be processed according to a second Java archive file pre-stored in the TEE container, so as to obtain a service processing result, where the second Java archive file includes confidential code in the application.
[0178] The device according to an embodiment of the present application can execute the method provided by the embodiment of the present application, and the implementation principle is similar. The actions performed by each module in the device according to each embodiment of the present application correspond to the steps in the method according to each embodiment of the present application. For the detailed function descriptions of the modules of the device, reference can specifically be made to the descriptions in the corresponding methods shown above, and details are not described herein again.
[0179] An embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory. The processor executes the above computer program to implement the steps of a confidential computing method for an application program. Compared with the related art, the following can be achieved: The present application sets up a middleware between the application program and the computing system. When the application program needs to perform confidential computing, the data to be processed will not be directly transmitted to the confidential computing hardware, thus avoiding the need to customize the application program in advance to adapt to the confidential computing hardware. The middleware in the embodiment of the present application receives the encrypted data to be processed transmitted through the encrypted data channel pre-established with the application program, thereby ensuring the integrity of the data during the process of being transmitted outside the application program. Further, the middleware of the present application pre-creates a REE container and a TEE container, and the present application also needs to perform confidential marking on the code of the application program during the compilation stage of the application program to determine the confidential code and the non-confidential code. It can be understood that the confidential code is the code used to process important data and the processing process cannot be leaked, while the non-confidential code is the code that does not require special protection against the risk of leakage. In the embodiment of the present application, the REE container includes a first Java archive file, and the first Java archive file includes the non-confidential code in the application program. The TEE container includes a second Java archive file, and the second archive file includes the confidential code in the application program, so that the confidential code can be securely accessed, but the internal logic is invisible. Further, if the data to be processed is of the first confidential level, the first Java archive file in the REE container is used to perform business processing on the data to be processed. If the data to be processed is of the higher second confidential level, the second Java archive file in the TEE container needs to be used for processing. The embodiment of the present application firstly expands the application scope of confidential computing, which is applicable to any Java application program. Secondly, it enhances the security of Java application data during transmission, processing, and storage. Thirdly, through the separation and request scheduling of the REE container and the TEE container hardware, it reduces the waste of TEE resources and lowers the operating cost.
[0180] In an alternative embodiment, an electronic device is provided, as Figure 4 shown. Figure 4 The electronic device 4000 shown in the figure includes: a processor 4001 and a memory 4003. Among them, the processor 4001 and the memory 4003 are connected, such as connected through a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, and the transceiver 4004 may be used for data interaction between this electronic device and other electronic devices, such as sending and / or receiving data, etc. It should be noted that in actual applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiments of the present application.
[0181] The processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0182] The bus 4002 may include a path for transmitting information between the above components. The bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 4002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus 4002 is only shown as a thick line in the figure, but it does not mean that there is only one bus or one type of bus.
[0183] The memory 4003 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or it may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, which is not limited herein.
[0184] The memory 4003 is used to store the computer program for implementing the embodiments of the present application and is controlled by the processor 4001 to execute. The processor 4001 is used to execute the computer program stored in the memory 4003 to implement the steps shown in the foregoing method embodiments.
[0185] The embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps and corresponding content of the foregoing method embodiments can be implemented.
[0186] The embodiments of the present application further provide a computer program product, including a computer program. When the computer program is executed by a processor, the steps and corresponding content of the foregoing method embodiments can be implemented.
[0187] The terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the description, claims and above-mentioned drawings of the present application are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than the illustrated or described order.
[0188] It should be understood that although the flowcharts of the embodiments of the present application indicate each operation step by an arrow, the execution order of these steps is not limited to the order indicated by the arrow. Unless there is a clear description in this article, in some implementation scenarios of the embodiments of the present application, the implementation steps in each flowchart can be executed in other orders according to requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on the actual implementation scenario. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage of these sub-steps or stages can also be executed at different times respectively. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiments of the present application do not limit this.
[0189] The above are only optional implementation manners of some implementation scenarios of the present application. It should be noted that for those of ordinary skill in the art, without departing from the technical concept of the solution of the present application, adopting other similar implementation means based on the technical idea of the present application also belongs to the protection scope of the embodiments of the present application.
Claims
1. A confidential computing method for an application program, characterized in that, Middleware applied between an application and a computing system. The middleware pre-creates a Rich Execution Environment (REE) container and a Trusted Execution Environment (TEE) container. The TEE container is communicatively connected to the confidential computing hardware of the computing system. The method includes: Receiving encrypted data to be processed sent by an application through a pre-established encrypted data channel; Invoking the confidential computing hardware through the TEE container to decrypt the encrypted data to be processed to obtain the data to be processed; If it is determined that the data to be processed is of a first confidentiality level, then using a first Java Archive (JAR) file pre-stored in the REE container to perform business processing on the data to be processed to obtain a business processing result. The first JAR file includes non-confidential code in the application; If the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, then performing business processing on the data to be processed according to a second JAR file pre-stored in the TEE container to obtain a business processing result. The second JAR file includes confidential code in the application; Wherein, the method further includes: Constructing a confidentiality dictionary and performing confidentiality marking on the code during the development stage of the application. The confidentiality dictionary includes interface parameters of service interfaces at a second encryption level exposed by the application and fields at the second encryption level in the database table; During the compilation stage of the application, using a derived key managed by the key management in the TEE environment to encrypt and compile the marked confidential code to obtain a second JAR file, and performing non-encrypted compilation on the non-confidential code to obtain a first JAR file; Storing the first JAR file in the REE application container and storing the second JAR file in the TEE application container.
2. The method according to claim 1, characterized in that, After obtaining the business processing result, it further includes: Invoking the confidential computing hardware through the TEE container to encrypt the business processing result, and returning the encrypted business processing result to the application through the encrypted data channel.
3. The method according to claim 2, wherein The data to be processed is the data input in a target input box displayed by the application; Determining the confidentiality level of the data to be processed includes: If it is determined that the data to be processed is collected by a first control pre-encapsulated in the target input box, then determining that the data to be processed is of a first confidentiality level; If it is determined that the data to be processed is collected by a second control pre-encapsulated in the target input box, then determining that the data to be processed is of a second confidentiality level; Wherein, the application includes at least one target input box, and each target input box pre-encapsulates a first control or a second control.
4. The method according to claim 3, wherein The data to be processed is collected by the application in the following manner: Display the first input box and prompt the operator of the application to input the information to be verified required for authorization verification. In response to the input operation of the information to be verified, call the first control to verify the information to be verified. If the verification passes, prompt the operator to input data in the first input box; in response to the input operation of the data, use the input data as the data to be processed. Or Display the second input box and prompt the operator to perform feature authentication. In response to the collection of the operator's features, call the second control to authenticate the features. If the feature authentication passes, prompt the operator to input data in the second input box; in response to the input operation of the data, use the input data as the data to be processed.
5. The method according to claim 3 or 4, characterized in that, The returning the service processing result to the application includes: If the data to be processed is of the first confidentiality level, instruct the operator of the application to input the information to be verified required for authorization verification. In response to the input operation of the information to be verified, call the first control to verify the information to be verified. If the verification passes, display the service processing result in the application. If the data to be processed is of the second confidentiality level, instruct the operator to perform feature authentication. In response to the collection of the operator's features, call the second control to verify the information to be verified. If the feature authentication passes, display the service processing result in the application.
6. The method according to claim 1, characterized in that, Before the receiving the encrypted data to be processed sent by the application through the pre-established encrypted data channel, further includes: Receive the access request sent by the application, where the access request includes an IP address; If it is determined that the IP address is correct, generate a derived secret key; Generate a signature certificate for the encrypted data channel according to the derived secret key and send it to the application, so that the application encrypts and transmits the data to be processed according to the signature certificate; Receive the decryption secret key generated by the application according to the signature certificate.
7. A confidential computing device for an application program, characterized in that, Applied to the middleware between the application and the computing system, the middleware pre-creates a REE container and a TEE container, and the TEE container is communicatively connected to the confidential computing hardware of the computing system. The device includes: A data receiving module, configured to receive the encrypted data to be processed sent by the application through the pre-established encrypted data channel; A decryption module, configured to decrypt the encrypted data to be processed by invoking the confidential computing hardware through the TEE container to obtain the data to be processed; A first processing module, configured to, if it is determined that the data to be processed is of the first confidentiality level, perform service processing on the data to be processed through a first Java archive file pre-stored in the REE container to obtain a service processing result, where the first Java archive file includes non-confidential code in the application; A second processing module, configured to, if the confidentiality level of the data to be processed is a second confidentiality level, and the second confidentiality level is higher than the first confidentiality level, perform business processing on the data to be processed according to a second Java archive file pre-stored in the TEE container, to obtain a business processing result, where the second Java archive file includes confidential code in the application; The apparatus further includes: A dictionary construction module, configured to construct a confidential dictionary during the development stage of the application and perform confidential marking on the code, where the confidential dictionary includes interface parameters of a service interface at a second encryption level exposed by the application and fields at a second encryption level in a database table; An encryption compilation module, configured to, during the compilation stage of the application, use a derived key managed by a key management in a TEE environment to perform encrypted compilation on the marked confidential code to obtain a second Java archive file, and perform non-encrypted compilation on non-confidential code to obtain a first Java archive file; A storage module, configured to store the first Java archive file in an REE application container and store the second Java archive file in a TEE application container.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the confidential computing method of the application according to any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the confidential computing method of the application according to any one of claims 1-6.
Citation Information
Patent Citations
Intelligent contract virtual machine system and intelligent contract execution method
CN118797721A