Data interaction method and device, server and storage medium
By generating intermediate certificates in a trusted execution environment and using secure communication protocols, combined with the blockchain identity authentication system, the problem of root certificate leakage in the federated learning system is solved, and data security sharing and system security improvement are achieved.
Patent Information
- Application Number
- CN202510333755.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-25
AI Technical Summary
In the existing federated learning system, CA root certificates are prone to being leaked or attacked, resulting in security issues in account password sharing and difficulty in data traceability.
Generate intermediate certificates in a trusted execution environment, create authentication interfaces through secure communication protocols, use blockchain identity authentication system to perform membership authentication, and data encryption transmission based on intermediate certificates to prevent root certificate leakage and unauthorized access.
Improve the security of root certificates, prevent root certificates from leaking or attacking, enhance the security of the federated learning system, and realize secure data sharing.
Smart Images

Figure CN120378114A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a data interaction method, a data interaction device, a server, and a storage medium based on a trusted execution environment. Background Art
[0002] Joint data analysis is a technology for multi-party collaborative data analysis and calculation, usually including technologies such as Federated Learning (FL), Secure Multi-party Computation (MPC), and Trusted Execute Environment (TEE).
[0003] In the prior art, the federated learning system is usually jointly maintained by multiple members of federated learning. However, the method of jointly maintaining and using a federated learning database with shared account passwords is prone to security problems such as account leakage, or the problem of inability to trace the source after data is updated. Joint data analysis usually adopts privacy computing as the data cooperation mode among parties, and encrypts data during data transmission and interaction among parties in federated learning. Therefore, the federated learning system needs to store the CA root certificate to authenticate and encrypt the data of each party. If the CA root certificate is directly stored in the system disk or database that can be accessed arbitrarily and the CA root certificate is frequently used to authenticate the certificates of terminals, there may be security risks caused by root certificate leakage or attack. Summary of the Invention
[0004] In view of the above, it is necessary to provide a data interaction method based on a trusted execution environment, which is used to store the root certificate in the trusted execution environment, prevent the root certificate from being leaked or attacked by creating an intermediate certificate and a security authentication interface, realize the secure sharing of certificate issuance and data interaction in the federated learning system, and improve the overall security of the federated learning system.
[0005] To achieve the above object, the present invention provides a data interaction method based on a trusted execution environment, including:
[0006] Construct a trusted execution environment in the server, generate an intermediate certificate based on the root certificate in the trusted execution environment, and create an authentication interface for the trusted execution environment based on a secure communication protocol;
[0007] Receive an identity authentication request of a federated learning member node sent by a terminal to the server, call the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and if the review fails, generate a rejection notice and send it to the terminal;
[0008] If the review is passed, the identity information of the terminal is obtained and sent to the trusted execution environment through the authentication interface, an identity authentication signature certificate of the terminal is generated based on the intermediate certificate, the identity authentication signature certificate and the authentication information are stored in the database of the blockchain identity authentication system, the terminal is added as a new federated learning member node, and the identity authentication signature certificate is returned to the terminal;
[0009] When a federated learning request is received, the identity authentication signature certificate of the federated learning member node that initiates the federated learning request is obtained for verification. After the verification is passed, multiple federated learning member nodes corresponding to the federated learning request are obtained from all federated learning member nodes, and a federated learning task is created for the multiple federated learning member nodes according to the federated learning request. The interaction data between the federated learning member nodes in the federated learning task is encrypted and transmitted based on the intermediate certificate.
[0010] Optionally, generating an intermediate certificate based on a root certificate in the trusted execution environment includes:
[0011] Generating a root key pair in the trusted execution environment, and creating a root certificate based on the root key pair;
[0012] Create an intermediate certificate from the private key of the root certificate.
[0013] Optionally, after creating the intermediate certificate according to the private key of the root certificate, the method further includes:
[0014] Periodically generating and updating a key pair in the trusted execution environment;
[0015] An intermediate certificate is created and updated based on the private key of the update key pair and the private key of the root key pair.
[0016] Optionally, the blockchain identity authentication system that calls the server reviews the authentication information in the identity authentication request, including:
[0017] Obtaining authentication information in the identity authentication request, generating an authentication notification according to the authentication information, and broadcasting the authentication notification to the blockchain identity authentication system of the blockchain identity authentication system;
[0018] Receive the audit information returned by the blockchain identity authentication system based on the authentication information, and determine whether the identity authentication request has been approved based on the audit information.
[0019] Optionally, the acquiring the identity information of the terminal and sending it to the trusted execution environment through the authentication interface, and generating the identity authentication signature certificate of the terminal based on the intermediate certificate, includes:
[0020] Obtain the identity information of the terminal, and send the identity information to the trusted execution environment through the authentication interface;
[0021] Generate an identity authentication signature certificate for the terminal in the trusted execution environment based on the private key of the intermediate certificate and the identity information of the terminal, and distribute the identity authentication signature certificate to the terminal through the authentication interface.
[0022] Optionally, the verification of the identity authentication signature certificate of the federated learning member node that initiates the federated learning request includes:
[0023] Invoke the authentication interface to obtain the intermediate certificate from the authentication interface;
[0024] Obtain the identity authentication signature certificate of the federated learning member node that initiates the federated learning request, and verify the digital signature of the identity authentication signature certificate according to the public key of the intermediate certificate.
[0025] Optionally, the encrypted transmission of the interaction data between the federated learning member nodes in the federated learning task based on the intermediate certificate includes:
[0026] When receiving a data transmission request from a federated learning member node in the federated learning task, determine the data sending node and the data receiving node according to the data transmission request;
[0027] Obtain the identity authentication signature certificates of the data sending node and the data receiving node, and verify the digital signatures of the identity authentication signature certificates according to the public key of the intermediate certificate;
[0028] If the identity authentication signature certificates of both the data sending node and the data receiving node pass the verification, encrypt the data sent by the data sending node using an asymmetric encryption algorithm and then send it to the data receiving node;
[0029] If any of the identity authentication signature certificates of the data sending node and the data receiving node fails to pass the verification, send an alarm notification to the node that fails to pass the verification.
[0030] In addition, to achieve the above object, the present invention further provides a data interaction device based on a trusted execution environment, and the data interaction device based on a trusted execution environment includes:
[0031] A certificate creation module, configured to build a trusted execution environment in the server, generate an intermediate certificate in the trusted execution environment based on a root certificate, and create an authentication interface for the trusted execution environment based on a secure communication protocol;
[0032] An authentication review module is used to receive an identity authentication request of a federated learning member node sent by a terminal to a server, call the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and generate a rejection notice and send it to the terminal if the review fails;
[0033] An identity authentication module, used to obtain the identity information of the terminal after the audit is passed and send it to the trusted execution environment through the authentication interface, generate an identity authentication signature certificate of the terminal based on the intermediate certificate, store the identity authentication signature certificate and the authentication information in the database of the blockchain identity authentication system, add the terminal as a new federated learning member node, and return the identity authentication signature certificate to the terminal;
[0034] A data transmission module is used to, when a federated learning request is received, obtain the identity authentication signature certificate of the federated learning member node that initiates the federated learning request for verification, obtain multiple federated learning member nodes corresponding to the federated learning request from all federated learning member nodes after the verification is passed, create a federated learning task for the multiple federated learning member nodes according to the federated learning request, and encrypt and transmit the interaction data between the federated learning member nodes in the federated learning task based on the intermediate certificate.
[0035] In addition, to achieve the above object, the present invention further provides a server, the server comprising:
[0036] at least one processor; and,
[0037] a memory communicatively connected to the at least one processor; wherein,
[0038] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned data interaction method based on the trusted execution environment.
[0039] In addition, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium storing a computer program, characterized in that when the computer program is executed by a processor, the above-mentioned data interaction method based on a trusted execution environment is implemented.
[0040] The present invention improves the security of the root certificate by building a trusted execution environment on the server to store the root certificate and performing secure communication through a specified authentication interface; protects the root certificate through an intermediate certificate created based on the root certificate to prevent the root certificate from being leaked or attacked; performs member identity authentication management through blockchain to prevent unauthorized node access and enhance the security of the federated learning center; and implements secure sharing of federated learning data by performing certificate verification during the data interaction process of federated learning. Brief Description of the Drawings
[0041] Figure 1 is an exemplary system architecture diagram to which the present invention can be applied;
[0042] Figure 2 is a flowchart of an embodiment of the data interaction method based on a trusted execution environment according to the present invention;
[0043] Figure 3 is a schematic diagram of an embodiment of the server according to the present invention;
[0044] Figure 4 is a schematic diagram of modules of an embodiment of the data interaction device based on a trusted execution environment according to the present invention.
[0045] The implementation, functional features, and advantages of the objectives of this application will be further described with reference to the embodiments and the accompanying drawings. Detailed Embodiments
[0046] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0047] It should be noted that the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0048] As Figure 1 shown, the system architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0049] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0050] Terminal devices 101, 102, and 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV) players, laptop computers, desktop computers, and so on.
[0051] Server 105 can be a server that provides various services, such as a background server that provides support for the pages displayed on terminal devices 101, 102, and 103.
[0052] It should be noted that the data interaction method based on the trusted execution environment provided by the embodiments of the present application is generally executed by the server / terminal device. Correspondingly, the computer-readable storage medium is generally disposed in the server / terminal device.
[0053] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0054] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 2 As shown in
[0055] Figure 19 is a flowchart of an embodiment of the data interaction method based on the trusted execution environment of the present invention. This data interaction method is applied to the server and includes steps S1 - S4.
[0056] In one embodiment, a trusted execution environment is built in the security processor of the server, and the trusted execution environment program is run through the security processor of the server. The memory of the security processor is encrypted in the trusted execution environment.
[0057] In one embodiment, generating an intermediate certificate based on a root certificate in the trusted execution environment includes:
[0058] Generate a root key pair in the trusted execution environment, and create a root certificate based on the root key pair;
[0059] Create an intermediate certificate according to the private key of the root certificate.
[0060] In this embodiment, the root certificate is a self-signed certificate issued by a trusted certificate authority (CA, Certificate Authority). It is the starting point of the entire certificate chain and has the highest level of trust. The intermediate certificate is issued by the root certificate and is used to provide an intermediate trust layer for the final end-entity certificate. The main purpose of the intermediate certificate is to establish a chain structure between the root certificate and the end-entity certificate, so that the root certificate does not directly participate in the signing of each end-entity certificate. The CA signs the end-entity certificate with the intermediate certificate instead of directly signing with the root certificate for security considerations to prevent the root certificate from being leaked or attacked. Because once the root certificate becomes invalid, the entire CA trust chain will collapse. Each certificate in the certificate chain is signed by the previous-level certificate, and the final root certificate is at the top of the chain.
[0061] In one embodiment, generating a root key pair in the trusted execution environment and creating a root certificate based on the root key pair includes:
[0062] Generate a root key pair in the trusted execution environment, where the root key pair includes a public key and a private key;
[0063] Create a root certificate signing request using the private key of the root key pair, and self-sign the root certificate signing request using the private key of the root key pair to generate a root certificate.
[0064] In one embodiment, creating an intermediate certificate according to the private key of the root certificate includes:
[0065] Generate a random key pair in the trusted execution environment;
[0066] Create an intermediate certificate signing request using the private key of the random key pair;
[0067] Sign the intermediate certificate signing request using the private key of the root key pair to generate an intermediate certificate.
[0068] In one embodiment, after creating an intermediate certificate according to the private key of the root certificate, it further includes:
[0069] Regularly generate an updated key pair (i.e., update the random key pair) in the trusted execution environment, and create a new intermediate certificate according to the private key of the updated key pair and the private key of the root key pair to replace the historical intermediate certificate.
[0070] In this embodiment, by periodically updating the key of the intermediate certificate, while maintaining the long-term stability of the root certificate, the security of the entire certificate chain is ensured at the same time.
[0071] In one embodiment, an API authentication interface is created for the trusted execution environment based on the HTTPS secure communication protocol. HTTPS is a secure communication protocol based on SSL / TLS that protects data security through encryption technology and authenticates the communicating parties to avoid data leakage and tampering.
[0072] In this embodiment, a unique accessible authentication interface for the trusted execution environment is created through the secure communication protocol, and only the intermediate certificate can be accessed and used through this authentication interface, preventing the root certificate from being casually accessed and used externally, thereby preventing the root certificate from being leaked or attacked.
[0073] In this embodiment, the root certificate is stored by building a trusted execution environment on the server, and secure communication is carried out through the specified authentication interface, improving the security of the root certificate. The root certificate is protected by the intermediate certificate created based on the root certificate, preventing the root certificate from being leaked or attacked.
[0074] S2. Receive the identity authentication request of the federated learning member node sent by the terminal, call the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and if the review fails, generate a rejection notice and send it to the terminal.
[0075] In one embodiment, calling the blockchain identity authentication system of the server to review the authentication information in the identity authentication request includes:
[0076] Obtain the authentication information in the authentication request, generate an authentication notice according to the authentication information, and broadcast the authentication notice to the blockchain identity authentication system of the server;
[0077] Receive the review information returned by the blockchain identity authentication system based on the authentication information, and judge whether the authentication request passes the review according to the review information.
[0078] Specifically, the blockchain identity authentication system may be a management terminal joined to the blockchain. After receiving the authentication notice, the administrator of the management terminal manually reviews the authentication information in the authentication notice and returns the corresponding review information.
[0079] In one embodiment, the blockchain identity authentication system reviews the authentication information according to the pre-set review rules. The review rules include but are not limited to the validity of the authentication information (such as whether the domain name ownership is valid), authenticity, etc.
[0080] In one embodiment, after calling the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, it also includes:
[0081] The audit data of the authentication information is recorded in a log and stored in a server database, wherein the audit data record includes the authentication information, the audit result and the audit node information.
[0082] S3. If the review is passed, the identity information of the terminal is obtained and sent to the trusted execution environment through the authentication interface, an identity authentication signature certificate of the terminal is generated based on the intermediate certificate, the identity authentication signature certificate and the authentication information are stored in the database of the blockchain identity authentication system, the terminal is added as a new federated learning member node, and the identity authentication signature certificate is returned to the terminal.
[0083] In one embodiment, the acquiring the identity information of the terminal and sending it to the trusted execution environment through the authentication interface, and generating the identity authentication signature certificate of the terminal based on the intermediate certificate, includes:
[0084] Acquire the identity information of the terminal, and send the identity information to the trusted execution environment through the authentication interface;
[0085] In the trusted execution environment, an identity authentication signature certificate of the terminal is generated based on the private key of the intermediate certificate and the identity information of the terminal, and the identity authentication signature certificate is distributed to the terminal through the authentication interface.
[0086] This embodiment uses blockchain to perform member identity authentication management to prevent unauthorized node access and enhance the security of the federated learning center.
[0087] S4. When a federated learning request is received, the identity authentication signature certificate of the federated learning member node that initiates the federated learning request is obtained for verification. After the verification is passed, multiple federated learning member nodes corresponding to the federated learning request are obtained from all federated learning member nodes, and a federated learning task is created for the multiple federated learning member nodes according to the federated learning request. The interaction data between the federated learning member nodes in the federated learning task is encrypted and transmitted based on the intermediate certificate.
[0088] In one embodiment, obtaining the identity authentication signature certificate of the federated learning member node that initiates the federated learning request for verification includes:
[0089] Calling the authentication interface to obtain the intermediate certificate from the authentication interface;
[0090] Obtain the identity authentication signature certificate of the federated learning member node that initiates the federated learning request, and verify the digital signature of the identity authentication signature certificate according to the public key of the intermediate certificate.
[0091] In one embodiment, after obtaining and verifying the identity authentication signature certificate of the federated learning member node that initiated the federated learning request, the method further includes:
[0092] If the identity authentication signature certificate of the federated learning member node that initiates the federated learning request fails to pass the verification, an alarm notification is generated and returned to the federated learning member node.
[0093] In one embodiment, the encrypting and transmitting the interactive data between the federated learning member nodes in the federated learning task based on the intermediate certificate includes:
[0094] When receiving a data transmission request from a federated learning member node in a federated learning task, determining a data sending node and a data receiving node according to the data transmission request;
[0095] Obtaining the identity authentication signature certificates of the data sending node and the data receiving node, and verifying the digital signatures of the identity authentication signature certificates according to the public key of the intermediate certificate;
[0096] If the identity authentication signature certificates of the data sending node and the data receiving node are both verified, the data sent by the data sending node is encrypted using an asymmetric encryption algorithm and then sent to the data receiving node;
[0097] If any identity authentication signature certificate of the data sending node and the data receiving node fails to pass the verification, an alarm notification is sent to the node that fails to pass the verification.
[0098] In one embodiment, determining a data sending node and a data receiving node according to the data transmission request includes:
[0099] Determine the federated learning member node that sends the data transmission request as a data sending node;
[0100] Obtain a data transmission object identifier from the data transmission request, obtain all federated learning member node identifiers of the federated learning task and match them with the data transmission object identifier, and determine that the federated learning member node corresponding to the successfully matched federated learning member node identifier is a data receiving node.
[0101] In one embodiment, after the federated learning task is completed, information about the federated learning task is recorded and stored in a database of the server.
[0102] In this embodiment, by performing certificate verification during the data interaction process of federated learning, secure sharing of federated learning data is achieved.
[0103] As can be seen from the above embodiments, the data interaction method based on a trusted execution environment proposed by the present invention improves the security of the root certificate by constructing a trusted execution environment in the server to store the root certificate and performing secure communication through a specified authentication interface; protects the root certificate through an intermediate certificate created based on the root certificate to prevent the root certificate from being leaked or attacked; manages member identity authentication through blockchain to prevent unauthorized nodes from accessing, enhancing the security of the federated learning center; and realizes secure sharing of federated learning data by performing certificate verification during the data interaction process of federated learning.
[0104] As Figure 3 shown, it is a schematic diagram of an embodiment of the server of the present invention. The server 1 is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions. The server 1 can be a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of hosts or network servers based on cloud computing, where cloud computing is a type of distributed computing and consists of a super virtual computer formed by a group of loosely coupled computers.
[0105] In this embodiment, the server 1 includes, but is not limited to, a memory 11, a processor 12, and a network interface 13 that can communicate with each other through a system bus. The memory 11 stores a data interaction program 10 based on a trusted execution environment, and the data interaction program 10 based on a trusted execution environment can be executed by the processor 12. Figure 4 Only the server 1 with components 11-13 and the data interaction program 10 based on a trusted execution environment is shown. Those skilled in the art can understand that Figure 4 the shown structure does not constitute a limitation on the server 1 and may include fewer or more components than shown, or combine certain components, or have different component arrangements.
[0106] Among them, the memory 11 includes a memory and at least one type of readable storage medium. The memory provides a cache for the operation of the server 1; the readable storage medium can be volatile or non-volatile. Specifically, the readable storage medium can be a storage medium such as flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the readable storage medium can be an internal storage unit of the server 1, such as the hard disk of the server 1; in other embodiments, the storage medium can also be an external storage device of the server 1, such as a plug-in hard disk equipped on the server 1, a SmartMedia Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. In this embodiment, the readable storage medium of the memory 11 mainly includes a program storage area and a data storage area. Among them, the program storage area is usually used to store the operating system installed on the server 1 and various application software, such as storing the code of the data interaction program 10 based on the trusted execution environment in an embodiment of the present invention, etc.; the data storage area can store data created according to the use of the blockchain identity authentication system, such as various types of data that have been output or will be output.
[0107] In some embodiments, the processor 12 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 12 is generally used to control the overall operation of the server 1, such as performing control and processing related to data interaction or communication with other devices. In this embodiment, the processor 12 is used to run the program code stored in the memory 11 or process data, such as running the data interaction program 10 based on the trusted execution environment.
[0108] The network interface 13 can include a wireless network interface or a wired network interface, and this network interface 13 is used to establish a communication connection between the server 1 and a client terminal (not shown in the figure).
[0109] Optionally, the server 1 may further include a user interface, which may include a display, an input unit such as a keyboard, and an optional user interface may further include a standard wired interface and a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, and an organic light-emitting diode (OLED) touch device. The display may also be appropriately referred to as a display screen or a display unit, which is used to display information processed in the server 1 and to display a visual user interface.
[0110] In one embodiment of the present invention, the data interaction program 10 based on the trusted execution environment implements the following steps S1-S4 when executed by the processor 12.
[0111] S1. Building a trusted execution environment in a server, generating an intermediate certificate based on a root certificate in the trusted execution environment, and creating an authentication interface for the trusted execution environment based on a secure communication protocol;
[0112] S2, receiving the identity authentication request of the federated learning member node sent by the terminal to the server, calling the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and generating a rejection notice and sending it to the terminal if the review fails;
[0113] S3. If the audit is passed, the identity information of the terminal is obtained and sent to the trusted execution environment through the authentication interface, an identity authentication signature certificate of the terminal is generated based on the intermediate certificate, the identity authentication signature certificate and the authentication information are stored in the database of the blockchain identity authentication system, the terminal is added as a new federated learning member node, and the identity authentication signature certificate is returned to the terminal;
[0114] S4. When a federated learning request is received, the identity authentication signature certificate of the federated learning member node that initiates the federated learning request is obtained for verification. After the verification is passed, multiple federated learning member nodes corresponding to the federated learning request are obtained from all federated learning member nodes, and a federated learning task is created for the multiple federated learning member nodes according to the federated learning request. The interaction data between the federated learning member nodes in the federated learning task is encrypted and transmitted based on the intermediate certificate.
[0115] The specific operation steps implemented by the above steps S1-S4 are substantially the same as those of the first embodiment of the data interaction method based on a trusted execution environment of the present invention, and will not be repeated here.
[0116] In other embodiments, the data interaction program 10 based on the trusted execution environment can also be divided into one or more modules, one or more modules are stored in the memory 11, and are executed by one or more processors (processor 12 in this embodiment) to complete the present invention. The module referred to in the present invention refers to a series of computer program instruction segments that can perform specific functions, and is used to describe the execution process of the data interaction program 10 based on the trusted execution environment in the server 1.
[0117] like Figure 4 FIG. 1 is a schematic diagram of a module of an embodiment of a data interaction device based on a trusted execution environment according to the present invention.
[0118] In one embodiment of the present invention, a data interaction device 1 based on a trusted execution environment includes a certificate creation module 110, an authentication review module 120, an identity authentication module 130, and a data transmission module 140. Exemplarily:
[0119] The certificate creation module 110 is used to build a trusted execution environment in the server, generate an intermediate certificate based on the root certificate in the trusted execution environment, and create an authentication interface for the trusted execution environment based on a secure communication protocol;
[0120] The authentication review module 120 is used to receive an identity authentication request of a federated learning member node sent by a terminal to a server, call the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and generate a rejection notice and send it to the terminal if the review fails;
[0121] The identity authentication module 130 is used to obtain the identity information of the terminal after the audit is passed and send it to the trusted execution environment through the authentication interface, generate the identity authentication signature certificate of the terminal based on the intermediate certificate, store the identity authentication signature certificate and the authentication information in the database of the blockchain identity authentication system, add the terminal as a new federated learning member node, and return the identity authentication signature certificate to the terminal;
[0122] The data transmission module 140 is used to, when receiving a federated learning request, obtain the identity authentication signature certificate of the federated learning member node that initiates the federated learning request for verification, obtain multiple federated learning member nodes corresponding to the federated learning request from all federated learning member nodes after the verification is passed, create a federated learning task for the multiple federated learning member nodes according to the federated learning request, and encrypt and transmit the interaction data between the federated learning member nodes in the federated learning task based on the intermediate certificate.
[0123] The specific operation steps implemented when the above-mentioned certificate creation module 110, authentication review module 120, identity authentication module 130 and data transmission module 140 are executed are generally the same as the above-mentioned data interaction method based on a trusted execution environment embodiment 1, and will not be repeated here.
[0124] In addition, the embodiment of the present invention also proposes a computer-readable storage medium, which can be volatile or non-volatile. Specifically, the computer-readable storage medium can be any one or any combination of a hard disk, a multimedia card, an SD card, a flash memory card, an SMC, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a portable compact disk read-only memory (CD-ROM), a USB memory, etc. The computer-readable storage medium stores a data interaction program 10 based on a trusted execution environment.
[0125] The data interaction program 10 based on the trusted execution environment implements the following operations when executed by the processor:
[0126] A1. Building a trusted execution environment in the server, generating an intermediate certificate based on the root certificate in the trusted execution environment, and creating an authentication interface for the trusted execution environment based on a secure communication protocol;
[0127] A2. Receive an identity authentication request of a federated learning member node sent by a terminal to a server, call the blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and generate a rejection notice and send it to the terminal if the review fails;
[0128] A3. If the audit is passed, the identity information of the terminal is obtained and sent to the trusted execution environment through the authentication interface, an identity authentication signature certificate of the terminal is generated based on the intermediate certificate, the identity authentication signature certificate and the authentication information are stored in the database of the blockchain identity authentication system, the terminal is added as a new federated learning member node, and the identity authentication signature certificate is returned to the terminal;
[0129] A4. When a federated learning request is received, the identity authentication signature certificate of the federated learning member node that initiates the federated learning request is obtained for verification. After the verification is passed, multiple federated learning member nodes corresponding to the federated learning request are obtained from all federated learning member nodes, and a federated learning task is created for the multiple federated learning member nodes according to the federated learning request. The interaction data between the federated learning member nodes in the federated learning task is encrypted and transmitted based on the intermediate certificate.
[0130] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0131] It should be noted that, in this document, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article or method comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, apparatus, article or method comprising such element.
[0132] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0133] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural or equivalent process transformations made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, are equally included in the patent protection scope of the present invention.
Claims
1. A data interaction method based on a trusted execution environment, characterized in that The method comprises: Building a trusted execution environment in the server, generating an intermediate certificate based on a root certificate in the trusted execution environment, and creating an authentication interface for the trusted execution environment based on a secure communication protocol; Receiving an identity authentication request of a federated learning member node sent by a terminal to a server, calling a blockchain identity authentication system of the server to review the authentication information in the identity authentication request, and generating a rejection notice and sending it to the terminal if the review fails; If the review is passed, the identity information of the terminal is obtained and sent to the trusted execution environment through the authentication interface, an identity authentication signature certificate of the terminal is generated based on the intermediate certificate, the identity authentication signature certificate and the authentication information are stored in the database of the blockchain identity authentication system, the terminal is added as a new federated learning member node, and the identity authentication signature certificate is returned to the terminal; When a federated learning request is received, the identity authentication signature certificate of the federated learning member node that initiates the federated learning request is obtained for verification. After the verification is passed, multiple federated learning member nodes corresponding to the federated learning request are obtained from all federated learning member nodes, and a federated learning task is created for the multiple federated learning member nodes according to the federated learning request. The interaction data between the federated learning member nodes in the federated learning task is encrypted and transmitted based on the intermediate certificate.
2. The data interaction method based on a trusted execution environment according to claim 1, wherein Generating an intermediate certificate based on the root certificate in the trusted execution environment includes: Generating a root key pair in the trusted execution environment, and creating a root certificate based on the root key pair; Create an intermediate certificate from the private key of the root certificate.
3. The data interaction method based on a trusted execution environment according to claim 1, wherein After creating an intermediate certificate based on the private key of the root certificate, it also includes: Periodically generating and updating a key pair in the trusted execution environment; An intermediate certificate is created and updated based on the private key of the update key pair and the private key of the root key pair.
4. The data interaction method based on a trusted execution environment according to claim 1, wherein The blockchain identity authentication system that calls the server reviews the authentication information in the identity authentication request, including: Obtaining authentication information in the identity authentication request, generating an authentication notification according to the authentication information, and broadcasting the authentication notification to the blockchain identity authentication system of the blockchain identity authentication system; Receive the audit information returned by the blockchain identity authentication system based on the authentication information, and determine whether the identity authentication request has been approved based on the audit information.
5. The data interaction method based on a trusted execution environment according to claim 1, wherein The acquiring the identity information of the terminal and sending it to the trusted execution environment through the authentication interface, and generating the identity authentication signature certificate of the terminal based on the intermediate certificate, comprises: Acquire the identity information of the terminal, and send the identity information to the trusted execution environment through the authentication interface; In the trusted execution environment, an identity authentication signature certificate of the terminal is generated based on the private key of the intermediate certificate and the identity information of the terminal, and the identity authentication signature certificate is distributed to the terminal through the authentication interface.
6. The data interaction method based on a trusted execution environment according to claim 1, wherein The obtaining and verifying the identity authentication signature certificate of the federated learning member node that initiated the federated learning request includes: Invoke the authentication interface to obtain the intermediate certificate from the authentication interface; Obtain the identity authentication signature certificate of the federated learning member node that initiates the federated learning request, and verify the digital signature of the identity authentication signature certificate according to the public key of the intermediate certificate.
7. The data interaction method based on a trusted execution environment according to claim 1, wherein The encrypted transmission of the interaction data between the federated learning member nodes in the federated learning task based on the intermediate certificate includes: When receiving a data transmission request from a federated learning member node in the federated learning task, determine the data sending node and the data receiving node according to the data transmission request; Obtain the identity authentication signature certificates of the data sending node and the data receiving node, and verify the digital signatures of the identity authentication signature certificates according to the public key of the intermediate certificate; If the identity authentication signature certificates of the data sending node and the data receiving node are both verified, encrypt the data sent by the data sending node using an asymmetric encryption algorithm and send it to the data receiving node; If any of the identity authentication signature certificates of the data sending node and the data receiving node fails to pass the verification, send an alarm notification to the node that fails to pass the verification.
8. A data interaction device based on a trusted execution environment, characterized in that, The data interaction device based on the trusted execution environment includes: A certificate creation module for constructing a trusted execution environment in the server, generating an intermediate certificate based on the root certificate in the trusted execution environment, and creating an authentication interface for the trusted execution environment based on the secure communication protocol; An authentication audit module for receiving an identity authentication request of a federated learning member node sent by a terminal, invoking the blockchain identity authentication system of the server to audit the authentication information in the identity authentication request, and generating a rejection notice and sending it to the terminal if the audit fails; An identity authentication module for obtaining the identity information of the terminal after the audit passes and sending it to the trusted execution environment through the authentication interface, generating an identity authentication signature certificate of the terminal based on the intermediate certificate, storing the identity authentication signature certificate and the authentication information in the database of the blockchain identity authentication system, adding the terminal as a new federated learning member node, and returning the identity authentication signature certificate to the terminal; A data transmission module for, when receiving a federated learning request, obtaining and verifying the identity authentication signature certificate of the federated learning member node that initiates the federated learning request, obtaining multiple federated learning member nodes participating in the corresponding federated learning request from all federated learning member nodes after the verification passes, creating a federated learning task for the multiple federated learning member nodes according to the federated learning request, and encrypting and transmitting the interaction data between the federated learning member nodes in the federated learning task based on the intermediate certificate.
9. A server, characterized in that, The server includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data interaction method based on a trusted execution environment according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the data interaction method based on a trusted execution environment according to any one of claims 1 to 7.