Multi-party computing security verification method, device, system, equipment, medium and product
By using confidential container contracts and signature key verification, the operation of applications within confidential containers is restricted, which solves the problem of data leakage and improves the security of cloud-native multi-party secure computing.
Patent Information
- Application Number
- CN202510594844.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-05-09
AI Technical Summary
In cloud-native multi-party secure computing based on confidential container technology, data cannot be restricted to applications running in confidential containers, resulting in a high risk of data leakage.
The confidential container contract is used to limit the applications running in the confidential container, obtain the confidential container startup verification request, determine the target computing participant associated with the contract, and use the pre-configured signing key for integrity verification to ensure the security of the image file.
It improves the security of confidential computing, avoids data leakage caused by storing data on disk or sending it over the network, and enhances data protection.
Smart Images

Figure CN120110812B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of computer technology, and in particular to a multi-party computing security verification method, apparatus, system, device, medium, and product. Background Art
[0002] Confidential-Containers (CCLs) is a technical specification for confidential computing in the cloud-native field. Based on CCLs, cloud-native multi-party secure computing can be implemented. However, during the implementation of this invention, it was discovered that the existing technology has at least the following technical problems:
[0003] In cloud-native multi-party secure computing based on confidential container technology, data can only be guaranteed to be available but not visible within the confidential container. Applications running in the confidential container cannot be restricted. Applications in the confidential container may write data to disk or send it over the network, causing data leakage. Summary of the Invention
[0004] Embodiments of the present invention provide a multi-party computing security verification method, apparatus, system, equipment, medium, and product, which can limit the applications running in confidential containers through container contracts, restrict the startup and operation of confidential containers, improve the security of confidential computing, and prevent suspicious applications from writing data to disk or sending it over the network, causing data leakage.
[0005] In a first aspect, an embodiment of the present invention provides a multi-party computing security verification method, which is applied to a remote authentication server. The method includes:
[0006] Obtain a confidential container startup verification request from the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0007] Determine the target computing participants associated with the confidential container contract and verify the integrity of the confidential container contract based on the pre-configured signing key of each target computing participant.
[0008] In a second aspect, an embodiment of the present invention provides a multi-party computing security verification method, which is applied to a confidential container running terminal. The method includes:
[0009] In response to a startup trigger operation of the confidential container to be started based on a preset confidential container contract, a confidential container startup verification request is sent to the remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract; wherein the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0010] If the integrity verification result is passed, the remote authentication server is requested to provide the image file included in the file list in the preset confidential container contract.
[0011] In a third aspect, an embodiment of the present invention further provides a multi-party computing security verification device, which is configured on a remote authentication server, and includes:
[0012] A verification request response module is used to obtain a confidential container startup verification request from the confidential container running end and determine the confidential container contract associated with the confidential container startup verification request; wherein the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run;
[0013] The contract verification module is used to determine the target computing participants associated with the confidential container contract and verify the integrity of the confidential container contract based on the pre-configured signature key of each target computing participant.
[0014] In a fourth aspect, an embodiment of the present invention further provides a multi-party computing security verification device, which is configured on a confidential container running terminal and includes:
[0015] a verification request module, configured to send a confidential container startup verification request to a remote authentication server in response to a startup trigger operation of a target confidential container, so that the confidential container startup verification request performs integrity verification on a target confidential container contract associated with the target confidential container;
[0016] The image file pulling module is used to request the image file included in the file list in the preset confidential container contract from the remote authentication server when the integrity verification result is passed.
[0017] In a fifth aspect, a multi-party computing security verification system is provided, characterized by comprising:
[0018] Confidential container running end and remote authentication server;
[0019] The confidential container running end is used to implement the multi-party computing security verification method provided by any embodiment of the present invention;
[0020] The remote authentication server is used to implement the multi-party computing security verification method provided by any embodiment of the present invention.
[0021] In a sixth aspect, an embodiment of the present invention further provides a computer device, the computer device comprising:
[0022] one or more processors;
[0023] a memory for storing one or more programs;
[0024] When one or more programs are executed by one or more processors, the one or more processors implement the multi-party computing security verification method provided by any embodiment of the present invention.
[0025] In a seventh aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the multi-party computing security verification method provided by any embodiment of the present invention is implemented.
[0026] In an eighth aspect, an embodiment of the present disclosure further provides a computer program product, including a computer program, which, when executed by a processor, implements the multi-party computing security verification method provided by any embodiment of the present invention.
[0027] The embodiments of the above invention have the following advantages or beneficial effects:
[0028] The embodiment of the present invention obtains a confidential container startup verification request from the confidential container running end, and determines the confidential container contract associated with the confidential container startup verification request; wherein the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; determines the target computing participant associated with the confidential container contract, and performs integrity verification on the confidential container contract based on the signature key pre-configured by each target computing participant. The technical solution of the embodiment of the present invention solves the problem that data leakage may occur during the confidential container computing process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it through the network, causing data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 This is a flowchart of a multi-party computing security verification method applied to a remote authentication server provided by an embodiment of the present invention;
[0030] Figure 2 This is a flowchart of another multi-party computing security verification method applied to a remote authentication server provided by an embodiment of the present invention;
[0031] Figure 3 This is a flowchart of a multi-party computing security verification method applied to a confidential container running terminal provided by an embodiment of the present invention;
[0032] Figure 4 This is a schematic diagram of the structure of a multi-party computing security verification device configured on a remote authentication server provided by an embodiment of the present invention;
[0033] Figure 5 This is a schematic diagram of the structure of a multi-party computing security verification device configured on a confidential container running end provided by an embodiment of the present invention;
[0034] Figure 6 This is a schematic diagram of the structure of a multi-party computing security verification system provided by an embodiment of the present invention;
[0035] Figure 7 This is a schematic diagram of an application example of a multi-party computing security verification system provided by an embodiment of the present invention;
[0036] Figure 8 It is a structural diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0037] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.
[0038] Figure 1 This is a flowchart of a multi-party computation security verification method for a remote authentication server, provided in an embodiment of the present invention. This embodiment is applicable to confidential computing scenarios, particularly those protecting data security in confidential computing. This method can be performed by a multi-party computation security verification device, which can be implemented in software and / or hardware and integrated into a computer device with application development capabilities.
[0039] like Figure 1 As shown, the multi-party computing security verification method of this embodiment includes the following steps:
[0040] S110: Obtain a confidential container startup verification request from the confidential container running end, and determine a confidential container contract associated with the confidential container startup verification request.
[0041] Among them, the confidential container running end can be a computer device end that can support the operation of the confidential container, that is, the running startup platform for the confidential container to be started.
[0042] The confidential container contract is the information that the running of the confidential container to be launched depends on, including the file list of image files that can be run in the confidential container to be launched. The file list is the information pre-agreed upon by the computing participants of the confidential computing implemented by the executable image files.
[0043] When a confidential computing participant deploys a confidential container through a confidential container contract and the confidential container is started, the corresponding confidential container becomes a confidential container to be started, and the confidential container running end that runs the confidential container to be started will issue a confidential container startup verification request.
[0044] When the remote authentication server receives the confidential container startup verification request issued by the confidential container running end, it will respond to the confidential container startup verification request and determine the confidential container contract associated with the confidential container startup verification request so as to perform verification based on the information in the corresponding confidential container contract.
[0045] S120. Determine the target computing participants associated with the confidential container contract, and verify the integrity of the confidential container contract based on the pre-configured signature key of each target computing participant.
[0046] Because a confidential container contract is information agreed upon by multiple computing participants, it is necessary to identify the target computing participant associated with the confidential container contract. Furthermore, the integrity of the confidential container contract can be verified based on the pre-configured signing key of each target computing participant. Each target computing participant's signing key is pre-configured on the remote authentication server.
[0047] After verifying the integrity of the confidential container contract, it can be confirmed that the confidential container contract has not been tampered with or compromised. This allows the computing environment of the confidential container's runtime to be verified, and the image file corresponding to the confidential container contract to be executed. The image files in the confidential container contract's file list have been screened and confirmed by each target computing participant to be trusted applications. This prevents suspicious applications from storing data on disk or sending it over the network, potentially causing data leaks.
[0048] The technical solution of this embodiment is to obtain the confidential container startup verification request of the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein, the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; determine the target computing participant associated with the confidential container contract, and verify the integrity of the confidential container contract according to the pre-configured signature key of each target computing participant. The technical solution of the embodiment of the present invention solves the problem that data leakage may occur during the confidential container computing process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it through the network, causing data leakage.
[0049] Figure 2 This is a flowchart of a multi-party computation security verification method for a remote authentication server, provided in an embodiment of the present invention. This embodiment shares the same inventive concept as the multi-party computation security verification method described above and further describes the process of generating a confidential container contract. This method can be executed by a multi-party computation security verification device, which can be implemented in software and / or hardware and integrated into a computer device with application development capabilities.
[0050] like Figure 2 As shown, the multi-party computing security verification method of this embodiment includes the following steps:
[0051] S210. In a preset container contract configuration interactive interface, obtain selection operations and signature operations of multiple target computing participants on candidate image files.
[0052] Among them, the preset container contract configuration interaction interface can be an interaction interface provided by the remote authentication server to the confidential computing participants, and each confidential computing participant can configure the interaction interface in the preset container contract.
[0053] The remote authentication server can be any of the confidential computing participants, and the participants can agree on one of them to serve as the remote authentication server. The remote authentication server can also be a dedicated user outside of the confidential computing participants who performs remote security authentication.
[0054] In the preset container contract configuration interactive interface, a list of candidate image files can be set, and each confidential computing participant can check and verify each image file.
[0055] S220: Determine an executable image file based on the selection operation, and perform signature encryption on the executable image file based on the signature operation. Each confidential computing participant can select a candidate image file from the candidate image file list that has been inspected and verified by it, and sign the selected image file.
[0056] S230: The file name and version number of the executable image file that has been processed by signature encryption are used as list information to obtain a file list.
[0057] The image files corresponding to the file names and version numbers in the file list indicate the image files that can be obtained and run.
[0058] S240. After obtaining the list signature operation of each target computing participant on the file list, the generation process of the confidential container contract is completed.
[0059] S250. On the preset signature key configuration page, obtain the signature key configuration operation of each target computing participant.
[0060] The preset signature key configuration page is a key configuration page provided by the remote authentication server. Confidential computing participants can configure their own signature verification keys in the remote authentication server to support integrity verification of container contracts.
[0061] S260. Determine, based on the signature key configuration operation, the signature verification key used by each target computing participant to verify the integrity of the confidential container contract.
[0062] S270: Obtain a confidential container startup verification request from the confidential container running end, and determine a confidential container contract associated with the confidential container startup verification request.
[0063] Among them, the confidential container contract is the result generated by the above steps, including a file list of image files that can be run in the confidential container to be started. The file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run.
[0064] S280. Determine the target computing participants associated with the confidential container contract, and verify the integrity of the confidential container contract based on the pre-configured signature key of each target computing participant.
[0065] The technical solution of this embodiment obtains the selection and signature operations of candidate image files by multiple target computing participants in the preset container contract configuration interactive interface; determines the image file that can be run based on the selection operation, and performs signature encryption processing on the image file that can be run based on the signature operation; uses the file name and version number of the image file that can be run after the signature encryption processing as the list information to obtain the file list; after obtaining the list signature operation of the file list by each target computing participant, the generation process of the confidential container contract is completed; obtains the signature key configuration operation of each target computing participant in the preset signature key configuration page; and The configuration operation determines the signature verification key used by each target computing participant to verify the integrity of the confidential container contract; obtains the confidential container startup verification request of the confidential container running end, and determines the confidential container contract associated with the confidential container startup verification request; wherein, the confidential container contract is the result generated by the above steps, including a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; determines the target computing participant associated with the confidential container contract, and verifies the integrity of the confidential container contract according to the signature key pre-configured by each target computing participant. The technical solution of the embodiment of the present invention solves the problem that data leakage may occur during the confidential container computing process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it through the network, causing data leakage.
[0066] Figure 3 This is a flowchart of a multi-party computing security verification method applied to a confidential container runtime, provided in an embodiment of the present invention. This embodiment, which shares the same inventive concept as the multi-party computing security verification method in the previous embodiment, further illustrates the process of starting a confidential container runtime. This method can be executed by a multi-party computing security verification device, which can be implemented in software and / or hardware and integrated into a computer device with application development capabilities.
[0067] like Figure 3 As shown, the multi-party computing security verification method of this embodiment includes the following steps:
[0068] S310: In response to a startup trigger operation of the confidential container to be started based on a preset confidential container contract, a confidential container startup verification request is sent to a remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract.
[0069] Among them, the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started. The file list is information pre-agreed upon by the computing participants of the confidential computing implemented by the image files that can be run.
[0070] When a confidential computing participant wishes to perform confidential computing, they deploy a confidential computing contract that meets their computing needs on a target confidential container. This target confidential container is referred to as the "to-be-launched confidential container." When the confidential computing participant triggers the to-be-launched confidential container based on the preset confidential container contract, the confidential container runtime can respond to the to-be-launched confidential container's launch trigger based on the preset confidential container contract by sending a confidential container launch verification request to the remote authentication server, enabling the remote authentication server to verify the integrity of the preset confidential container contract.
[0071] S320: If the integrity verification result is passed, request the remote authentication server for the image file included in the file list in the preset confidential container contract.
[0072] After the confidential container operator obtains the verified image file contained in the file list in the preset confidential container contract from the remote authentication server, it can run the confidential container to implement the calculation process corresponding to the image file contained in the file list in the preset confidential container contract.
[0073] Furthermore, after obtaining the image file, the confidential computing container can decrypt the computing data according to the signature key of each computing participant in the preset confidential container contract to obtain the target data object; start the confidential container to be started, and run the image file based on the target data object.
[0074] If the integrity verification result is a failure, the confidential container will not be started, and the image file in the file list of the preset confidential container contract will not be obtained.
[0075] The technical solution of this embodiment, in response to the startup trigger operation of the confidential container to be started based on the preset confidential container contract, sends a confidential container startup verification request to the remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract; when the integrity verification result is verification passed, the remote authentication server is requested to include the mirror file included in the file list in the preset confidential container contract. The technical solution of the embodiment of the present invention solves the problem of data leakage that may occur during the confidential container calculation process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it over the network, causing data leakage.
[0076] Figure 4 A structural diagram of a multi-party computing security verification device configured at a remote authentication server provided in an embodiment of the present invention. This embodiment can be used in confidential computing scenarios, especially in situations where data security is protected in confidential computing. The multi-party computing security verification device can be implemented by software and / or hardware and integrated into a computer terminal device with application development capabilities.
[0077] like Figure 4 The multi-party computing security verification device shown includes: a verification request response module 410 and a contract verification module 420.
[0078] Among them, the verification request response module 410 is used to obtain the confidential container startup verification request of the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein, the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; the contract verification module 420 is used to determine the target computing participant associated with the confidential container contract, and perform integrity verification on the confidential container contract according to the pre-configured signature key of each target computing participant.
[0079] The technical solution of this embodiment is to obtain the confidential container startup verification request of the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein, the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; determine the target computing participant associated with the confidential container contract, and verify the integrity of the confidential container contract according to the pre-configured signature key of each target computing participant. The technical solution of the embodiment of the present invention solves the problem that data leakage may occur during the confidential container computing process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it through the network, causing data leakage.
[0080] In an optional embodiment, the multi-party computing security verification device configured on the remote authentication server further includes a confidential container contract generation module for:
[0081] In the preset container contract configuration interactive interface, multiple target computing participants are asked to select and sign candidate image files.
[0082] Determine the image file that can be run based on the selection operation, and perform signature encryption processing on the image file that can be run based on the signature operation;
[0083] The file name and version number of the executable image file that has been signed and encrypted are used as list information to obtain a file list;
[0084] After obtaining the list signature operation of each target computing participant on the file list, the generation process of the confidential container contract is completed.
[0085] In an optional embodiment, the multi-party computing security verification device configured on the remote authentication server further includes a computing participant key configuration module for:
[0086] After the confidential container contract is generated, obtain the signature key configuration operation of each target computing participant on the preset signature key configuration page;
[0087] The signature verification key used by each target computing participant to verify the integrity of the confidential container contract is determined based on the signature key configuration operation.
[0088] In an optional embodiment, the multi-party computing security verification device configured on the remote authentication server further includes a data sending module for:
[0089] When the integrity verification result is that the verification is passed, the image file corresponding to the image file information included in the file list is sent to the confidential container running end.
[0090] The multi-party computing security verification device configured at the remote authentication server provided by the embodiment of the present invention can execute the multi-party computing security verification method applied to the remote authentication server provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0091] Figure 5 This is a schematic diagram of the structure of a multi-party computing security verification device configured on a confidential container running terminal, provided by an embodiment of the present invention. This embodiment is applicable to confidential computing scenarios, particularly for protecting data security in confidential computing. The multi-party computing security verification device can be implemented using software and / or hardware and integrated into a computer terminal device with application development capabilities.
[0092] like Figure 5 As shown, the multi-party computing security verification device includes: a verification request module 510 and an image file pulling module 520.
[0093] Among them, the verification request module 510 is used to send a confidential container startup verification request to the remote authentication server in response to the startup trigger operation of the confidential container to be started based on the preset confidential container contract, so that the remote authentication server can perform integrity verification on the preset confidential container contract; wherein, the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by the computing participants of the confidential computing implemented by the image files that can be run; the image file pulling module 520 is used to request the remote authentication server for the image file included in the file list in the preset confidential container contract when the verification result of the integrity verification is verification passed.
[0094] The technical solution of this embodiment, in response to the startup trigger operation of the confidential container to be started based on the preset confidential container contract, sends a confidential container startup verification request to the remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract; when the integrity verification result is verification passed, the remote authentication server is requested to include the mirror file included in the file list in the preset confidential container contract. The technical solution of the embodiment of the present invention solves the problem of data leakage that may occur during the confidential container calculation process. The container contract can be used to limit the applications running in the confidential container, restrict the startup and operation of the confidential container, improve the security of confidential computing, and prevent suspicious applications from writing data to the disk or sending it over the network, causing data leakage.
[0095] In an optional embodiment, the multi-party computing security verification device configured at the confidential container running end further includes a container running module, which is used to:
[0096] After obtaining the image file, the calculation data is decrypted according to the signature key of each computing participant in the preset confidential container contract to obtain the target data object;
[0097] Start the secret container to be started and run the image file based on the target data object.
[0098] The multi-party computing security verification device configured at the confidential container running end provided by an embodiment of the present invention can execute the multi-party computing security verification method applied to the confidential container running end provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0099] Figure 6 This is a structural diagram of a multi-party computing security verification system provided by an embodiment of the present invention. This embodiment can be used in confidential computing scenarios, especially to protect data security in confidential computing.
[0100] Specifically, such as Figure 6As shown, the multi-party computing security verification system includes: a confidential container running end 610 and a remote authentication service end 620.
[0101] Among them, the confidential container running end 610 is used to implement the multi-party computing security verification method applied to the confidential container running end as described in any of the above embodiments.
[0102] The remote authentication server 620 is used to implement the multi-party computing security verification method applied to the remote authentication server as described in any of the above embodiments.
[0103] Figure 7 The diagram shows the interaction between computing participants, the confidential container runtime 610, and the remote authentication server 620. Specifically, participants in cloud-native multi-party secure computing agree on the container images that can be run within the container through a container contract; participants in cloud-native multi-party secure computing sign the container contract; participants in multi-party secure computing jointly configure a remote authentication server, which stores the signature keys of the multi-party secure computing participants; a participant can use the container contract to deploy a confidential container on an existing container platform that supports confidential computing; when the confidential container is started, the integrity of the container contract is verified by the remote authentication server; the confidential container runtime obtains the decryption key of the data encryption key through remote authentication, decrypts the encryption key to obtain the data decryption key; the encryption key in the container contract decrypts the data provider's data.
[0104] Figure 8 A schematic structural diagram of a computer device provided in an embodiment of the present invention. Figure 8 A block diagram of an exemplary computer device 12 suitable for use in implementing embodiments of the present invention is shown. Figure 8 The computer device 12 shown is only an example and should not limit the functionality and scope of use of the embodiments of the present invention. The computer device 12 can be any terminal device with computing capabilities, such as an intelligent controller, a server, a mobile phone, or other terminal devices.
[0105] like Figure 8 As shown, computer device 12 is implemented as a general-purpose computing device. Components of computer device 12 may include, but are not limited to, one or more processors or processing units 16, system memory 28, and a bus 18 that connects various system components (including system memory 28 and processing unit 16).
[0106] Bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.
[0107] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0108] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache 32. Computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be configured to read and write non-removable, non-volatile magnetic media ( Figure 8 Not shown, usually called a "hard drive"). Although Figure 8 Although not shown, a magnetic disk drive for reading and writing to a removable non-volatile magnetic disk (e.g., a "floppy disk"), as well as an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. System memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments of the present invention.
[0109] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 42 generally implement the functions and / or methodologies of the embodiments described herein.
[0110] The computer device 12 may also communicate with one or more external devices 14 (e.g., a keyboard, a pointing device, a display 24, etc.), one or more devices that enable a user to interact with the computer device 12, and / or any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the computer device 12 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with the other modules of the computer device 12 via the bus 18. It should be understood that although Figure 8 Not shown, other hardware and / or software modules may be used in conjunction with computer device 12, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0111] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the multi-party computing security verification method for a remote authentication server provided in the embodiment of the present invention, which includes:
[0112] Obtain a confidential container startup verification request from the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0113] Determine the target computing participants associated with the confidential container contract and verify the integrity of the confidential container contract based on the pre-configured signing key of each target computing participant.
[0114] Alternatively, for example, a multi-party computing security verification method applied to a confidential container running terminal provided in an embodiment of the present invention may be implemented, the method including:
[0115] In response to a startup trigger operation of the confidential container to be started based on a preset confidential container contract, a confidential container startup verification request is sent to the remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract; wherein the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0116] If the integrity verification result is passed, the remote authentication server is requested to provide the image file included in the file list in the preset confidential container contract.
[0117] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the multi-party computing security verification method applied to a remote authentication server as provided in any embodiment of the present invention is implemented. The method includes:
[0118] Obtain a confidential container startup verification request from the confidential container running end, and determine the confidential container contract associated with the confidential container startup verification request; wherein the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0119] Determine the target computing participants associated with the confidential container contract and verify the integrity of the confidential container contract based on the pre-configured signing key of each target computing participant.
[0120] Alternatively, a multi-party computing security verification method applied to the confidential container running end may be implemented, the method including:
[0121] In response to a startup trigger operation of the confidential container to be started based on a preset confidential container contract, a confidential container startup verification request is sent to the remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract; wherein the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run;
[0122] If the integrity verification result is passed, the remote authentication server is requested to provide the image file included in the file list in the preset confidential container contract.
[0123] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to: an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device.
[0124] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0125] Program code embodied on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0126] The computer program code for performing the operations of the present invention can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0127] Those skilled in the art will appreciate that the modules or steps of the present invention described above can be implemented using a general-purpose computing device. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computer device, which can then be stored in a storage device and executed by the computing device. Alternatively, they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module. Thus, the present invention is not limited to any specific combination of hardware and software.
[0128] An embodiment of the present disclosure further provides a computer program product, including a computer program, which, when executed by a processor, implements the multi-party computing security verification method provided in any embodiment of the present disclosure.
[0129] In the process of implementation, the computer program product can be written in one or more programming languages or a combination thereof to write computer program code for performing the operations of the present disclosure, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0130] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the concept of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A multi-party computing security verification method, applied to a remote authentication server, characterized in that: include: Obtaining a confidential container startup verification request from a confidential container running end, and determining a confidential container contract associated with the confidential container startup verification request; wherein the confidential container startup verification request is sent by the confidential container running end in response to a startup trigger operation of a confidential container to be started based on a preset confidential container contract, and the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed upon by computing participants of the confidential computing implemented by the image files that can be run; Determine the target computing participants associated with the confidential container contract, and verify the integrity of the confidential container contract based on the pre-configured signature key of each target computing participant; If the integrity verification result is a passed verification, sending the image file corresponding to the image file information included in the file list to the confidential container running end; The image file is a trusted application program that can be run by the confidential container running terminal determined by the target computing participant.
2. The method according to claim 1, characterized in that The generation process of the confidential container contract includes: In a preset container contract configuration interactive interface, obtaining selection operations and signature operations of candidate image files by multiple target computing participants; Determining the executable image file based on the selection operation, and performing signature encryption processing on the executable image file based on the signing operation; The file name and version number of the executable image file that has been processed with signature encryption are used as list information to obtain the file list; After obtaining the list signature operation of each target computing participant on the file list, the generation process of the confidential container contract is completed.
3. The method according to claim 2, characterized in that After the confidential container contract is generated, the method further includes: On the preset signature key configuration page, obtain the signature key configuration operation of each target computing participant; A signature verification key for each target computing participant to verify the integrity of the confidential container contract is determined according to the signature key configuration operation.
4. A multi-party computing security verification method, applied to a confidential container running terminal, characterized in that: include: In response to a startup trigger operation of the confidential container to be started based on a preset confidential container contract, a confidential container startup verification request is sent to a remote authentication server, so that the remote authentication server performs integrity verification on the preset confidential container contract according to a signature key pre-configured by a computing participant associated with the preset confidential container contract; wherein the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed by computing participants of the confidential computing implemented by the image files that can be run; If the integrity verification result is a passed verification, requesting the remote authentication server for the image file included in the file list in the preset confidential container contract; The image file is a trusted application program that can be run by the confidential container running terminal determined by the computing participant.
5. The method according to claim 4, characterized in that After obtaining the image file, the method further includes: Decrypt the computation data using the signature key of each computation participant in the preset confidential container contract to obtain the target data object; Start the confidential container to be started, and run the image file based on the target data object.
6. A multi-party computing security verification device, configured at a remote authentication server, characterized in that: include: A verification request response module is configured to obtain a confidential container startup verification request from a confidential container running terminal and determine a confidential container contract associated with the confidential container startup verification request; wherein the confidential container startup verification request is sent by the confidential container running terminal in response to a startup trigger operation of a confidential container to be started based on a preset confidential container contract, and the confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed upon by computing participants of the confidential computing implemented by the image files that can be run; a contract verification module, configured to determine the target computing participants associated with the confidential container contract and perform integrity verification on the confidential container contract based on the pre-configured signature key of each target computing participant; An image file sending module is used to send the image file corresponding to the image file information included in the file list to the confidential container running end if the verification result of the integrity verification is passed; The image file is a trusted application program that can be run by the confidential container running terminal determined by the target computing participant.
7. A multi-party computing security verification device, configured at a confidential container running end, characterized in that: include: A verification request module is configured to send a confidential container startup verification request to a remote authentication server in response to a startup trigger operation of a confidential container to be started based on a preset confidential container contract, so that the remote authentication server performs integrity verification on the preset confidential container contract based on a signature key pre-configured by a computing participant associated with the preset confidential container contract; wherein the preset confidential container contract includes a file list of image files that can be run in the confidential container to be started, and the file list is information pre-agreed upon by computing participants of the confidential computing implemented by the image files that can be run; An image file pulling module, configured to request the image file included in the file list in the preset confidential container contract from the remote authentication server when the verification result of the integrity verification is passed; The image file is a trusted application program that can be run by the confidential container running terminal determined by the computing participant.
8. A multi-party computing security verification system, characterized in that: include: Confidential container running end and remote authentication server; The confidential container running end is used to implement the multi-party computing security verification method according to claim 4 or 5; The remote authentication server is used to implement the multi-party computing security verification method as described in any one of claims 1-3.
9. A computer device, characterized in that: The computer device comprises: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the multi-party computing security verification method as described in any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the multi-party computing security verification method as described in any one of claims 1 to 5 is implemented.
11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the multi-party computing security verification method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Application program starting method and device, electronic equipment and storage medium
CN114791834A
Verification method and system
CN116401649A