An Encryption Communication Method and System for a Trusted Execution Environment
By deploying server agents and external client agents in a trusted execution environment, negotiating session keys for encrypted communication, the transmission link security problem is solved, and automatic encrypted transmission and low-cost deployment of outbound data is realized.
Patent Information
- Application Number
- CN202510623589.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-05-15
AI Technical Summary
The existing trusted execution environment ignores the security of the transmission link during data transmission, resulting in the outbound data being easily stolen or tampered with, and security vulnerabilities exist.
Deploy the server agent in a trusted execution environment, deploy the client agent externally, the client agent negotiates the session key with the server agent, and use the session key for encrypted communication to realize the automatic encrypted transmission of the outbound data.
It realizes automatic encrypted transmission of outbound data in a trusted execution environment, avoids security vulnerabilities such as data theft or tampering, and reduces the deployment cost of encrypted communications, and improves the transparency and compatibility of the system.
Smart Images

Figure CN120151113B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of trusted computing technology, and particularly to an encryption communication method and system for a trusted execution environment. Background Art
[0002] With the development of cloud computing and big data technologies, data security and privacy protection are particularly important, especially during data transmission and storage. As a physically isolated environment, the "trusted computing" ability of a trusted execution environment can effectively prevent malicious access in scenarios with strict requirements for data privacy and security (such as finance, healthcare, government affairs, etc.). However, TEE systems generally focus on protecting the internal data processing logic and ignore the security of the transmission link, which may result in security vulnerabilities due to the theft or tampering of out-of-domain data.
[0003] Therefore, the existing technologies still need to be improved. Summary of the Invention
[0004] The technical problem to be solved by this application is to provide an encryption communication method and system for a trusted execution environment in view of the deficiencies of the existing technologies.
[0005] To solve the above technical problem, in the first aspect of this application, an encryption communication method for a trusted execution environment is provided. A server proxy is deployed inside the trusted execution environment, and a client proxy is deployed outside the trusted execution environment. The encryption communication method for the trusted execution environment specifically includes:
[0006] The client proxy receives a connection request and establishes a connection with the server proxy when the connection request is received.
[0007] The client proxy negotiates a session key with the server proxy.
[0008] The client proxy uses the session key to perform encrypted communication with the server proxy to achieve automatic encrypted transmission of out-of-domain data in the trusted execution environment.
[0009] In the encryption communication method for the trusted execution environment, the establishment of a connection between the client proxy and the server proxy specifically is:
[0010] The client proxy creates a connection instance through an event callback and establishes a connection with the server proxy through the connection instance.
[0011] In the encryption communication method for the trusted execution environment, the negotiation of the session key between the client proxy and the server proxy specifically includes:
[0012] The client proxy sends a client public key to the server proxy.
[0013] The client agent receives the server public key sent by the server agent and verifies the server public key. Wherein, the server agent verifies the client public key when receiving the client public key, and generates a session key when the verification of the client public key passes;
[0014] The client agent receives the session key generated by the server agent, and after the verification of the server public key passes, uses the session key to conduct encrypted communication with the server agent.
[0015] The encrypted communication method for the trusted execution environment, wherein the negotiation of the session key between the client agent and the server agent further includes:
[0016] The server agent receives the client public key sent by the client agent;
[0017] The agent of the service verifies the client public key;
[0018] When the verification of the client public key passes, the server agent sends the server public key to the client agent.
[0019] The encrypted communication method for the trusted execution environment, wherein the session key is the session key generated by the server agent using the SM4 encryption algorithm.
[0020] The encrypted communication method for the trusted execution environment, wherein the client agent and the server agent conduct encrypted communication using the session key to implement the encryption of the transmission data in the trusted execution environment, specifically including:
[0021] The client agent obtains the original data sent by the client, and encrypts the original data using the session key to form the first ciphertext data;
[0022] The client agent sends the first ciphertext data to the server agent, decrypts the first ciphertext data through the server agent, and sends the decrypted original data to the target service.
[0023] The encrypted communication method for the trusted execution environment, wherein the client agent and the server agent conduct encrypted communication using the session key to implement the encryption of the transmission data in the trusted execution environment further includes:
[0024] The client agent receives the second ciphertext data encrypted by the server agent using the session key, decrypts the second ciphertext data using the session key, and sends the decrypted server data to the request side corresponding to the connection request.
[0025] The described encrypted communication method for a trusted execution environment, wherein the transmission data between the client agent and the server agent is encapsulated using a TLV structure.
[0026] The described encrypted communication method for a trusted execution environment, wherein before the client agent receives a connection request and establishes a connection with the server agent when the connection request is received, the method further includes:
[0027] When the client agent starts, the client agent reads its corresponding listening port and target address from a configuration file and listens for request information for the listening port, wherein the target address is used to determine the target service.
[0028] The second aspect of the present application provides an encrypted communication system for a trusted execution environment, wherein a server agent is deployed inside the trusted execution environment, and a client agent is deployed outside the trusted execution environment;
[0029] The client agent is used to establish a connection with the server agent when receiving request information sent by a client;
[0030] The server agent is used to negotiate a session key with the client agent;
[0031] The client agent is further used to perform encrypted communication with the server agent using the session key to achieve encryption of the transmission data in the trusted execution environment.
[0032] Beneficial effects: Compared with the prior art, the present application provides an encrypted communication method and system for a trusted execution environment. The method includes that the client agent receives a connection request and establishes a connection with the server agent when the connection request is received; the client agent negotiates a session key with the server agent; the client agent performs encrypted communication with the server agent using the session key to achieve automatic encrypted transmission of the out-of-domain data in the trusted execution environment. By setting a server agent inside the trusted execution environment and a client agent outside the trusted execution environment, negotiating a session key through the server agent and the client agent, and performing encrypted communication using the negotiated session key, the present application not only realizes automatic encrypted transmission of the out-of-domain data in the trusted execution environment, avoiding security vulnerabilities caused by theft or tampering of the out-of-domain data. At the same time, it is not necessary to modify the original code of the trusted execution environment, reducing the deployment cost of the encrypted communication in the trusted execution environment. Description of the Drawings
[0033] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0034] Figure 1 It is a schematic block diagram of the encrypted communication system of the trusted execution environment provided by the embodiments of the present application.
[0035] Figure 2 It is a flowchart of the encrypted communication method of the trusted execution environment provided by the embodiments of the present application.
[0036] Figure 3 It is a timing diagram of a specific example of the encrypted communication method of the trusted execution environment provided by the embodiments of the present application. Detailed implementation manners
[0037] The embodiments of the present application provide an encrypted communication method and system for a trusted execution environment. To make the purpose, technical solutions and effects of the present application clearer and more definite, the following further details the present application with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0038] Those skilled in the art of this technology can understand that unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.
[0039] Those skilled in the art of this technology can understand that unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the field to which the present application belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.
[0040] It should be understood that the sequence numbers and magnitudes of the steps in this embodiment do not indicate the order of execution. The order of execution of each process is determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0041] Through research, it is found that with the development of cloud computing and big data technologies, data security and privacy protection are particularly important, especially during data transmission and storage. As a physically isolated environment, the trusted execution environment can effectively prevent malicious access in scenarios with strict requirements for data privacy and security (such as finance, healthcare, government affairs, etc.) due to its "trusted computing" ability. However, TEE systems generally focus on protecting the internal data processing logic and ignore the security of the transmission link, which may lead to security vulnerabilities due to the theft or tampering of data leaving the domain.
[0042] To solve the above problems, in the embodiments of the present application, a server proxy is deployed inside the trusted execution environment, and a client proxy is deployed outside the trusted execution environment. The client proxy receives a connection request and establishes a connection with the server proxy when the connection request is received; the client proxy negotiates a session key with the server proxy; the client proxy uses the session key to perform encrypted communication with the server proxy to achieve automatic encrypted transmission of the data leaving the domain of the trusted execution environment. In the embodiments of the present application, the server proxy and the client proxy perform a session key protocol and encrypted communication, which can not only achieve automatic encrypted transmission of the data leaving the domain of the trusted execution environment, but also reduce the deployment cost of encrypted communication. At the same time, the server proxy and the client proxy in the embodiments of the present application are both independent modules and can be accessed without modifying the business logic of the trusted execution environment, improving the transparency and compatibility of the encrypted communication system of the trusted execution environment, making it have good platform compatibility and reducing the intrusion and maintenance workload on the original system.
[0043] The following further illustrates the application content by describing the embodiments in conjunction with the accompanying drawings.
[0044] An application environment diagram of an encrypted communication method for a trusted execution environment provided in this embodiment can be as Figure 1 shown. Referring to Figure 1, a server proxy is deployed inside the trusted execution environment, and a client proxy is deployed outside the trusted execution environment. The client proxy communicates with the server proxy. Among them, the client proxy is used to receive a connection request sent by the client, establish a connection with the server proxy when the connection request is received, the client proxy is used to negotiate a session key with the server proxy, and after the session key negotiation is completed, the client proxy is further used to encrypt the original data sent by the client with the session key and send the encrypted ciphertext data to the server proxy. The server proxy is used to decrypt the ciphertext data with the session key to obtain the original plaintext data and send the restored original data to the server.
[0045] As Figure 2 and Figure 3 described above, the encryption communication method of the trusted execution environment provided by the embodiments of the present application specifically includes:
[0046] S10. The client proxy receives the connection request and establishes a connection with the server proxy when the connection request is received.
[0047] Specifically, the client proxy is deployed outside the trusted execution environment and is used to listen for connection requests for the trusted execution environment, and the connection request is sent by the client. For example, the client proxy listens for connection requests sent by a browser or an application. Among them, the connection request includes a listening port and a target address. The listening port is used to determine the service entry of the client proxy, and the target address is the address of the host where the server proxy is located, that is, the internal service address of the trusted execution environment to which the ciphertext data encrypted by the client proxy needs to be forwarded. The client proxy can determine the target service corresponding to the connection request and the service entry corresponding to the target service according to the listening port and the target address in the connection request.
[0048] Furthermore, in practical applications, the server can be composed of multiple service units (such as multiple privacy computing units, etc.) included in the trusted execution environment, or can be composed of the trusted execution environment, etc. Among them, each trusted execution environment can be configured with one listening port or multiple listening ports. For this reason, in order to support parallel communication for multiple listening ports, the client proxy supports multi-port listening, that is, the client proxy can start multiple listening ports at the same time to enable the client proxy to listen for connection requests for the listening ports of one trusted execution environment, or listen for connection requests for the listening ports of multiple trusted execution environments.
[0049] Based on this, before the client proxy receives the connection request and establishes a connection with the server proxy when the connection request is received, the method further includes:
[0050] When the client proxy starts, the client proxy reads its corresponding listening port and target address from the configuration file, and listens for request information for the listening port, where the target address is used to determine the target service.
[0051] Specifically, the configuration file of the client proxy is configured with a listening port and a target address, and the client proxy can simultaneously open all the listening ports configured in its configuration file. For example, if the configuration file of the client proxy is configured with five listening ports, then the client proxy can simultaneously open these five listening ports to simultaneously listen to these five listening ports. Among them, the multiple listening ports simultaneously opened by the client proxy can be multiple listening ports configured for a trusted execution environment, or can be listening ports configured for multiple trusted execution environments, that is, the client proxy can correspond to one server proxy or multiple server proxies, and when corresponding to multiple server proxies, it can simultaneously listen to connection requests for multiple server proxies. In this way, the server proxy corresponding to the client proxy can be dynamically configured by configuring the configuration file in the client proxy, so that the encrypted communication method of the trusted execution environment provided by the implementation of this application can be applied to various application scenarios.
[0052] Further, after the client proxy receives a connection request, it will establish a connection with the server proxy. Among them, the client proxy can directly send a connection request to the server proxy to establish a connection, or can establish an asynchronous connection with the server proxy through a connection instance. In the embodiment of this application, the establishment of a connection between the client proxy and the server proxy is specifically:
[0053] The client proxy creates a connection instance through an event callback, and establishes a connection with the server proxy through the connection instance.
[0054] Specifically, when the client proxy receives a connection request, that is, when a client establishes a connection with the client proxy, the client proxy will create a connection instance (that is, a Connection instance) through an event callback, and asynchronously establish a server proxy connection through the connection instance. Among them, a TCP connection can be established between the client proxy and the server proxy using the TCP protocol, etc. Of course, when the client proxy creates a connection instance through an event callback, it will determine the listening port and target address corresponding to the connection request, and add the listening port and target address to the connection instance, so as to facilitate determining the server proxy to be connected based on the listening port and target address. This application establishes a connection with the server proxy through event-driven and combines it with the client proxy starting multiple listening ports simultaneously through multi-threading, which can meet the requirements of large-scale concurrent communication.
[0055] S20. The client proxy negotiates a session key with the server proxy.
[0056] Specifically, after the client proxy establishes a connection with the server proxy, the client proxy will negotiate a session key with the server proxy to determine the session key used for communication between the client proxy and the server proxy. The session key is used to encrypt the transmission data between the client proxy and the server proxy, so as to enable encrypted communication between the client proxy and the server proxy. Among them, the SM4 session key can be used as the session key to perform efficient symmetric encryption on the transmission data between the client proxy and the server proxy, so as to improve the security of the transmission data between the client proxy and the server proxy.
[0057] Exemplarily, the negotiation of the session key between the client proxy and the server proxy specifically includes:
[0058] The client proxy sends the client public key to the server proxy;
[0059] The client proxy receives the server public key sent by the server proxy and verifies the server public key. Among them, the server proxy verifies the client public key when it receives the client public key, and generates a session key when the verification of the client public key passes;
[0060] The client proxy receives the session key generated by the server proxy, and uses the session key to perform encrypted communication with the server proxy after the verification of the server public key passes.
[0061] Specifically, after the client proxy establishes a connection with the server proxy, the client proxy will send the client public key it uses to the server proxy and request the server proxy to send the server public key it uses. Among them, the client public key is the SM2 public key certificate in front of the client proxy, and the server public key is the SM2 public key certificate in front of the server proxy.
[0062] Further, when the server proxy receives the client public key, it verifies the client public key and generates a session key when the verification of the client public key passes. Among them, when the server proxy receives the client public key of the client proxy, it can first feedback the server public key it uses to the client proxy, and then verify the received client public key and feedback the verification result after the verification is completed; it can also be to first verify the client public key, send the server public key to the client proxy when the verification passes, and feedback verification failure or directly discard the client public key when the verification fails, so that the client proxy determines that the session key negotiation fails after receiving the verification failure or not receiving the server public key within the preset time. Of course, in practical applications, the verification of the client public key and the sending of the server public key can be two independent processes. Specifically, the client proxy sends a request message to the server proxy at the same time as or after sending the client public key. The server proxy verifies the client public key after receiving it, and the server proxy sends the server public key to the client proxy after receiving the request message.
[0063] In the embodiment of the present application, the negotiation of the session key between the client proxy and the server proxy further includes:
[0064] The server proxy receives the client public key sent by the client proxy;
[0065] The proxy of the service verifies the client public key;
[0066] When the verification of the client public key passes, the server proxy sends the server public key to the client proxy.
[0067] Specifically, after the server proxy receives the client public key and the request message, the server proxy can verify the client public key based on the request message. Among them, the verification process of the client public key can be performed locally on the server proxy or through a remote interface to be verified by a remote server.
[0068] Exemplarily, such as Figure 3As shown, the verification process of the client public key by the server proxy and the verification process of the server public key by the client proxy can both be executed by a remote service. That is to say, both the server proxy and the client proxy connect to the remote service (such as a remote CA or TEE certificate center service, etc.) by calling a remote interface, and then send the server public key and the client public key to the remote service. The remote service verifies the server public key and the client public key, and can also perform certificate revocation, etc. The verification process of the server public key and the client public key by the remote service is the same. Here, the verification process of the client public key is taken as an example for illustration. Specifically, the verification process of the client public key by the remote service can be as follows: After receiving the client public key, the server proxy calls the remote interface to connect to the remote service and sends the client public key to the remote service. The remote service verifies the client public key. If the verification passes, the remote server sends the client public key back to the server proxy to inform the server proxy that the verification of the client public key has passed; if the verification fails, the remote service can directly discard the client public key. In the embodiment of the present application, the client public key is verified by calling a remote interface, so that the server proxy can access a remote CA or TEE certificate center service, and perform key authentication and certificate revocation, etc. through the remote CA or TEE certificate center, further improving the security of communication between the client proxy and the server proxy.
[0069] Furthermore, when the verification of the client public key passes, the server proxy generates a session key based on the client public key encryption. Among them, the session key can be a randomly generated SM4 session key. Specifically, the server proxy can randomly generate a session key through the SM4 encryption algorithm after the verification of both the server public key and the client public key passes, and then encrypt the session key with the client public key to obtain the encrypted session key, and send the encrypted session key to the client proxy. After receiving the encrypted session key, the client proxy can decrypt the encrypted session key with the client private key corresponding to the client public key to obtain the session key, and use the session key to encrypt the transmission data between the client proxy and the server proxy. Of course, in practical applications, the server proxy can also execute the session key generation process after successfully verifying the client public key received by it, and send the generated session key encrypted with the client public key to the client proxy; after the verification of the server public key by the client proxy, the client proxy decrypts the encrypted session key, and uses the decrypted session key to encrypt the transmission data between the client proxy and the server proxy, etc.
[0070] When the client proxy and the server proxy negotiate the session key in the embodiment of the present application, the client proxy will verify the server public key signed by the server proxy, and the server proxy will verify the client public key signed by the client proxy. Only after both the server public key and the client public key pass the verification, a two-way trusted link will be established between the client proxy and the server proxy, and the session key generated through negotiation will be used for encryption and decryption on the two-way trusted link, realizing the construction of a two-way trusted link through a strong encryption algorithm and a key negotiation mechanism, ensuring the confidentiality and integrity of data during transmission.
[0071] S30. The client proxy uses the session key to perform encrypted communication with the server proxy to realize the automatic encrypted transmission of the out-of-domain data of the trusted execution environment.
[0072] Specifically, the session key is used to encrypt and decrypt the transmission data on the two-way trusted link established between the client proxy and the server proxy. That is to say, before transmitting data through the two-way trusted link, the session key will be used to encrypt the original data to be transmitted, and then the encrypted ciphertext data will be transmitted through the two-way trusted link. Finally, the session key will be used to decrypt the ciphertext data to obtain the original plaintext data.
[0073] Exemplarily, the client proxy and the server proxy use the session key to perform encrypted communication to realize the encryption of the transmission data of the trusted execution environment, which specifically includes:
[0074] The client proxy obtains the original data sent by the client and encrypts the original data with the session key to form the first ciphertext data.
[0075] The client proxy sends the first ciphertext data to the server proxy, decrypts the first ciphertext data through the server proxy, and sends the decrypted original data to the target service.
[0076] Specifically, the original data is the data that the client needs to transmit to its corresponding target service. The client will first send the original data to the client proxy, and the client proxy will encrypt the original data with the session key to obtain the first ciphertext data. Then, the first ciphertext data will be transmitted to the server proxy through the two-way trusted link between the client proxy and the server proxy. After receiving the first ciphertext data, the server proxy will decrypt the first ciphertext data with the session key to obtain the original plaintext data, and transmit the original plaintext data to the target service to realize the encryption of the transmission data of the trusted execution environment.
[0077] Exemplarily, the encryption communication between the client proxy and the server proxy using the session key to implement the encryption of the transmission data in the trusted execution environment further includes:
[0078] The client proxy receives the second ciphertext data encrypted by the server proxy using the session key, decrypts the second ciphertext data using the session key, and sends the decrypted server data to the request end corresponding to the connection request.
[0079] Specifically, when the target service needs to send data to the client, the target service sends the server data that needs to be sent to the server proxy. The server proxy encrypts the server data using the session key to obtain the second encrypted data. The server proxy sends the second encrypted data to the client proxy through the two-way trusted link between the server proxy and the client proxy. After receiving the second ciphertext data, the client proxy decrypts the second ciphertext data using the session key to obtain the plaintext server data, and sends the plaintext server data to the client.
[0080] In one embodiment, in order to further reduce the intrusion into the original system and the maintenance workload, in addition to the encryption and decryption operations being completed on the client proxy and the server proxy, the protocol encapsulation operation is also completed on the client proxy and the server proxy. That is to say, after the client proxy and the server proxy perform encryption and decryption using the session key, they will also perform protocol encapsulation operations on the encrypted ciphertext data or the decrypted plaintext data. Specifically, the transmission data between the client proxy and the server proxy is encapsulated using the TLV structure. That is, after the client proxy and the server proxy encrypt and decrypt the transmission data using the session key, they will package the data structure through the TLV protocol, so that the original business application does not need to perceive the existence of the security mechanism.
[0081] In summary, this embodiment provides an encryption communication method for a trusted execution environment. This embodiment provides an encryption communication system for a trusted execution environment. As Figure 1 shown, a server proxy is deployed inside the trusted execution environment, and a client proxy is deployed outside the trusted device;
[0082] The client proxy is used to establish a connection with the server proxy when receiving the request information sent by the client;
[0083] The server proxy is used to negotiate a session key with the client proxy;
[0084] The client proxy is also used to perform encryption communication with the server proxy using the session key to implement the encryption of the transmission data in the trusted execution environment.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An encryption communication method for a trusted execution environment, characterized in that A server proxy is deployed inside the trusted execution environment, and a client proxy is deployed outside the trusted execution environment; The encryption communication method of the trusted execution environment specifically includes: The client proxy receives a connection request and establishes a connection with the server proxy when the connection request is received; The client proxy negotiates a session key with the server proxy; The client proxy uses the session key to perform encrypted communication with the server proxy to achieve automatic encrypted transmission of the out-of-domain data of the trusted execution environment; Among them, the establishment of a connection between the client proxy and the server proxy is specifically: The client proxy creates a connection instance through an event callback and establishes a connection with the server proxy through the connection instance. When the client proxy creates a connection instance through an event callback, it determines the listening port and target address corresponding to the connection request, and adds the listening port and target address to the connection instance to facilitate determining the server proxy to be connected based on the listening port and target address; Among them, the client proxy and the server proxy use the session key to perform encrypted communication to achieve encryption of the transmission data of the trusted execution environment, which specifically includes: The client proxy obtains the original data sent by the client and encrypts the original data with the session key to form the first ciphertext data; The client proxy sends the first ciphertext data to the server proxy through the two-way trusted link between the client proxy and the server proxy. The server proxy decrypts the first ciphertext data and sends the decrypted original data to the target service to achieve encryption of the transmission data of the trusted execution environment.
2. The encrypted communication method for a trusted execution environment according to claim 1, wherein The negotiation of the session key between the client proxy and the server proxy specifically includes: The client proxy sends the client public key to the server proxy; The client proxy receives the server public key sent by the server proxy and verifies the server public key. The server proxy verifies the client public key when it receives the client public key and generates a session key when the client public key verification passes; The client proxy receives the session key generated by the server proxy and uses the session key to perform encrypted communication with the server proxy after the server public key verification passes.
3. The encrypted communication method for a trusted execution environment according to claim 2, wherein The negotiation of the session key between the client proxy and the server proxy further includes: The server proxy receives the client public key sent by the client proxy; The server proxy verifies the client public key; When the client public key verification passes, the server proxy sends the server public key to the client proxy.
4. The encrypted communication method for a trusted execution environment according to claim 2, characterized in that, The session key is the session key generated by the server proxy using the SM4 encryption algorithm.
5. The encryption communication method of the trusted execution environment according to claim 1, characterized in that, The client proxy and the server proxy use the session key to perform encrypted communication to achieve encryption of the transmission data of the trusted execution environment, which further includes: The client proxy receives the second ciphertext data encrypted by the server proxy using the session key, decrypts the second ciphertext data using the session key, and sends the decrypted server data to the request side corresponding to the connection request.
6. The encrypted communication method for a trusted execution environment according to claim 1, wherein The data transmitted between the client agent and the server agent is encapsulated in a TLV structure.
7. The encrypted communication method for a trusted execution environment according to claim 1, wherein Before the client agent receives a connection request and establishes a connection with the server agent when the connection request is received, the method further includes: When the client agent is started, the client agent reads its corresponding listening port and target address from the configuration file, and listens for request information for the listening port, where the target address is used to determine the target service.
8. An encrypted communication system for a trusted execution environment, characterized in that, A server agent is deployed inside the trusted execution environment, and a client agent is deployed outside the trusted execution environment; When the client agent is used to receive request information sent by the client, it establishes a connection with the server agent; The server agent is used to negotiate a session key with the client agent; The client agent is further used to perform encrypted communication with the server agent using the session key to implement encrypted transmission of data in the trusted execution environment; Among them, the establishment of a connection between the client agent and the server agent is specifically: The client agent creates a connection instance through event callback, and establishes a connection with the server agent through the connection instance. When the client agent creates a connection instance through event callback, it determines the listening port and target address corresponding to the connection request, and adds the listening port and target address to the connection instance to facilitate determining the server agent to be connected based on the listening port and target address; Among them, the implementation of encrypted transmission of data in the trusted execution environment by performing encrypted communication between the client agent and the server agent using the session key specifically includes: The client agent obtains the original data sent by the client, and encrypts the original data using the session key to form the first ciphertext data; The client agent sends the first ciphertext data to the server agent through the two-way trusted link between the client agent and the server agent. The server agent decrypts the first ciphertext data and sends the decrypted original data to the target service to implement encrypted transmission of data in the trusted execution environment.
Citation Information
Patent Citations
Pluggable intelligent financial auditing platform
CN113114632A
Business processing method and device
CN119583077A
Methods and systems for verifying a worker agent
US12238213B1
Business processing methods, and apparatuses
WO2025044529A1