Method and system for secure software delivery
By using encrypted data files and policy files in air-isolated computing devices, combined with a trusted execution environment and a portable storage device, security control over the software transmission process is achieved, malware attacks are solved, and data security and access rights are ensured.
Patent Information
- Application Number
- CN202380081571.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-29
- Filing Date
- 2023-11-29
- Publication Date
- 2025-07-08
AI Technical Summary
Existing air isolation computing devices are susceptible to malware attacks during software transmission, and traditional encryption methods are difficult to effectively protect data security.
Using the method of encrypting data files and policy files, the encryption key is stored using a trusted execution environment, and transmitted through a portable storage device, the destination server decrypts and access control based on the policy information and keys.
Improves data security of air-isolated computing devices during software transmission, prevents malware attacks, and ensures that only authorized devices and users can access encrypted data.
Smart Images

Figure CN120283220A_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims the benefit of and priority to U.S. Provisional Patent Application No. 63 / 385,377, filed on November 29, 2022, the entire disclosure of which is incorporated herein by reference.
[0003] Background
[0004] Air - gapped machines typically include computing systems or servers that are physically disconnected (air gap open) from other machines or networks and thus prevent attempts at remote attacks against the air - gapped machines. Conventional software or data delivery methods for air - gapped systems involve using portable storage devices to transfer data between computing systems. These methods rely on encrypting the data before storing it on the portable storage device, and public - key / private - key pairs for decrypting and accessing the data, which are protected either manually or by relying on access controls. Traditional encryption systems support operations where data is encrypted in such a way that it can only be decrypted by a user with a unique decryption key. For symmetric - key encryption systems, such as the Advanced Encryption Standard (AES), the encryption and decryption keys are the same, and every effort must be made to prevent the key from being leaked to an adversary, which would allow the adversary to gain the ability to decrypt and access sensitive data. For public - key encryption systems, such as RSA, a pair of public and private keys is used, such that once data is encrypted with the public key, it can only be decrypted with its corresponding private key. If an adversary obtains the public key, the adversary still cannot decrypt the data. However, individual computing devices are still vulnerable to software attacks, such as malware attacks. These computing devices can be compromised, where the malware may gain access to the device and access the keys used to decrypt the associated data.
[0005] Overview
[0006] It should be understood that the following general description and the following detailed description are merely exemplary and explanatory and not restrictive.
[0007] This document describes methods, systems, and apparatuses for providing secure software delivery. A secure build server can be configured to encrypt one or more software artifacts (e.g., data files, container images, bioinformatics data such as genomic, epigenomic, and / or proteomic data from patient test samples, etc.) into an encrypted data file, and encrypt a first key and a policy file associated with the encrypted data file. The policy file can include policy information for authenticating access to the encrypted data file. The secure build server can store the encrypted first key via a trusted execution environment and store the encrypted data file and the policy file via a portable storage device. A destination server can access the portable storage device to receive the encrypted data file, the encrypted policy file, and the encrypted first key. The destination server can use a second key to decrypt the encrypted software application, the encrypted policy file, and the encrypted first key. The destination server can authenticate the software application based on the policy information and use the software application and the first key to decrypt the encrypted data file and access one or more software artifacts.
[0008] In an embodiment, a method is disclosed that includes encrypting, by a first computing device, one or more software artifacts into an encrypted data file, encrypting an encryption key and a policy file associated with the encrypted data file, where the policy file includes policy information for authenticating access to the encrypted data file, storing the encrypted encryption key via a trusted execution environment of the first computing device, and storing the encrypted data file and the policy file via a portable storage device, where a second computing device accesses the encrypted data file via a software application of the second computing device authenticated based on the encryption key and the policy information.
[0009] In an embodiment, a method is disclosed that includes: receiving, by a computing device, an encrypted data file, an encrypted policy file, and an encrypted first encryption key, decrypting the encrypted software application, the encrypted policy file, and the encrypted first encryption key based on a second encryption key, where the policy file includes policy information for authenticating access to the encrypted data file, authenticating the software application based on the policy information, decrypting the encrypted data file based on the authentication of the software application and based on the first encryption key via the software application, and accessing one or more software artifacts based on the decrypted data file.
[0010] In an embodiment, a system including a first computing device and a second computing device is disclosed. The first computing device includes a trusted execution environment. The first computing device is configured to encrypt one or more software artifacts into an encrypted data file, encrypt a first encryption key associated with the encrypted data file and a policy file, where the policy file includes policy information for authenticating access to the encrypted data file, store the encrypted first encryption key via the trusted execution environment, store the encrypted data file and the policy file via a portable storage device. The second computing device is configured to decrypt the encrypted software application, the encrypted policy file and the encrypted first encryption key based on a second encryption key, authenticate the software application based on the policy information, decrypt the encrypted data file via the software application based on the authentication of the software application and based on the first encryption key, and access the one or more software artifacts based on the decrypted data file.
[0011] The various steps of the methods disclosed herein or the steps performed by the systems disclosed herein can be performed at the same time or different times, and / or at the same geographical location or different geographical locations (e.g., countries). The various steps of the methods disclosed herein can be performed by the same person / entity or different persons / entities.
[0012] Additional advantages will be set forth in part in the description that follows, or may be learned by practice. These advantages will be realized and attained by the elements and combinations particularly pointed out in the appended claims. Brief Description of the Drawings
[0014] The drawings incorporated in and forming a part of this specification are used to explain the principles of the methods and systems described herein:
[0015] Figure 1 An example system is shown;
[0016] Figure 2 An example scenario is shown;
[0017] Figure 3 An example encryption / decryption process is shown;
[0018] Figure 4 An example encryption / decryption process is shown;
[0019] Figure 5 A flowchart of an example method is shown; and
[0020] Figure 6 A flowchart of an example method is shown.
[0021] Detailed Description
[0022] As used in this specification and the appended claims, unless the context clearly dictates otherwise, the singular forms "a", "an", and "the" include plural referents. Ranges may be expressed herein as from "about" one particular value and / or to "about" another particular value. When such a range is expressed, another configuration includes from one particular value and / or to another particular value. Similarly, when values are expressed as approximations by use of the antecedent "about", it will be understood that the particular value forms another configuration. It will be further understood that each of the endpoints of each range is significant with respect to the other endpoint and independent of the other endpoint.
[0023] "Optional" or "optionally" means that the subsequently described event or circumstance may or may not occur, and that the description includes instances where the event or circumstance occurs and instances where it does not.
[0024] Throughout the description and claims of this specification, the word "comprise" and variations of the word such as "comprising" and "comprises" mean "including but not limited to", and are not intended to exclude, for example, other components, integers, or steps. "Exemplary" means "an example of...", and is not intended to convey an indication of a preferred or ideal configuration. "Such as" is used in a non-limiting sense, for purposes of explanation.
[0025] It should be understood that when combinations, subsets, interactions, groups, etc. of components are described, although specific references to each various individual and collective combinations and permutations of these components may not be explicitly described, each of them is specifically contemplated and described herein. This applies to all parts of this application, including but not limited to the steps in the methods described. Thus, if there are a variety of additional steps that can be performed, it should be understood that each of these additional steps can be performed by any particular configuration or combination of configurations of the methods described.
[0026] As will be understood by those skilled in the art, implementation may be in hardware, software, or a combination of software and hardware. Additionally, the methods and systems may take the form of a computer program product on a computer-readable storage medium (e.g., non-transitory), having processor-executable instructions (e.g., computer software) embodied in the storage medium. Any suitable computer-readable storage medium may be utilized, including hard disks, CD-ROMs, optical storage devices, magnetic storage devices, memristors, non-volatile random access memory (NVRAM), flash memory, or combinations thereof.
[0027] Throughout this application, reference is made to block diagrams and flowcharts. It will be understood that each block in the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by processor-executable instructions. These processor-executable instructions can be loaded onto a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the processor-executable instructions executed on the computer or other programmable data processing apparatus create a device for implementing the functions specified in the block or blocks of the flowchart.
[0028] These processor-executable instructions can also be stored in a computer-readable memory, which can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the processor-executable instructions stored in the computer-readable memory produce an article of manufacture including the processor-executable instructions for implementing the functions specified in the block or blocks of the flowchart. The processor-executable instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus, thereby producing a computer-implemented process, such that the processor-executable instructions executed on the computer or other programmable apparatus provide the steps for implementing the functions specified in the block or blocks of the flowchart.
[0029] The blocks of the block diagrams and flowcharts support combinations of devices for performing the specified functions, combinations of steps for performing the specified functions, and combinations of program instruction means for performing the specified functions. It should also be understood that each block in the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by a special-purpose hardware-based computer system that performs the specified functions or steps, or by a combination of special-purpose hardware and computer instructions.
[0030] Figure 1Shows an example system 100 for secure software transfer. In the example, some or all steps of any of the described methods can be performed on a computing device as described herein. The system can include a first computing device 101, a second computing device 102, and an electronic device 103. The first computing device 101 can include a server computing device (e.g., a security build server). For example, the first computing device 101 can include a digital computer. The digital computer can include a memory 110, one or more input / output (I / O) interfaces 120, a processor 122, and one or more network interfaces 124. The memory 110, one or more input / output (I / O) interfaces 120, the processor 122, and one or more network interfaces 124 can communicate with each other via a local interface 118. The local interface 118 can include one or more buses or other wired or wireless connections. The local interface 118 can include additional elements, such as controllers, buffers (caches), drivers, repeaters, and receivers, which are omitted for simplicity, to enable communication. The local interface 118 can also include address, control, and / or data connections to enable proper communication between the memory 110, one or more input / output (I / O) interfaces 120, the processor 122, and one or more network interfaces 124.
[0031] One or more I / O interfaces 120 can include one or more interfaces for receiving user input from one or more devices or components and / or for providing system output to one or more devices or components. User input can be provided via, for example, a keyboard and / or a mouse. System output can be provided via a display device and a printer (not shown). The I / O interface 120 can include, for example, a serial port, a parallel port, a Small Computer System Interface (SCSI), an Infrared (IR) interface, a Radio Frequency (RF) interface, and / or a Universal Serial Bus (USB) interface. In the example, at least one of the one or more I / O interfaces 120 can be configured to connect to the electronic device 103. The electronic device 103 can include a portable storage device, which includes one or more of a USB storage device, a Secure Digital storage device, a mobile device, a smart phone, a tablet computer, or any other computing device capable of communicating with the first computing device 101 and / or the second computing device 102 and storing data / information.
[0032] Processor 122 may be a hardware device for executing software, particularly software that may be stored in memory 110. Processor 122 may be any custom or commercially available processor, a central processing unit (CPU), an auxiliary processor among several processors associated with the first computing device 101, a semiconductor-based microprocessor (in the form of a microchip or chipset), or any device commonly used to execute software instructions. When the first computing device 101 is running, processor 122 may be configured to execute software stored within memory 110, transfer data to and from memory 110, and generally control the operation of the first computing device 101 according to the software. In an example, processor 122 may further include a trusted execution environment that includes hardware-based memory encryption (e.g., Intel Software Guard Extensions (SGX) CPU). The trusted execution environment may be used to store keys for encrypting / decrypting data. For example, the first computing device 101 may generate a public-private key pair for encrypting / decrypting data. The first computing device 101 may store the public key via the trusted execution environment and store the private key via a portable storage device (e.g., USB storage device, secure digital storage device). In an example, the first computing device 101 may be configured to send the private key to a destination server via a secure backhaul network.
[0033] One or more network interfaces 124 may be used to send and receive data from the first computing device 101 via a network (e.g., intranet, extranet, Internet, secure backhaul network, etc.). Network interface 124 may include, for example, a 10BaseT Ethernet adapter, a 100BaseT Ethernet adapter, a LAN PHY Ethernet adapter, a token ring adapter, a wireless network adapter (e.g., WiFi, cellular, satellite), or any other suitable network interface device. One or more network interfaces 124 may include addresses, controls, and / or data connections to enable proper communication on the network.
[0034] Memory 110 may include any one or combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, hard disk drive, magnetic tape, CDROM, DVDROM, etc.). Additionally, memory 110 may incorporate electronic, magnetic, optical, and / or other types of storage media. Note that memory 110 may have a distributed architecture where various components are located remotely from each other but may be accessed by processor 122.
[0035] The software in the memory 110 may include one or more software programs, each software program including an ordered list of executable instructions for implementing logical functions. The software in the memory system 110 of the first computing device 101 may include an operating system (O / S) 112, an encryption program 114, and software artifact data 116. The operating system 112 may control the execution of other computer programs and provide scheduling, input / output control, file and data management, memory management, and communication control, as well as related services. For example, the first computing device 101 may receive one or more software artifacts (e.g., data files, container images, or bioinformatics data) and store the one or more software artifacts as software artifact data 116 in the memory 110. One or more software artifacts of the software artifact data 116 may be encrypted by the encryption program 114 into an encrypted data file, where the first computing device 101 may cause the encrypted data file to be stored at the electronic device 103. The first computing device 101 may generate a public-private key (e.g., asymmetric encryption) associated with the encrypted data file. The first computing device 101 may encrypt the public key and store the public key in a trusted execution environment, and encrypt the private key and cause the encrypted private key to be stored at the electronic device 103. Additionally, the first computing device 101 may generate policy information associated with the encrypted data file. The policy information may include information for authenticating a receiving device (e.g., a destination server) or an individual to authorize access to the encrypted data file. For example, the policy information may include one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software or encryption key information authorized to access the encrypted data file. The first computing device 101 may encrypt the policy information into an encrypted policy file and cause the policy file to be stored at the electronic device 103. In an example, the first computing device 101 may also include a third-party software policy manager that generates the policy information. In an example, before providing access to the encrypted data file to the second computing device 102, the first computing device 101 may pre-share the encrypted policy file with the second computing device 102 via, for example, another electronic device or a secure backhaul network. In an example, the first computing device 101 may associate signed code with the policy information and the encrypted data file for verifying the encrypted data file.
[0036] The second computing device 102 may include a server computing device (e.g., a destination server). For example, the second computing device 102 may include a digital computer. The digital computer may include a memory 126, one or more input / output (I / O) interfaces 134, a processor 136, and one or more network interfaces 138. The memory 126, one or more input / output (I / O) interfaces 134, the processor 136, and one or more network interfaces 138 may communicate with each other via a local interface 132. The local interface 132 may include one or more buses or other wired or wireless connections. The local interface 132 may include additional elements, such as controllers, buffers (caches), drivers, repeaters, and receivers, which are omitted for simplicity, to enable communication. The local interface 132 may also include address, control, and / or data connections to enable appropriate communication among the memory 126, one or more input / output (I / O) interfaces 134, the processor 136, and one or more network interfaces 138.
[0037] One or more I / O interfaces 134 may include one or more interfaces for receiving user input from one or more devices or components and / or for providing system output to one or more devices or components. User input may be provided via, for example, a keyboard and / or a mouse. System output may be provided via a display device and a printer (not shown). The I / O interface 134 may include, for example, a serial port, a parallel port, a Small Computer System Interface (SCSI), an Infrared (IR) interface, a Radio Frequency (RF) interface, and / or a Universal Serial Bus (USB) interface. In an example, at least one of the one or more I / O interfaces 120 may be configured to connect to an electronic device 103 for accessing an encrypted data file, an encrypted policy file, and / or an encrypted private key.
[0038] The processor 136 can be a hardware device for executing software, particularly software that can be stored in the memory 126. The processor 136 can be any custom or commercially available processor, a central processing unit (CPU), an auxiliary processor among several processors associated with the second computing device 102, a semiconductor-based microprocessor (in the form of a microchip or chipset), or any device commonly used to execute software instructions. When the second computing device 102 is operating, the processor 136 can be configured to execute software stored within the memory 126, transfer data to and from the memory 126, and generally control the operation of the second computing device 102 according to the software. In an example, the processor 136 can also include a trusted execution environment that includes hardware-based memory encryption (e.g., Intel Software Guard Extensions (SGX) CPU). The trusted execution environment can be used to store authentication keys associated with a user of the second computing device 102 (e.g., Secure Shell (SSH) keys). For example, a user of the second computing device 102 can provide user input to the second computing device 102 via the I / O interface 134 to request an authentication key. The second computing device 102 can generate a decryption key via the trusted execution environment and store the decryption key. In an example, the SSH key can be generated by a third-party application / device and provided to the second computing device 102. In an example, the authentication key can be valid only for a period of time (e.g., 10 minutes, 1 hour, 1 week, etc.).
[0039] One or more network interfaces 138 can be used to send and receive data from the second computing device 102 via a network (e.g., intranet, extranet, Internet, etc.). The network interface 138 can include, for example, a 10BaseT Ethernet adapter, a 100BaseT Ethernet adapter, a LAN PHY Ethernet adapter, a token ring adapter, a wireless network adapter (e.g., WiFi, cellular, satellite), or any other suitable network interface device. One or more network interfaces 138 can include addresses, controls, and / or data connections to enable proper communication on the network.
[0040] The memory 126 can include any one or combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, hard disk drive, magnetic tape, CDROM, DVDROM, etc.). Additionally, the memory 126 can incorporate electronic, magnetic, optical, and / or other types of storage media. Note that the memory 126 can have a distributed architecture where various components are located far from each other but can be accessed by the processor 136.
[0041] The software in the memory 126 can include one or more software programs, each software program including an ordered list of executable instructions for implementing logical functions. The software in the memory system 126 of the second computing device 102 can include an operating system (O / S) 128 and software applications 130. The operating system 128 can control the execution of other computer programs and provide scheduling, input / output control, file and data management, memory management, and communication control, as well as related services. For example, the second computing device 102 can access encrypted data files, encrypted policy files, and / or encrypted private keys via the electronic device 103. The second computing device 102 can use the stored decryption keys to decrypt the encrypted policy files and encrypted private keys. In an example, when the second computing device 102 initially receives the software application 130, for example, via a third-party device, the software application 130 can initially be encrypted. The second computing device 102 can decrypt the encrypted software application 130 based on an authentication key. The second computing device 102 can authenticate the software application based on policy information. The second computing device 102 can use the authenticated software application to decrypt the encrypted data files based on the private keys. In an example, signed code can be associated with the policy information and / or the encrypted data files. The second computing device 102 can also verify the encrypted data files based on the associated signed code. The second computing device 102 can access one or more software artifacts based on the decrypted data files. In an example, the second computing device 102 can store one or more software artifacts in a secure location.
[0042] As Figure 1As shown, application programs and other executable program components, such as operating systems 112 / 128, are depicted as discrete blocks. However, it should be recognized that such programs and components may reside in different storage components of the first computing device 101 and / or the second computing device 102 at different times. For example, encryption program 114 and / or software application 130 may be stored on or transmitted via some form of computer-readable medium. Any of the disclosed methods may be performed by computer-readable instructions embodied on a computer-readable medium. A computer-readable medium may be any available medium that can be accessed by a computer. For example, a computer-readable medium may include "computer storage media" and "communication media". "Computer storage media" may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. In an example, computer storage media may include RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical storage devices, magnetic cassettes, magnetic tape, magnetic disk storage devices or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0043] Figure 2An example scenario for securely transferring software is shown, where a first computing device 101 (e.g., a secure build server) can provide an encrypted data file, an encrypted policy file, and an encrypted private key to a second computing device 102 (e.g., a destination server) via an electronic device 103 (e.g., a portable storage device such as a USB storage device, a secure digital storage device, etc.). The second computing device can decrypt the encrypted data file and access the content of the data file based on the policy file and the private key. The first computing device 101 can receive one or more software artifacts 210 (e.g., data files, container images, or bioinformatics data). The first computing device can encrypt the software artifact into an encrypted data file 230 and associate a signed code with the encrypted data file 230. Additionally, the first computing device 101 generates and encrypts a policy file 212 and a private key 214 associated with the encrypted data file 230. In an example, the first computing device 101 can generate a public-private key (e.g., asymmetric encryption) associated with the encrypted data file 230. The first computing device 101 can encrypt the public key (e.g., via the trusted execution environment of the first computing device 101) and store the encrypted public key, and encrypt the private key and store the encrypted private key at the electronic device 103. The second computing device 102 can access the encrypted and signed data file 230 and the encrypted policy file 232 via the electronic device 103. The second computing device 102 receives and stores an authentication key 224 (e.g., an SSH key) associated with a user of the second computing device 102. For example, a user can provide an input requesting an authentication key, where the authentication key can be generated, for example, by the second computing device 102 or a third-party device. The authentication key can be valid only for a period of time (e.g., 10 minutes, 1 hour, 1 week, etc.). The authentication key 224 can be used to decrypt the encrypted software application, the encrypted policy file, and the encrypted private key 232. For example, the second computing device 102 can receive an encrypted software application, where the software application 226 can be used to decrypt the encrypted data file 230. The second computing device 102 can authenticate the software application 226 based on the policy file 222. The second computing device 102 can use the authenticated software application 226 to decrypt the encrypted data file according to the private key 228. The second computing device 102 can access one or more software artifacts based on the decrypted data file 220.
[0044] Figure 3Shows an example process for securely transferring software. At 302, a first computing device 101 (e.g., a secure build server) can encrypt one or more software artifacts (e.g., data files, container images, or bioinformatics data) into an encrypted data file. At 304, the first computing device 101 can generate and encrypt a private key and a policy file associated with the encrypted data file. The policy file can include policy information for authenticating access to the encrypted data file. The policy information can include one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software or encryption key information authorized to access the encrypted data file. In an example, the first computing device 101 can generate a public-private key pair (e.g., asymmetric encryption) associated with the encrypted data file. The first computing device 101 can store the public key via a trusted execution environment of the first computing device 101 (e.g., hardware-based memory encryption such as an Intel SGX CPU). At 306, the first computing device 101 can cause the encrypted data file, the encrypted private key, and the encrypted policy file to be stored via an electronic device 103 (e.g., a portable storage device such as a USB storage device, a secure digital storage device, etc.). At 308, a second computing device 102 (e.g., a destination server) can access the encrypted data file, the encrypted private key, and the encrypted policy file via the electronic device 103. At 310, the second computing device 102 can decrypt the encrypted private key, the encrypted policy file, and the encrypted software application based on an authentication key associated with a user of the second computing device 102 (e.g., an SSH key). For example, the authentication key can be generated based on a user request. At 312, the second computing device 102 can authenticate the software application based on the policy information. At 314, the second computing device 102 can use the authenticated software application to decrypt the encrypted data file based on the private key and access one or more software artifacts. In an example, the second computing device 102 can store one or more software artifacts in a secure location.
[0045] Figure 4 Shows an example process for securely transferring software. Steps 402 and 404 are similar to Figure 3Steps 302 and 304. However, additional step 406 may be included, where the first computing device 101 may send the encrypted policy file directly to the second computing device 102. For example, the first computing device 101 may send the policy file to the second computing device 102 via a secure backhaul network. At 408, the first computing device 101 may cause the encrypted data file and the encrypted private key to be stored via the electronic device 103. At 410, the second computing device 102 may access the encrypted data file and the encrypted private key via the electronic device 103. Steps 412, 414, and 416 are respectively similar to Figure 3 Steps 310, 312, and 314.
[0046] Figure 5 FIG. shows a flowchart of an example method 500. The method 500 may be implemented by the first computing device 101, the second computing device 102, the electronic device 103, any combination thereof, or any other suitable device. At step 510, one or more software artifacts may be encrypted into an encrypted data file. For example, one or more software artifacts may be encrypted into an encrypted data file by the first computing device 101. The first computing device 101 may include a secure build server. One or more software artifacts may include one or more of a data file, a container image, or bioinformatics data.
[0047] At step 520, the key and the policy file associated with the encrypted data file may be encrypted. For example, the key and the policy file associated with the encrypted data file may be encrypted by the first computing device 101. For example, the key and the policy file may be generated by the first computing device 101 based on the encrypted data file. The key may include a private key that may be used to decrypt the encrypted data file. In an example, the first computing device 101 may generate a public key and a private key based on the encrypted data file (e.g., a public-private key pair based on asymmetric encryption). The policy file may include policy information for authenticating access to the encrypted data file. The policy information may include one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software or encryption key information authorized to access the encrypted data file. In an example, the first computing device 102 may associate the signature code with the policy information and the encrypted data file.
[0048] At step 530, the encrypted key may be stored via the trusted execution environment of the first computing device 101. The trusted execution environment may include hardware-based memory encryption (e.g., Intel Software Guard Extensions (SGX) CPU).
[0049] In step 540, the encrypted data file and the policy file can be stored via a portable storage device. For example, the first computing device 101 can cause the encrypted data file and the policy file to be stored via the portable storage device. The portable storage device can be external to the first computing device 101 and the second computing device 102, and can include one or more of a USB storage device or a Secure Digital storage device. In an example, the second computing device 101 can access the encrypted data file via a software application of the second computing device. The software application can be authenticated based on a key and policy information. For example, the second computing device 102 can access the portable storage device to receive the encrypted data file and the encrypted policy file. The second computing device 102 can include a second trusted execution environment that includes hardware-based memory encryption (e.g., Intel Software Guard Extensions (SGX) CPU). The second computing device 102 can store an authentication key associated with a user of the second computing device 102 via the trusted execution environment. The second computing device 102 can decrypt the encrypted software application, the encrypted policy file, and the encrypted key based on the authentication key. The second computing device 102 can authenticate the software application based on the policy information of the policy file. The second computing device 102 can use the software application to decrypt the encrypted data file based on the authentication of the software application and based on the key, and access one or more software artifacts.
[0050] Figure 6 A flowchart of an example method 600 is shown. The method 600 can be implemented by the first computing device 101, the second computing device 102, the electronic device 103, any combination thereof, or any other suitable device. In step 610, an encrypted data file, an encrypted policy file, and an encrypted first key can be received. For example, the second computing device 102 can receive the encrypted data file, the encrypted policy file, and the encrypted first key. The second computing device 102 can include a destination server. The second computing device 102 can receive the encrypted data file, the encrypted policy file, and the encrypted first key from a secure build server (e.g., the first computing device 101) via a portable storage device. The portable storage device can be external to the second computing device 102 and the first computing device 101, and can include one or more of a USB storage device or a Secure Digital storage device.
[0051] As an example, the first computing device 101 can encrypt one or more software artifacts into an encrypted data file. Additionally, the first computing device 101 can encrypt a first key (e.g., a private key), a public key, and a policy file. The first computing device 101 can cause the encrypted data file, the encrypted first key, and the encrypted policy file to be stored via a portable storage device. In the example, the first computing device can associate the signed code with the policy information and the encrypted data file. In the example, the first computing device 101 can pre-share (e.g., send) the encrypted policy file to the second computing device 102 via a secure backhaul network or network path.
[0052] In step 620, the software application, the encrypted policy file, and the encrypted first key can be decrypted based on a second key. For example, the software application, the encrypted policy file, and the encrypted first key can be decrypted by the second computing device 102 based on the second key. For example, when the second computing device 102 initially receives the software application, e.g., via a third-party device, the software application can initially be encrypted. In the example, the second computing device 102 can include a trusted execution environment that includes hardware-based memory encryption (e.g., Intel Software Guard Extensions (SGX) CPU). The second computing device 102 can store an authentication key (e.g., the second key) associated with a user of the second computing device 102 via the trusted execution environment. The policy file can include policy information for authenticating access to the encrypted data file. The policy information can include one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software or encryption key information authorized to access the encrypted data file.
[0053] In step 630, for example, the software application can be authenticated based on the policy information. For example, the software application can be authenticated by the second computing device 102 based on the policy information.
[0054] In step 640, the encrypted data file can be decrypted via the software application based on the authentication of the software application and based on the first key. For example, the second computing device can decrypt the encrypted data file via the software application based on the authentication of the software application and based on the first key. In the example, the encrypted data file can be verified by the second computing device 102 based on the signed code associated with the policy information and the encrypted data file. The encrypted data file can be decrypted based on the verification of the encrypted data file.
[0055] In step 650, one or more software artifacts may be accessed based on the decrypted data file. For example, one or more software artifacts may be accessed by computing device 102 based on the decrypted data file. The one or more software artifacts may include: one or more software artifacts including one or more of a data file, a container image, or bioinformatics data.
[0056] Although the methods and systems have been described in connection with preferred embodiments and specific examples, it is not intended to limit the scope to the specific embodiments set forth, as the embodiments herein are intended to be illustrative in all respects and not restrictive.
[0057] Unless otherwise expressly stated, it is in no way intended that any method set forth herein be construed as requiring that its steps be performed in a specific order. Accordingly, where a method claim does not actually recite an order to be followed by its steps or where no order is otherwise specifically set forth in the claim or description, no order is to be inferred in any respect. This applies to any possible non - explicit basis for interpretation, including: logical issues of arrangement or operational flow of steps; simple meaning derived from grammatical organization or punctuation; the number or type of embodiments described in the specification.
[0058] It will be apparent to those skilled in the art that various modifications and variations can be made without departing from the scope or spirit. Considering the specification and practice disclosed herein, other embodiments will be apparent to those skilled in the art. It is intended that the specification and examples be considered only as exemplary, with the true scope and spirit of the invention being indicated by the appended claims.
Claims
1. A method, comprising: encrypting, by a first computing device, one or more software artifacts into an encrypted data file; encrypting a key and a policy file associated with the encrypted data file, wherein the policy file includes policy information for authenticating access to the encrypted data file; storing the encrypted key via a trusted execution environment of the first computing device; and storing the encrypted data file and the policy file via a portable storage device, wherein a second computing device accesses the encrypted data file via a software application of the second computing device authenticated based on the key and the policy information.
2. The method according to claim 1, wherein, The first computing device includes a security build server, and the second computing device includes a destination server.
3. The method according to any one of claims 1-2, wherein The one or more software artifacts include one or more of a data file, a container image, or bioinformatics data.
4. The method according to any one of claims 1-3, wherein, The policy information includes one or more of the following: identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information.
5. The method according to any one of claims 1-4, further comprising associating signed code with the policy information and the encrypted data file.
6. The method according to any one of claims 1-5, wherein The trusted execution environment includes hardware-based memory encryption.
7. The method according to any one of claims 1-6, wherein The portable storage device includes one or more of a USB storage device or a secure digital storage device.
8. The method according to any one of claims 1-7, wherein, The portable storage device is external to the first computing device and the second computing device.
9. The method according to any one of claims 1-9, wherein, The second computing device decrypts the encrypted key and the encrypted policy file based on a second key associated with the second computing device.
10. A method, comprising: receiving, by a computing device, an encrypted data file, an encrypted policy file, and an encrypted first key; decrypting, based on a second key, an encrypted software application, the encrypted policy file, and the encrypted first key, wherein the policy file includes policy information for authenticating access to the encrypted data file; authenticating the software application based on the policy information; decrypting the encrypted data file via the software application based on the authentication of the software application and based on the first key; and accessing one or more software artifacts based on the decrypted data file.
11. The method according to claim 10, wherein, The computing device includes a destination server, wherein the destination server receives the encrypted data file, the encrypted policy file, and the encrypted first key from a security build server.
12. The method according to any one of claims 10 - 11, wherein, The computing device receives the encrypted data file, the encrypted policy file, and the encrypted first key via a portable storage device.
13. The method according to claim 12, wherein, The portable storage device includes one or more of a USB storage device or a secure digital storage device.
14. The method according to claim 12, wherein, The portable storage device is external to the computing device.
15. The method according to any one of claims 10-14, wherein, The second key is stored via a trusted execution environment of the computing device.
16. The method according to claim 15, wherein, The trusted execution environment includes hardware-based memory encryption.
17. The method according to any one of claims 10-16, wherein, The policy information includes one or more of the following: identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information.
18. The method according to any one of claims 10-17, wherein, The one or more software artifacts include one or more of a data file, a container image, or bioinformatics data.
19. The method according to any one of claims 10-18, further comprising verifying the encrypted data file based on signed code associated with the policy information and the encrypted data file.
20. The method according to claim 19, wherein, Decrypt the encrypted data file based on the verification of the encrypted data file.
21. A system, comprising: A first computing device including a trusted execution environment, wherein the first computing device is configured to: Encrypt one or more software artifacts into an encrypted data file; Encrypt a first key and a policy file associated with the encrypted data file, wherein the policy file includes policy information for authenticating access to the encrypted data file; Store the encrypted first key via the trusted execution environment; And Store the encrypted data file and the encrypted policy file via a portable storage device; And A second computing device configured to: Decrypt the encrypted software application, the encrypted policy file, and the encrypted first key based on a second key; Authenticate the software application based on the policy information; Decrypt the encrypted data file via the software application based on the authentication of the software application and based on the first key; And Access the one or more software artifacts based on the decrypted data file.
22. The system according to claim 21, wherein, The first computing device includes a security build server, and the second computing device includes a destination server.
23. The system according to any one of claims 21-22, wherein, The trusted execution environment includes hardware-based memory encryption.
24. The system according to any one of claims 21-23, wherein, The one or more software artifacts include one or more of a data file, a container image, or bioinformatics data.
25. The system according to any one of claims 21-24, wherein, The policy information includes one or more of the following: identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information.
26. The system according to any one of claims 21-25, wherein The first computing device is further configured to associate signed code with the policy information and the encrypted data file.
27. The system according to claim 26, wherein, The second computing device is further configured to verify the encrypted data file based on the signed code associated with the policy information and the encrypted data file.
28. The system according to claim 27, wherein, The second computing device is further configured to decrypt the encrypted data file based on the verification of the encrypted data file.
29. The system according to any one of claims 21-28, wherein, The portable storage device includes one or more of a USB storage device or a secure digital storage device.
30. The system according to any one of claims 21-29, wherein The portable storage device is external to the first computing device and the second computing device.
31. The system according to any one of claims 21-30, wherein, The second computing device is further configured to receive the encrypted data file and the policy file via the portable storage device.
32. The system according to any one of claims 21-31, wherein, The second computing device includes a second trusted execution environment, wherein the second computing device is further configured to store the second key via the second trusted execution environment.