Confidential computing remote verification methods, devices, systems, equipment, media and products
Through the federated collaboration of the computing coordinator and the remote verification server of the participants, the computing environment verification and integrity verification are performed separately, which solves the complexity problem of the central verification server when the confidential computing instance changes, and realizes more efficient and secure confidential computing environment verification.
Patent Information
- Application Number
- CN202510594959.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-05-09
AI Technical Summary
When the hardware, firmware and/or software information associated with a confidential computing instance changes, existing technologies require a central remote verification server to make corresponding configuration changes, increasing the complexity of multi-party confidential computing and trusted data space.
Through the remote verification server of the computing coordinator and the remote verification server of the computing participant in a federal collaborative manner, the computing environment verification and integrity verification are performed separately, reducing the dependence on the central remote verification server, and only performing confidential computing environment verification on the computing platform and the remote verification server of the participant.
It reduces the computational complexity of the central remote verification server, reduces the system complexity when the computing environment changes, and improves the efficiency and security of confidential computing.
Smart Images

Figure CN120128426B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of computer technology, and in particular, to a confidential computing remote verification method, apparatus, system, equipment, medium, and product. Background Art
[0002] In a confidential computing system based on remote authentication, the remote authentication server must save the hardware, firmware, and software information associated with the confidential computing instance to provide verification basis information to the remote authentication server during the security verification process of multi-party confidential computing.
[0003] However, in the process of implementing the present invention, it was found that there are at least the following technical problems in the prior art:
[0004] When the hardware, firmware, and / or software information associated with a confidential computing instance changes, the remote verification server needs to make corresponding configuration changes, which greatly increases the complexity of multi-party confidential computing and trusted data space. Summary of the Invention
[0005] Embodiments of the present invention provide a method, apparatus, system, equipment, medium, and product for remote verification of confidential computing, which can reduce the computational complexity of the remote verification process of confidential computing by completing the remote authentication service of confidential computing in a federally collaborative manner through the remote verification server of the computing coordinator and the remote verification server of the computing participant.
[0006] In a first aspect, an embodiment of the present invention provides a confidential computing remote verification method, which is applied to a remote verification server of a computing coordinator. The method includes:
[0007] In response to a confidential computing instance startup verification request from any confidential computing platform, a verification process for performing security verification on a target confidential computing instance is initiated; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance;
[0008] Verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is pre-configured by each associated computing participant;
[0009] If the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server can perform confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0010] In a second aspect, an embodiment of the present invention provides a confidential computing remote verification method, which is applied to a remote verification server of a computing participant, and the method includes:
[0011] In response to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, the computing environment verification is performed on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result;
[0012] Send the computing environment verification results to the computing coordinator's remote verification server;
[0013] Among them, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0014] In a third aspect, an embodiment of the present invention further provides a confidential computing remote verification device, which is configured on a remote verification server of a computing coordinator, and includes:
[0015] a verification request response module, configured to initiate a verification process for security verification of a target confidential computing instance in response to a verification request initiated by a confidential computing instance of any confidential computing platform; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance verification request; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance;
[0016] an integrity verification module, configured to verify the integrity of an instance configuration file of a target confidential computing instance based on signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each associated computing participant;
[0017] The computing environment verification module is used to send a confidential computing environment verification request to the remote verification server of the participant corresponding to the confidential computing platform when the integrity verification passes, so that the remote verification server of the participant can perform confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0018] In a fourth aspect, an embodiment of the present invention further provides a confidential computing remote verification device, which is configured at a remote verification server of a computing participant, and includes:
[0019] The computing environment verification request response module is used to respond to the confidential computing environment verification request sent by the computing coordinator remote verification server, perform computing environment verification on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information, and obtain the computing environment verification result;
[0020] The verification result feedback module is used to send the computing environment verification results to the computing coordination party remote verification server;
[0021] Among them, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0022] In a fifth aspect, an embodiment of the present invention further provides a confidential computing remote verification system, characterized by comprising:
[0023] The confidential computing platform of the confidential computing participants, the remote verification server of the computing participants, and the remote verification server of the computing coordinator;
[0024] The confidential computing platform is used to trigger the operation of the target confidential computing instance and initiate a confidential computing instance startup verification request to the remote verification server of the computing coordinator;
[0025] The computing coordinator remote verification server is used to respond to the confidential computing instance startup verification request, perform integrity verification on the target confidential computing instance, and initiate a confidential computing environment verification request to the computing participant remote verification server, so as to implement the confidential computing remote verification method applied to the computing coordinator remote verification server provided by any embodiment;
[0026] The remote verification server of the computing participant is used to respond to the confidential computing environment verification request, verify the confidential computing environment of the confidential computing platform, and feedback the verification results to complete the remote verification process of the target confidential computing instance, so as to implement the confidential computing remote verification method applied to the remote verification server of the computing participant provided by any embodiment.
[0027] In a sixth aspect, an embodiment of the present invention further provides a computer device, the computer device comprising:
[0028] one or more processors;
[0029] a memory for storing one or more programs;
[0030] When one or more programs are executed by one or more processors, the one or more processors implement the confidential computing remote verification method provided by any embodiment of the present invention.
[0031] In a seventh aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the remote verification method for confidential computing provided by any embodiment of the present invention is implemented.
[0032] In an eighth aspect, an embodiment of the present disclosure further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the remote verification method for confidential computing as provided in any embodiment of the present invention.
[0033] The embodiments of the above invention have the following advantages or beneficial effects:
[0034] In an embodiment of the present invention, a verification process for performing security verification on a target confidential computing instance is initiated by responding to a verification request initiated by a confidential computing instance of any confidential computing platform; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance verification request; the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; the integrity of the instance configuration file of the target confidential computing instance is verified based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each associated computing participant; if the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which will increase the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The computing environment verification and integrity verification can be separated in a federal collaborative manner through the computing coordinator remote verification server and the computing participant remote verification server. The confidential computing environment information no longer needs to be configured to the central remote verification server, which reduces the complexity of the verification calculation of the central remote verification server. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a flowchart of a confidential computing remote verification method provided by an embodiment of the present invention;
[0036] Figure 2 This is a flowchart of another confidential computing remote verification method provided by an embodiment of the present invention;
[0037] Figure 3 This is a flowchart of another confidential computing remote verification method provided by an embodiment of the present invention;
[0038] Figure 4 This is a schematic diagram of the structure of a confidential computing remote verification device provided by an embodiment of the present invention;
[0039] Figure 5 This is a schematic diagram of the structure of another confidential computing remote verification device provided by an embodiment of the present invention;
[0040] Figure 6 This is a schematic diagram of the structure of a confidential computing remote verification system provided by an embodiment of the present invention;
[0041] Figure 7 This is a schematic diagram of the workflow of a confidential computing remote verification system provided by an embodiment of the present invention;
[0042] Figure 8 It is a structural diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0043] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.
[0044] Figure 1 This is a flowchart of a confidential computing remote verification method applied to a remote verification server of a computing coordinator, provided in an embodiment of the present invention. This embodiment is applicable to confidential computing scenarios, particularly when performing security verification at the startup of a confidential computing instance. The method can be executed by a confidential computing remote verification device configured on the remote verification server of the computing coordinator. The device can be implemented in software and / or hardware and integrated into a computer device with application development capabilities.
[0045] like Figure 1 As shown, the confidential computing remote verification method of this embodiment includes the following steps:
[0046] S110. In response to a verification request initiated by a confidential computing instance of any confidential computing platform, a verification process for security verification of the target confidential computing instance is started.
[0047] A confidential computing instance refers to a specific use case in which confidential computing technology is applied in real-world scenarios to solve specific business problems or implement specific functions by protecting the privacy and confidentiality of data throughout its entire processing lifecycle (including storage, processing, and transmission). An example is the calculation of relevant indicators in a banking system. A confidential computing instance may involve multiple parties, including the instance developer and the providers of one or more data objects used in the instance.
[0048] The target confidential computing instance may be a pre-configured confidential computing instance associated with the confidential computing instance initiation verification request. Pre-configuration can be understood as the pre-configuration of the target confidential computing instance by multiple computing participants involved in the confidential computing instance.
[0049] The confidential computing platform is the confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance. For example, it is the confidential computing platform corresponding to the computing participant running the target confidential computing instance. When a computing participant deploys the confidential computing instance to its corresponding confidential computing platform using the confidential computing configuration file of the target confidential computing instance and the confidential computing instance is started, the confidential computing platform can trigger a confidential computing instance startup verification request and send it to the remote verification server of the computing coordinator.
[0050] The computing coordinator remote verification server is a service system used to assist multiple computing participants in confidential computing to perform security verification on the operation of the target confidential computing instance.
[0051] After receiving the confidential computing instance startup verification request, the computing coordinator's remote verification server will respond to the confidential computing instance startup verification request of the confidential computing platform and start the verification process for the security verification of the target confidential computing instance.
[0052] S120. Verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance.
[0053] The signature key information is pre-configured by each associated computing participant of the target confidential computing instance. It is understood that each associated computing participant mentioned here includes the computing participant running the target confidential computing instance.
[0054] A signing key is used to create digital signatures, verifying the origin and integrity of messages. Signing keys typically come in pairs: a private key for signing and a public key for verifying signatures.
[0055] Each computing participant uses its private key to encrypt the confidential computing instance information or its hash value, generating a digital signature. Anyone can decrypt and verify the signature using the corresponding public key. Successful verification indicates that the target confidential computing instance is indeed associated with the corresponding computing participant and has not been tampered with during transmission.
[0056] S130. When the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0057] In this embodiment, the remote verification server of the computing coordinator differs from the traditional central remote verification server in that it only needs to verify the integrity of the target confidential computing instance. It further triggers the remote verification server of the corresponding participant in the confidential computing platform to verify the confidential computing environment.
[0058] Therefore, if the integrity verification of the target confidential computing instance passes, the computing coordinator's remote verification server will send a confidential computing environment verification request to the participant's remote verification server corresponding to the confidential computing platform. This allows the participant's remote verification server to verify the confidential computing environment of the target confidential computing instance, thus completing the remote verification of the target confidential computing instance.
[0059] The participant remote verification server verifies the confidential computing environment of the target confidential computing instance based on the infrastructure information of the computing environment pre-configured by the corresponding computing participant on the participant remote verification server. This infrastructure information may include various hardware, firmware, and software information of the participant's confidential computing platform.
[0060] After receiving the message that the confidential computing environment has been successfully verified, the remote verification server of the participating party will feedback the message to the confidential computing platform, and the target confidential computing instance can start running.
[0061] If the integrity verification fails, the remote verification server of the computing coordinator will feedback a message to the confidential computing platform, and the target confidential computing instance will exit and will not be run, and will not send a confidential computing environment verification request to the remote verification server of the participant corresponding to the confidential computing platform.
[0062] The technical solution of this embodiment starts a verification process for security verification of the target confidential computing instance by responding to a verification request initiated by a confidential computing instance of any confidential computing platform; wherein, the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance verification request; the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; the integrity of the instance configuration file of the target confidential computing instance is verified based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each associated computing participant; if the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which will increase the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The computing environment verification and integrity verification can be separated in a federal collaborative manner through the computing coordinator remote verification server and the computing participant remote verification server. The confidential computing environment information no longer needs to be configured to the central remote verification server, which reduces the complexity of the verification calculation of the central remote verification server.
[0063] Figure 2 This is a flowchart of a confidential computing remote verification method applied to a remote verification server for a computing coordinator, provided in an embodiment of the present invention. This embodiment, which shares the same inventive concept as the confidential computing remote verification method described in the previous embodiment, further describes the process of configuring verification information for a confidential computing instance. This method can be performed by a confidential computing remote verification device, which can be implemented in software and / or hardware and integrated into a computer device with application development capabilities.
[0064] like Figure 2 As shown, the confidential computing remote verification method of this embodiment includes the following steps:
[0065] S210. On the preset confidential computing instance configuration interaction page, obtain the confidential computing instance file configuration operation of each associated computing participant.
[0066] Among them, the confidential computing instance file configuration operation can be a configuration operation performed by each associated computing participant on the image file that has been reviewed and determined to be able to run in the confidential computing instance, such as entering the computing coordinator's remote authentication server address corresponding to the corresponding image file and the participant's remote verification server address where the confidential computing instance is located.
[0067] In the computing coordinator's remote verification server, the preset confidential computing instance configuration interaction page provides functional controls for configuring the confidential computing instance configuration file. Confidential computing participants can input operations on the provided preset confidential computing instance configuration interaction page, and the computing coordinator's remote verification server receives the response operation. On this page, each participant of the confidential computing instance can open the corresponding preset confidential computing instance configuration interaction page in their respective confidential computing platforms, determine the image file that can be run, and enter the computing coordinator's remote authentication server address corresponding to the image file and the participant's remote verification server address where the confidential computing instance is located to obtain the confidential computing instance configuration file, and digitally sign and encrypt the file.
[0068] S220. According to the confidential computing instance file configuration operation, determine the configuration file of the target confidential computing instance jointly configured and signed by each associated computing participant.
[0069] The configuration file includes the address of the remote verification server of the computing coordinator and the address of the remote verification server of the participant.
[0070] Each participant of the confidential computing instance can open the corresponding preset confidential computing instance configuration interaction page in their respective confidential computing platforms, select and determine the image file that can be run, and enter the computing coordinator's remote authentication server address corresponding to the image file and the participant's remote authentication server address where the confidential computing instance is located to obtain the confidential computing instance configuration file, and digitally sign and encrypt the file.
[0071] S230: On a preset remote verification configuration interaction page, obtain the key configuration operation of each associated computing participant; and determine the signature key of each associated computing participant according to the key configuration operation.
[0072] Among them, the signing key is used to perform integrity verification during the remote verification process of the target confidential computing instance.
[0073] Confidential computing participants can configure their own signature verification keys and other keys in the coordinator's remote authentication server to support integrity verification of confidential computing instance configuration files.
[0074] S240. In response to a verification request initiated by a confidential computing instance of any confidential computing platform, a verification process for security verification of the target confidential computing instance is started.
[0075] Among them, the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; the confidential computing platform is the confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance.
[0076] S250. Verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance.
[0077] The signature key information is pre-configured by each associated computation participant.
[0078] S260. When the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0079] S270. After obtaining the confidential computing environment verification pass message sent by the participant's remote verification server, send the data encryption key of each associated computing participant to the confidential computing platform.
[0080] Once the compute coordinator and remote attestation service provider confirm that the confidential computing platform's computing environment has been verified, they can send the data encryption key of each associated computing participant to the confidential computing platform. When the confidential computing platform runs the target confidential computing instance, it can decrypt and use the data in the verified confidential computing environment, ensuring data security.
[0081] The technical solution of this embodiment is to obtain the confidential computing instance file configuration operation of each associated computing participant on the preset confidential computing instance configuration interaction page; determine the configuration file of the target confidential computing instance jointly configured and signed by each associated computing participant based on the confidential computing instance file configuration operation; obtain the key configuration operation of each associated computing participant on the preset remote verification configuration interaction page; and determine the signature key of each associated computing participant based on the key configuration operation; respond to the confidential computing instance startup verification request of any confidential computing platform, and start the verification process for security verification of the target confidential computing instance; verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; if the integrity verification passes, send a confidential computing environment verification request to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance; after obtaining the confidential computing environment verification pass message sent by the participant remote verification server, send the data encryption key of each associated computing participant to the confidential computing platform. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which will increase the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The computing environment verification and integrity verification can be separated in a federal collaborative manner through the computing coordinator remote verification server and the computing participant remote verification server. The confidential computing environment information no longer needs to be configured to the central remote verification server, which reduces the complexity of the verification calculation of the central remote verification server.
[0082] Figure 3 This flowchart provides a method for remote authentication of confidential computing applied to a remote authentication server for a computing participant, according to an embodiment of the present invention. This embodiment, which shares the same inventive concept as the method for remote authentication of confidential computing described in the preceding embodiments, further illustrates the process by which a remote authentication server for a computing participant performs security authentication of a computing environment. This method can be executed by a remote authentication device for confidential computing configured on the remote authentication server for a computing participant. This device can be implemented using software and / or hardware and integrated into a computer device with application development capabilities.
[0083] like Figure 3 As shown, the confidential computing remote verification method of this embodiment includes the following steps:
[0084] S310. In response to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, the computing environment verification is performed on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result.
[0085] Among them, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0086] After a target confidential computing instance has passed integrity verification on the compute coordinator's remote verification server, it initiates a confidential computing environment verification request. The remote verification server of the computing participant corresponding to the confidential computing platform running the target confidential computing instance then performs confidential computing exchange verification. This means that the remote verification server of the computing participant and the remote verification server of the compute coordinator form a federation to complete the verification process for the target confidential computing instance.
[0087] Confidential computing environment validation is the process of ensuring that the confidential computing platform can provide security functions such as data confidentiality, integrity, and computing trustworthiness as expected. This includes verification at the hardware, firmware, and software levels.
[0088] Computing participants remotely authenticate the server based on pre-configured computing environment information. This means that each confidential computing participant's infrastructure information is configured and registered on the associated computing participant remote authentication server. Any changes to the confidential computing platform's infrastructure only require updates to the computing participant remote authentication server associated with the platform. This eliminates the complex verification and computational process for multiple participants, reducing the security verification and computational costs of the confidential computing system.
[0089] In an optional embodiment, the remote verification server of the computing participant may be provided with a preset computing environment information configuration interaction page. Then, on the preset computing environment information configuration interaction page, the computing environment information configuration operation of the confidential computing platform is obtained; based on the computing environment configuration operation, the computing environment configuration information of the confidential computing platform is determined; wherein the computing environment configuration information includes the hardware information, firmware information, and software information of the confidential computing platform.
[0090] S320: Send the computing environment verification result to the computing coordinator's remote verification server.
[0091] After completing the computing environment verification, the remote verification server of the computing participant sends the verification results to the remote verification server of the computing coordinator. The remote verification server of the computing coordinator can use the corresponding verification tools and public keys to verify and read the remote computing environment verification results, so that the remote verification server of the computing coordinator can promote the subsequent computing instance startup process based on the computing environment verification results.
[0092] The technical solution of this embodiment is to respond to the confidential computing environment verification request sent by the remote verification server of the computing coordinator and verify the computing environment of the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result; and send the computing environment verification result to the remote verification server of the computing coordinator; wherein the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who started the target confidential computing instance. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which increases the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The confidential computing environment verification can be completed by collaborating with the remote verification server of the computing coordinator, that is, the computing environment of the confidential computing platform is verified by the remote verification service of the corresponding computing participant, and the computing environment information does not need to be configured to the central remote verification server, thereby reducing the complexity of the verification calculation of the central remote verification server.
[0093] Figure 4 A structural diagram of a confidential computing remote verification device configured on a remote verification server of a computing coordinator is provided in an embodiment of the present invention. This embodiment can be applied to confidential computing scenarios, especially situations where security verification is performed when a confidential computing instance is started and run. The confidential computing remote verification device can be implemented by software and / or hardware and integrated into a computer terminal device with application development capabilities.
[0094] like Figure 4 The confidential computing remote verification device shown includes: a verification request response module 410, an integrity verification module 420 and a computing environment verification module 430.
[0095] Among them, the verification request response module 410 is used to respond to the verification request initiated by the confidential computing instance of any confidential computing platform, and start the verification process for security verification of the target confidential computing instance; wherein, the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; the confidential computing platform is the confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; the integrity verification module 420 is used to verify the integrity of the instance configuration file of the target confidential computing instance according to the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each associated computing participant; the computing environment verification module 430 is used to send a confidential computing environment verification request to the participant remote verification server corresponding to the confidential computing platform when the integrity verification passes, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0096] The technical solution of this embodiment starts a verification process for security verification of the target confidential computing instance by responding to a verification request initiated by a confidential computing instance of any confidential computing platform; wherein, the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance verification request; the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; the integrity of the instance configuration file of the target confidential computing instance is verified based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each associated computing participant; if the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which will increase the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The computing environment verification and integrity verification can be separated in a federal collaborative manner through the computing coordinator remote verification server and the computing participant remote verification server. The confidential computing environment information no longer needs to be configured to the central remote verification server, which reduces the complexity of the verification calculation of the central remote verification server.
[0097] In an optional embodiment, the confidential computing remote verification device configured on the remote verification server of the computing coordinator further includes an information sending module for:
[0098] After obtaining the confidential computing environment verification pass message sent by the participant's remote verification server, the data encryption key of each associated computing participant is sent to the confidential computing platform.
[0099] In an optional embodiment, the confidential computing remote verification device configured on the remote verification server of the computing coordinator further includes a computing instance configuration module for:
[0100] Before obtaining the confidential computing instance startup verification request, obtain the confidential computing instance file configuration operation of each associated computing participant on the preset confidential computing instance configuration interaction page;
[0101] According to the confidential computing instance file configuration operation, determine the configuration file of the target confidential computing instance that is jointly configured and signed by each associated computing participant;
[0102] The configuration file includes the address of the remote verification server of the computing coordinator and the address of the remote verification server of the participant.
[0103] In an optional embodiment, the confidential computing remote verification device configured on the remote verification server of the computing coordinator further includes a signature key configuration module for:
[0104] On the preset remote verification configuration interaction page, obtain the key configuration operations of each associated computing participant;
[0105] Determine the signature key of each associated computation participant based on the key configuration operation;
[0106] Among them, the signing key is used to perform integrity verification during the remote verification process of the target confidential computing instance.
[0107] The confidential computing remote verification device configured on the computing coordinator remote verification server provided in an embodiment of the present invention can execute the confidential computing remote verification method applied to the computing coordinator remote verification server provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0108] Figure 5 A structural diagram of a confidential computing remote verification device configured on a remote verification server of a computing participant provided in an embodiment of the present invention. This embodiment can be applied to confidential computing scenarios, especially situations where security verification is performed when a confidential computing instance is started and run. The confidential computing remote verification device can be implemented by software and / or hardware and integrated into a computer terminal device with application development capabilities.
[0109] like Figure 5 The confidential computing remote verification device shown includes: a computing environment verification request response module 510 and a verification result feedback module 520.
[0110] Among them, the computing environment verification request response module 510 is used to respond to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, and perform computing environment verification on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result; the verification result feedback module 520 is used to send the computing environment verification result to the remote verification server of the computing coordinator; wherein, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0111] The technical solution of this embodiment is to respond to the confidential computing environment verification request sent by the remote verification server of the computing coordinator and verify the computing environment of the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result; and send the computing environment verification result to the remote verification server of the computing coordinator; wherein the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who started the target confidential computing instance. The technical solution of the embodiment of the present invention solves the problem that the central remote authentication service completes all confidential computing verification calculations, which increases the complexity of multi-party confidential computing and trusted data space when the computing environment changes. The confidential computing environment verification can be completed by collaborating with the remote verification server of the computing coordinator, that is, the computing environment of the confidential computing platform is verified by the remote verification service of the corresponding computing participant, and the computing environment information does not need to be configured to the central remote verification server, thereby reducing the complexity of the verification calculation of the central remote verification server.
[0112] In an optional embodiment, the confidential computing remote verification device configured on the remote verification server of the computing participant further includes a computing environment information configuration module for:
[0113] Before receiving the confidential computing environment verification request, obtain the confidential computing platform's computing environment information configuration operation on the preset computing environment information configuration interaction page;
[0114] Determine the computing environment configuration information of the confidential computing platform based on the computing environment configuration operation;
[0115] Among them, the computing environment configuration information includes the hardware information, firmware information and software information of the confidential computing platform.
[0116] The confidential computing remote verification device configured on the computing coordinator remote verification server provided in an embodiment of the present invention can execute the confidential computing remote verification method applied to the computing coordinator remote verification server provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0117] Figure 6 This is a structural diagram of a confidential computing remote verification system provided by an embodiment of the present invention. This embodiment can be applied to confidential computing scenarios, especially situations where security verification is performed when a confidential computing instance is started and run.
[0118] like Figure 6 As shown, the confidential computing remote verification system includes a confidential computing platform 610 of a confidential computing participant, a computing participant remote verification server 620 and a computing coordinator remote verification server 630.
[0119] The confidential computing platform 610 is used to trigger the execution of the target confidential computing instance and initiate a confidential computing instance startup verification request to the remote verification server of the computing coordinator. The confidential computing platform 610 can also interact with the remote verification server 630 of the computing participants to configure the corresponding platform infrastructure information for confidential computing environment verification. Each computing participant in a confidential computing instance can configure the confidential computing instance configuration file through its corresponding confidential computing platform 610 to obtain the confidential computing instance configuration file.
[0120] The computing coordinator remote verification server 620 is used to respond to the confidential computing instance startup verification request, perform integrity verification on the target confidential computing instance, and initiate a confidential computing environment verification request to the computing participant remote verification server to implement the confidential computing remote verification method provided by any embodiment applied to the computing coordinator remote verification server.
[0121] The computing participant remote verification server 630 is used to respond to the confidential computing environment verification request, verify the confidential computing environment of the confidential computing platform 610, and feedback the verification results to complete the remote verification process of the target confidential computing instance, so as to implement the confidential computing remote verification method applied to the computing participant remote verification server provided by any embodiment.
[0122] Figure 7 This article provides a workflow diagram of a confidential computing remote verification system. Specifically, the confidential computing remote verification process includes the following steps:
[0123] First, multi-party secure computing participants interact with the remote authentication server of the computing coordinator through their respective confidential computing-capable confidential computing platforms to jointly generate and sign a confidential computing instance configuration file. Each participant independently verifies and validates the image file that can be run within the confidential computing instance. Each participant defines the address of the coordinator's remote authentication server and the address of the participant's remote authentication server where the confidential computing instance resides. Each participant independently signs the confidential computing instance configuration file.
[0124] Then, the multi-party secure computing participants jointly configure the coordinator's remote authentication server. One of the participants, or a mutually agreed independent third party, sets up the coordinator's remote authentication server to remotely authenticate the confidential computing instance. Each participant configures their signature verification key and other keys on the coordinator's remote authentication server to support integrity verification of the confidential computing instance configuration file.
[0125] A participant in a confidential computing instance can deploy a confidential computing instance using a confidential computing configuration file. When the deployed confidential computing instance is started, it triggers a verification process on the remote verification server of the computing coordinator. Specifically, the confidential computing instance starts on the participant's confidential computing platform and triggers a remote verification process, requesting verification from the remote verification server of the coordinator.
[0126] The compute coordinator's remote verification server responds to the confidential computing platform's request and initiates the remote verification process. It verifies the signature of the confidential computing instance configuration information based on the key information provided by each participant. If verification fails, it returns a failure message, exits the confidential computing instance, and the process ends. If verification succeeds, it issues a remote verification request for the confidential computing environment based on the compute participant's remote verification server address in the confidential computing instance configuration information.
[0127] After receiving the request, the remote verification server of the computing participant verifies the confidential computing environment based on the information provided by the confidential computing instance. If verification fails, a failure message is returned, the confidential computing instance exits, and the process ends. If successful, remote verification is successful, and the confidential computing instance obtains the key of each participant from the remote verification server of the computing coordinator. These keys can be used to decrypt the confidential data provided by each participant.
[0128] The confidential computing instance obtains the required data from each participant and begins the computation. The confidential computing instance obtains the required data from each participant. It decrypts the data using the key obtained in the previous step. The confidential computing instance uses this data to begin the computation.
[0129] Figure 8 A schematic structural diagram of a computer device provided in an embodiment of the present invention. Figure 8 A block diagram of an exemplary computer device 12 suitable for use in implementing embodiments of the present invention is shown. Figure 8 The computer device 12 shown is only an example and should not limit the functionality and scope of use of the embodiments of the present invention. The computer device 12 can be any terminal device with computing capabilities, such as an intelligent controller, a server, a mobile phone, or other terminal devices.
[0130] like Figure 8 As shown, computer device 12 is implemented as a general-purpose computing device. Components of computer device 12 may include, but are not limited to, one or more processors or processing units 16, system memory 28, and a bus 18 that connects various system components (including system memory 28 and processing unit 16).
[0131] Bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.
[0132] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0133] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache 32. Computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be configured to read and write non-removable, non-volatile magnetic media ( Figure 8 Not shown, usually called a "hard drive"). Although Figure 8 Although not shown, a magnetic disk drive for reading and writing to a removable non-volatile magnetic disk (e.g., a "floppy disk"), as well as an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. System memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments of the present invention.
[0134] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 42 generally implement the functions and / or methodologies of the embodiments described herein.
[0135] The computer device 12 may also communicate with one or more external devices 14 (e.g., a keyboard, a pointing device, a display 24, etc.), one or more devices that enable a user to interact with the computer device 12, and / or any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the computer device 12 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with the other modules of the computer device 12 via the bus 18. It should be understood that although Figure 8 Not shown, other hardware and / or software modules may be used in conjunction with computer device 12, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0136] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the confidential computing remote verification method provided by the embodiment of the present invention for the remote verification server of the computing coordinator, which includes:
[0137] In response to a confidential computing instance startup verification request from any confidential computing platform, a verification process for performing security verification on a target confidential computing instance is initiated; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance;
[0138] Verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is pre-configured by each associated computing participant;
[0139] If the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server can perform confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0140] Alternatively, a confidential computing remote verification method applied to a computing participant remote verification server as provided in any embodiment of the present invention may be implemented, the method comprising:
[0141] In response to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, the computing environment verification is performed on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result;
[0142] Send the computing environment verification results to the computing coordinator's remote verification server;
[0143] Among them, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0144] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the method for remote verification of confidential computing applied to a remote verification server of a computing coordinator as provided in any embodiment of the present invention is implemented. The method includes:
[0145] In response to a confidential computing instance startup verification request from any confidential computing platform, a verification process for performing security verification on a target confidential computing instance is initiated; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance;
[0146] Verify the integrity of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is pre-configured by each associated computing participant;
[0147] If the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server can perform confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance.
[0148] Alternatively, when the program is executed by the processor, the program may also implement a confidential computing remote verification method applied to a computing participant remote verification server as provided in any embodiment of the present invention, the method comprising:
[0149] In response to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, the computing environment verification is performed on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result;
[0150] Send the computing environment verification results to the computing coordinator's remote verification server;
[0151] Among them, the target confidential computing instance is the confidential computing instance associated with the confidential computing environment verification request, and the computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
[0152] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to: an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device.
[0153] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0154] Program code embodied on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0155] The computer program code for performing the operations of the present invention can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0156] Those skilled in the art will appreciate that the modules or steps of the present invention described above can be implemented using a general-purpose computing device. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computer device, which can then be stored in a storage device and executed by the computing device. Alternatively, they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module. Thus, the present invention is not limited to any specific combination of hardware and software.
[0157] An embodiment of the present disclosure also provides a computer program product, including a computer program, which, when executed by a processor, implements the confidential computing remote verification method provided by any embodiment of the present disclosure.
[0158] In the process of implementation, the computer program product can be written in one or more programming languages or a combination thereof to write computer program code for performing the operations of the present disclosure, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0159] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the concept of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A confidential computing remote verification method, applied to a remote verification server of a computing coordination party, characterized in that: include: In response to a confidential computing instance startup verification request from any confidential computing platform, a verification process for performing security verification on a target confidential computing instance is initiated; wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the confidential computing instance startup verification request; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; Performing integrity verification of the instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each of the associated computing participants; the integrity verification is used to confirm that the target confidential computing instance is associated with the associated computing participant and has not been tampered with during transmission; When the integrity verification passes, a confidential computing environment verification request is sent to the participant remote verification server corresponding to the confidential computing platform, so that the participant remote verification server performs confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance; wherein, the confidential computing environment verification is based on the infrastructure information of the computing environment pre-configured by the computing participant of the target confidential computing instance on the participant remote verification server.
2. The method according to claim 1, characterized in that The method further comprises: After obtaining the confidential computing environment verification pass message sent by the participant's remote verification server, the data encryption key of each associated computing participant is sent to the confidential computing platform.
3. The method according to claim 1, characterized in that Before obtaining the confidential computing instance startup verification request, the method further includes: On the preset confidential computing instance configuration interaction page, obtain the confidential computing instance file configuration operation of each associated computing participant; Determining, according to the confidential computing instance file configuration operation, a configuration file of the target confidential computing instance jointly configured and signed by each of the associated computing participants; The configuration file includes the address of the remote verification server of the computing coordinator and the address of the remote verification server of the participant.
4. The method according to claim 3, characterized in that The method further comprises: On a preset remote verification configuration interaction page, obtaining the key configuration operation of each of the associated calculation participants; Determining the signature key of each of the associated computation participants according to the key configuration operation; The signature key is used to perform integrity verification during the remote verification process of the target confidential computing instance.
5. A confidential computing remote verification method, applied to a remote verification server of a computing participant, characterized in that: include: In response to the confidential computing environment verification request sent by the remote verification server of the computing coordinator, the computing environment verification is performed on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information to obtain the computing environment verification result; Sending the computing environment verification result to the computing coordinator remote verification server; The target confidential computing instance is a confidential computing instance associated with the confidential computing environment verification request, and the target confidential computing instance has undergone integrity verification at the remote verification server of the computing coordinator; The computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
6. The method according to claim 5, characterized in that Before obtaining the confidential computing environment verification request, the method further includes: On the preset computing environment information configuration interaction page, obtain the computing environment information configuration operation of the confidential computing platform; Determining computing environment configuration information of the confidential computing platform according to the computing environment configuration operation; Among them, the computing environment configuration information includes the hardware information, firmware information and software information of the confidential computing platform.
7. A confidential computing remote verification device, configured at a remote verification server of a computing coordination party, characterized in that: include: A verification request response module is configured to initiate a verification process for a target confidential computing instance in response to a verification request initiated by a confidential computing instance of any confidential computing platform, wherein the target confidential computing instance is a pre-configured confidential computing instance associated with the verification request initiated by the confidential computing instance; and the confidential computing platform is a confidential computing platform corresponding to one of the associated computing participants of the target confidential computing instance; an integrity verification module, configured to verify the integrity of an instance configuration file of the target confidential computing instance based on the signature key information corresponding to the target confidential computing instance; wherein the signature key information is information pre-configured by each of the associated computing participants; and the integrity verification is used to confirm that the target confidential computing instance is associated with the associated computing participant and has not been tampered with during transmission; A computing environment verification module is used to send a confidential computing environment verification request to the participant remote verification server corresponding to the confidential computing platform when the integrity verification passes, so that the participant remote verification server can perform confidential computing environment verification on the target confidential computing instance to complete the remote verification of the target confidential computing instance; wherein, the confidential computing environment verification is based on the infrastructure information of the computing environment pre-configured by the computing participant of the target confidential computing instance on the participant remote verification server.
8. A confidential computing remote verification device, configured at a remote verification server of a computing participant, characterized in that: include: The computing environment verification request response module is used to respond to the confidential computing environment verification request sent by the computing coordinator remote verification server, perform computing environment verification on the confidential computing platform corresponding to the target confidential computing instance according to the pre-configured computing environment information, and obtain the computing environment verification result; A verification result feedback module is used to send the computing environment verification result to the computing coordination party remote verification server; The target confidential computing instance is a confidential computing instance associated with the confidential computing environment verification request, and the target confidential computing instance has undergone integrity verification at the remote verification server of the computing coordinator; The computing environment information is the computing environment information of the confidential computing platform of the computing participant who starts the target confidential computing instance.
9. A confidential computing remote verification system, characterized in that: include: The confidential computing platform of the confidential computing participants, the remote verification server of the computing participants, and the remote verification server of the computing coordinator; The confidential computing platform is used to trigger the operation of the target confidential computing instance and initiate a confidential computing instance startup verification request to the remote verification server of the computing coordinator; The computing coordinator remote verification server is used to respond to the confidential computing instance startup verification request, perform integrity verification on the target confidential computing instance, and initiate a confidential computing environment verification request to the computing participant remote verification server, so as to implement the confidential computing remote verification method according to any one of claims 1 to 4; The computing participant remote verification server is used to respond to the confidential computing environment verification request, verify the confidential computing environment of the confidential computing platform, and feedback the verification results to complete the remote verification process of the target confidential computing instance, so as to implement the confidential computing remote verification method as described in claim 5 or 6.
10. A computer device, characterized in that: The computer device comprises: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the confidential computing remote verification method as described in any one of claims 1-6.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the confidential computing remote verification method as described in any one of claims 1 to 6 is implemented.
12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the confidential computing remote verification method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Multi-faceted compute instance identity
CN107113300A
Control of access to computing resources implemented in isolated environment
CN118159967A