TEE-based data sandbox sharing isolation credibility guarantee method

By building a data sandbox security management system based on TEE and IMA, the security risks of data flow in trusted data space are solved, and the security and credibility of data in the cross-subject sharing process is realized. It is suitable for complex scenarios of multi-party participation and cross-platform data sharing.

CN120509027APending Publication Date: 2025-08-19NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510678171.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

There are security risks in the data flow process in the trusted data space. The existing technology is difficult to effectively prevent data leakage and tampering during cross-subject sharing. It lacks a unified trusted verification mechanism, which affects the authenticity and consistency of the data.

Method used

Build a data sandbox security management system based on TEE and IMA, including a data sandbox management module, signature verification module, data sandbox trusted startup module, runtime measurement module and data security storage module to realize the trusted release, startup and life cycle management of data sandbox, combining TEE's hardware isolation and IMA's software isolation to provide end-to-end protection.

Benefits of technology

Ensure the security and integrity of the data in the data sandbox during the circulation process, effectively resist potential attacks, and support flexible security policy adjustments. It is suitable for complex scenarios where multi-party entities participate and cross-platform data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120509027A_ABST
    Figure CN120509027A_ABST
Patent Text Reader

Abstract

The invention discloses a TEE-based data sandbox sharing isolation credibility guarantee method, and aims to solve the problem that data circulation of a current credible data space has security risks. According to the technical scheme, firstly, a data sandbox security management system composed of a data sandbox management module, a signature verification module, a data sandbox trusted starting module, a runtime measurement module, a data security storage module and the like is constructed with TEE and IMA as supporting environments; the data sandbox management module cooperates with the signature verification module, the data sandbox credible starting module and the data security storage module to perform credible publishing and credible starting on a data sandbox mirror image and perform security storage on a user account and a password so as to realize management of a data sandbox life cycle in the data sandbox layer; the credibility of the data sandbox is proved to the client; according to the method, the security of the data in the data sandbox in the process of flowing from hardware to an operating system bottom layer to a trusted data space can be ensured, and potential attack means can be resisted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer data security, and in particular to a data sandbox shared isolation trust assurance method based on a Trusted Execution Environment (TEE). Background Art

[0002] A data sandbox is a secure environment for isolating and managing data analysis. Essentially a container, it uses technologies such as virtualization and containerization to provide a controlled, independent runtime for data processing and analysis. The data sandbox is designed to allow users to run programs and process data without impacting the security and privacy of external systems or data.

[0003] The trusted data space is a data circulation and utilization infrastructure that connects multiple parties based on consensus rules and realizes the sharing and use of data resources. It is an application ecosystem for the co-creation of data element value and an important carrier for supporting the construction of a national integrated data market. It has three core capabilities: data trust management and control, resource interaction, and value co-creation. It can support dynamic management and control, real-time evidence storage, and result traceability of the entire process of data circulation and utilization. The core idea of the trusted data space is to create a safe data circulation and utilization space with "trust and controllability". By building a safe and trusted data sharing environment, it provides an efficient and reliable cooperation platform for multiple parties such as data providers, data users, and data operators, thereby effectively solving the trust problem in data circulation, promoting the rational allocation and efficient circulation of data elements, and further promoting the high-quality development of the digital economy.

[0004] Currently, trusted data spaces face several major security challenges. First, in trusted data spaces, data generation, storage, transmission, and use involve multiple entities and processes, posing numerous challenges to data security and privacy protection. While existing technologies provide a certain degree of data isolation and privacy protection, they still face numerous deficiencies in complex data sharing scenarios. These include difficulties in effectively preventing data leakage and tampering during cross-entity sharing, and the inability to verify data authenticity and integrity in real time. Second, practical applications of trusted data spaces still present security risks such as side-channel attacks, which impact the security and integrity of data within trusted environments. Furthermore, the lack of a unified trusted verification mechanism when data is shared across platforms and entities makes it difficult to effectively ensure data authenticity and consistency. These issues severely constrain the security and trustworthiness of trusted data spaces and urgently require innovative technological solutions to enhance the security and efficiency of data sharing.

[0005] Trusted Execution Environment (TEE) is a secure execution environment that integrates hardware and software features and is widely used to achieve secure data processing. Unlike the ordinary execution environment provided by the operating system, the Trusted Execution Environment provides a protected isolation area through hardware support, ensuring that the code and data therein can run without external interference. By protecting trusted applications end-to-end, the Trusted Execution Environment can provide confidentiality and integrity protection for the transmission and processing of sensitive data, thereby improving the security of the entire operating environment. TEE also provides a secure storage area for storing sensitive information and sensitive data (such as user accounts, passwords, etc.). Currently, Trusted Execution Environment is widely used in fields such as secure computing and security authentication, and plays an important role in preventing privileged attacks from root users, operating systems, hypervisors, etc.

[0006] The Linux kernel's Integrity Measurement Architecture (IMA) is a security mechanism that integrates kernel and userspace features and is widely adopted for file integrity and authenticity verification. Unlike traditional file system integrity checking tools, IMA provides a protected isolation zone through kernel support, ensuring that file measurement and verification can be performed without external interference. This isolation zone differs from the isolation zone provided by the Trusted Execution Environment (TEE). TEEs typically rely on hardware support (such as Intel SGX or ARM TrustZone) to create a trusted execution environment completely independent of the main operating system and hardware. In contrast, IMA's isolation zone relies primarily on software-level isolation mechanisms provided by the kernel, protecting file integrity and authenticity through kernel modules and security policies. By protecting file integrity end-to-end, IMA can provide integrity and authenticity protection for the storage and processing of sensitive data, thereby improving the security of the entire operating environment. Currently, IMA is widely used in areas such as system secure boot, file integrity verification, and security authentication, playing a particularly important role in preventing attacks from privileged actors such as malware and system administrators.

[0007] To solve the security issues in the trusted data space, the current methods mainly include:

[0008] 1) "A Multi-Agent Data Sharing and Authorization Management Method for Trusted Data Spaces" (publication number [CN 118254786 A])

[0009] This patent proposes a multi-subject data sharing and authorization management method for trusted data spaces. By building a unified authorization management framework, it enables dynamic authorization and access control between data providers, users, and regulators. This method supports fine-grained permission management, can flexibly adjust authorization policies based on the sensitivity of the data and usage scenarios, and records the authorization and usage process through the blockchain to ensure the transparency and traceability of data sharing. However, data sharing scenarios involving multiple subjects increase the risk of data leakage and abuse of permissions. The authorization management framework relies on the immutable nature of the blockchain, but the blockchain itself may face problems such as smart contract vulnerabilities and improper private key management, which may lead to the bypass of the authorization mechanism and thus cause data security risks.

[0010] 2) "A method and device for developing public data based on a data sandbox," publication number [CN 119089487 A]

[0011] This patent discloses a method and device for public data development based on a data sandbox. It proposes a method based on containerization and multi-tenancy to achieve dual isolation of public data development, preventing authorized development operators from accessing unmasked raw public data, thereby ensuring that public data is available but invisible. However, this patent only provides security protection at the application layer and does not combine TEE to enhance the trustworthiness of the data sandbox. Therefore, it cannot provide sufficient protection in the face of advanced threats or malicious attacks, which to some extent limits its application in scenarios with high security requirements.

[0012] 3) "A method and system for sharing private data based on a trusted execution environment" (publication number [CN 116925837 A])

[0013] A privacy data sharing method and system based on a trusted execution environment are disclosed, and a privacy data sharing method and system based on a trusted execution environment (TEE) are proposed. By building a secure data processing environment in the TEE, the encrypted storage and secure calculation of private data are realized. This method utilizes the hardware isolation characteristics of the TEE to ensure that the data is not accessed by external malicious programs during the processing process. At the same time, it combines zero-knowledge proof technology to verify the authenticity and integrity of the data, thereby realizing data sharing while protecting privacy. However, this method does not fully consider the needs of the trusted data space for dynamic control of the entire process of data circulation and utilization. When sharing data across platforms, the trusted authentication mechanism of the data sandbox still needs to be further improved.

[0014] While these existing technologies attempt to address security issues within trusted data spaces, including some that utilize hardware isolation, they fail to address the security issues inherent in trusted data spaces and cannot effectively protect against potential attacks. Therefore, ensuring the secure transfer of data within trusted data spaces remains a critical issue in this field. Summary of the Invention

[0015] The technical problem to be solved by this invention is that the current trusted data space is not secure enough and the data flow in the trusted data space still poses security risks. This invention provides a TEE-based data sandbox isolation and shared trust assurance method. This method leverages the isolation characteristics of containers to provide a clear data input and output interface for the data sandbox. This ensures the security of data in the data sandbox during its flow from the hardware to the underlying operating system and then to the trusted data space, effectively defending against potential attacks.

[0016] In order to solve the above technical problems, the technical solution of the present invention is as follows: First, a data sandbox security management system is constructed with the Trusted Execution Environment (TEE) and the Linux kernel-level Integrity Measurement Architecture (IMA) as the supporting environment. The system consists of a data sandbox management module, a signature verification module, a data sandbox trusted startup module, a runtime measurement module, a data security storage module, etc. The data sandbox management module works in conjunction with the signature verification module, the data sandbox trusted startup module, and the data security storage module to perform trusted publishing of data sandbox images, trusted startup of data sandboxes, and secure storage of user accounts and passwords, thereby achieving management of the data sandbox lifecycle in the data sandbox layer and proving the trustworthiness of the data sandbox to the client.

[0017] The technical solution of the present invention comprises the following steps:

[0018] The first step is to build a data sandbox security management system, which consists of a data sandbox management module, a signature verification module, a data sandbox trusted startup module, a runtime measurement module, a data security storage module, a data sandbox layer, an image repository, a secure storage area, and a data sandbox image pool. The image repository stores signed data sandbox images and data sandbox image identifiers. The runtime measurement module is divided into a server and a client. The server-side runtime measurement module is deployed together with the data sandbox management module, the signature verification module, the data sandbox trusted startup module, the data security storage module, the data sandbox layer, the image repository, and the data sandbox image pool on a server running the Trusted Execution Environment (TEE) and the Linux Kernel Integrity Measurement Architecture (IMA). The client-side runtime measurement module is deployed on any other client machine (the client machine does not need to have TEE and IMA installed).

[0019] The data sandbox layer is the environment in which the server-side operating system stores and runs data sandboxes. Each data sandbox in the data sandbox layer has a unique identifier: its serial number on the server to which it belongs. This serial number is generated when the data sandbox is built and is unique. A data sandbox is started by its corresponding data sandbox image. Similarly, each data sandbox image also has a unique identifier: its serial number on the server to which it belongs. This serial number is generated when the data sandbox image is built and is unique.

[0020] TEE and IMA are deployed at the bottom layer of the operating system of the server running the trusted execution environment.

[0021] The image repository stores and manages data sandbox images. It provides a centralized storage location for data sandbox images and image identifiers. These data sandbox images contain the files, dependencies, and configuration information required for data sandbox operation. The image repository supports uploading, downloading, and retrieving data sandbox images, allowing users to easily store data sandbox images in the repository and retrieve them from the image repository when needed. It also features image version management, allowing users to distinguish and manage different versions of data sandbox images. Furthermore, the data sandbox image repository can be deployed on a local server or hosted on a cloud platform to meet the needs of different users.

[0022] The Data Sandbox Security Management System has two types of users: data providers and data users. Data providers own data and can upload it to the Data Sandbox Security Management System to build a data sandbox. Data users, on the other hand, use the Data Sandbox Security Management System to access and use the data sandbox containing the data they need.

[0023] The secure storage area is a special storage space provided by the TEE, responsible for storing sensitive information and data, including user accounts, passwords, and data sandbox metrics. The secure storage area is isolated from the ordinary storage space and can only be accessed by authorized trusted applications (TAs). The secure storage area has high security and confidentiality, preventing data from being accessed and tampered with by malware or unauthorized users. The TEE's secure storage area supports multiple access control mechanisms to ensure that data can only be accessed and operated in a specific secure environment. In addition, the TEE's secure storage area also provides data integrity and confidentiality protection, preventing data leakage and tampering through encryption and authentication technologies. In short, the TEE's secure storage area is an important part of the TEE security mechanism, providing reliable protection for sensitive information and data.

[0024] A data sandbox is essentially a container. A container is a lightweight, portable, self-contained software runtime environment with a complete file system. It allows developers to package applications and their dependencies together to ensure that applications run consistently across different environments. Containers are implemented through operating system-level virtualization technology, sharing the host machine's operating system kernel and providing each container with an independent runtime space, including a file system, network interfaces, and process space. The core advantages of container technology lie in its fast startup, efficient resource utilization, and good isolation, enabling applications to maintain consistent behavior across development, testing, and production environments. Containers are typically built from container images, which are read-only templates that include everything needed to run an application. Container technology is widely used in cloud computing, microservices architecture, and continuous integration / continuous deployment (CI / CD), greatly simplifying application deployment and management.

[0025] The data sandbox management module is connected to the signature verification module, the data sandbox trusted startup module, and the data security storage module. When a data provider builds a data sandbox on the data sandbox security management system, the data sandbox management module receives the configuration information and the data sandbox base image (the data sandbox base image contains the necessary runtime environment for the data sandbox) provided by the data provider, generates a data sandbox image to be uploaded (the data sandbox image is an image designed for secure data processing, which is based on the data sandbox base image and produced according to user needs), and sends the data sandbox image to be uploaded to the signature verification module. When a "data sandbox startup request" is received from a data user, the data sandbox management module sends the "data sandbox startup request" parameters to the data sandbox trusted startup module. The data sandbox management module is also responsible for sending the user account and password of the data sandbox management system to the data security storage module. When a "data sandbox image download request" is received from a data user, the "data sandbox image download request" parameters are sent to the signature verification module.

[0026] The signature verification module is connected to the data sandbox management module and the image repository. It receives the data sandbox image to be uploaded from the data sandbox management module, uses the TEE to sign the uploaded data sandbox image, generates a signed data sandbox image, and sends the signed data sandbox image and the data sandbox image identifier to the image repository. When the data sandbox management module receives a "request to download a specified data sandbox image," the signature verification module performs a download and signature verification on the data sandbox image downloaded from the image repository, verifies the integrity and authenticity of the downloaded data sandbox image, and sends the verified data sandbox image and the data sandbox image signature to the data sandbox management module.

[0027] The data sandbox trusted startup module is connected to the data sandbox management module, the data security storage module, the data sandbox layer, and the runtime measurement module of the client. It receives the "start data sandbox request" parameter from the data sandbox management module, and starts the data sandbox in the data sandbox layer according to the identifier of the data sandbox image to be started in the "start data sandbox request" parameter, generates a data sandbox measurement value, sends the data sandbox measurement value to the data security storage module, sends the data sandbox startup success signal and the started data sandbox identifier or the data sandbox startup failure signal to the data sandbox management module, and sends the started data sandbox identifier to the client runtime measurement module.

[0028] The server-side runtime measurement module is connected to the client-side runtime measurement module. It receives the "Data Sandbox Credibility Request" from the client-side runtime measurement module and uses the integrity measurement architecture (IMA) in the operating system to monitor and measure the running data sandbox in the data sandbox layer corresponding to the data sandbox identifier to be proven trustworthy in the "Data Sandbox Credibility Request" in real time. It then sends the response data (including tamper-proof signature data) to the client-side runtime measurement module to ensure the security and trustworthiness of the data sandbox during operation. The server-side runtime measurement module pre-sets the proof key, the public key of which can be obtained and verified by the client-side runtime measurement module.

[0029] The runtime measurement module of the client is connected to the data sandbox trusted startup module and the runtime measurement module of the server. It receives and stores the startup data sandbox identifier sent by the data sandbox trusted startup module, selects the data sandbox to be proven to be trustworthy based on the startup data sandbox identifier, generates a "data sandbox trustworthiness certification request", sends the "data sandbox trustworthiness certification request" to the runtime measurement module of the server, and receives the response data returned by the runtime measurement module of the server to determine whether the data sandbox to be proven is trustworthy. The runtime measurement module of the client stores the public key of the preset certification key of the server-side runtime measurement module and the relevant configuration information of the data sandbox basic image corresponding to the startup data sandbox identifier. This configuration information includes the data sandbox image execution command sequence baseline value. The client can be a data provider or a data user and can operate any device, which may not have TEE and IMA.

[0030] The data security storage module is connected to the data sandbox management module and the data sandbox trusted startup module, receives the user account and password from the data sandbox management module, receives the data sandbox measurement value from the data sandbox trusted startup module, and securely stores and manages the user account, password and data sandbox measurement value to ensure the confidentiality and integrity of the user account, password and data sandbox measurement value.

[0031] In the second step, the data sandbox management module works together with the signature verification module, the data sandbox trusted startup module, and the data security storage module to reliably publish the data sandbox image, reliably start the data sandbox, and securely store the user account and password. This manages the life cycle of the data sandbox in the data sandbox layer and proves the trustworthiness of the data sandbox to the client. The method is:

[0032] 2.1 The data sandbox management module and the server-side runtime measurement module work in parallel to coordinate the full life cycle trusted management of the data sandbox image. The method is:

[0033] 2.1.1 The data sandbox management module receives a request from a non-logged-in user (including data providers and data users) or a client request. If the data sandbox management module receives a "registration request" from the user (parameters include the registration request flag and the account to be registered and the password), go to 2.1.2; if the data sandbox management module receives a "login request" from the user (parameters include the login request flag and the login account and password), go to 2.1.3; if the server-side runtime measurement module receives a "data sandbox credibility proof request" from the client (parameters include the data sandbox identifier to be proven credible and the data sandbox identifier to be proven), go to 2.1.8; if neither the data sandbox management module nor the server-side runtime measurement module receives a user request or client request, go to 2.1.1 and continue monitoring.

[0034] 2.1.2 The data sandbox management module sends the "registration request" parameters to the data security storage module and goes to step 6.

[0035] 2.1.3 The data sandbox management module sends the login account and password of the "login request" parameter to the data security storage module and goes to step 6.

[0036] 2.1.4 The data sandbox management module receives a request from a logged-in user. If the data sandbox management module receives an "upload data sandbox image request" (parameters include a data sandbox construction flag and the basic image and configuration information provided by the user) from the user (data provider), go to 2.1.5; if the data sandbox management module receives a "download data sandbox image request" (parameters include a download image request flag and the identifier of the data sandbox image to be downloaded) from the user (data user), go to 2.1.6; if the data sandbox management module receives a "start data sandbox request" (parameters include a start data sandbox request flag and the identifier of the data sandbox image to be started) from the user, go to 2.1.7; if the server-side runtime measurement module receives a "certify data sandbox trustworthiness request" (parameters include the data sandbox identifier to be proven trustworthy and the data sandbox identifier to be proven) from the client, go to 2.1.8; if the data sandbox management module receives a "logout request" (parameters include a logout request flag) from the user, go to 2.1.9; if no user request is received, go to 2.1.4 and continue monitoring.

[0037] 2.1.5 The data sandbox management module sends the "upload data sandbox image request" parameters to the signature verification module and goes to the third step.

[0038] 2.1.6 The data sandbox management module sends the "download data sandbox image request" parameter to the signature verification module and proceeds to step 3.

[0039] 2.1.7 The data sandbox management module sends the "start data sandbox request" parameters to the data sandbox trusted startup module and goes to step 4.

[0040] 2.1.8 The server-side runtime measurement module receives the client's "Prove Data Sandbox Trust Request" and proceeds to step 5.

[0041] 2.1.9 The user logs out and goes to 2.1.1.

[0042] In the third step, if the signature verification module receives the "upload data sandbox image request" parameter from the data sandbox management module, it executes 3.1-3.2 to build the data sandbox image to be uploaded based on the data sandbox management module parameters, and the signature verification module performs the upload operation; if the signature verification module receives the "download data sandbox image request" parameter from the data sandbox management module, it executes 3.3 to verify the signature of the data sandbox image to be downloaded and then download it. The specific method is:

[0043] 3.1 Build a data sandbox image according to the parameters of the "Upload Data Sandbox Image Request" by:

[0044] 3.1.1 The data sandbox management module generates a container file Dockerfile based on the configuration information in the "Upload data sandbox image request" parameters. This Dockerfile defines the environment and tools required for the data sandbox to run.

[0045] 3.1.2 The data sandbox management module calls the Docker toolchain to execute the docker build command, constructing a data sandbox image based on the Dockerfile. It also determines the data sandbox image identifier based on the data sandbox flag and stores the data sandbox image identifier within the data sandbox image. This data sandbox image is the data sandbox image to be uploaded. After construction is complete, the data sandbox management module sends the data sandbox image to be uploaded to the signature verification module.

[0046] 3.2 The signature verification module receives the data sandbox image to be uploaded from the data sandbox management module, signs and uploads the uploaded data sandbox image, and the method is:

[0047] 3.2.1 The signature verification module calculates the hash value of the received data sandbox image to be uploaded, and then uses the TEE_SignData interface of TEE to sign the hash value of the uploaded data sandbox image to obtain the data sandbox image signature, and adds this data sandbox image signature to the data sandbox image to obtain the signed data sandbox image.

[0048] 3.2.2 The signature verification module pushes the signed data sandbox image to the image repository. If the push is successful, go to 3.2.3. If the push fails, go to 3.2.4.

[0049] 3.2.3 The signature verification module sends the data sandbox image signature and the information that the data sandbox image is successfully uploaded to the data sandbox management module. After receiving the signature, the data sandbox management module feeds back the data sandbox image signature and the information that the data sandbox image is successfully uploaded to the user (data provider), and then go to 2.1.4.

[0050] 3.2.4 The signature verification module sends a message to the data sandbox management module indicating that the data sandbox image upload has failed. After receiving the message, the data sandbox management module returns the message to the user (data provider) indicating that the data sandbox image upload has failed. Go to 2.1.4.

[0051] 3.3 The signature verification module verifies the signature of the data sandbox image to be downloaded according to the "Download Data Sandbox Image Request" parameters and then downloads it. The specific method is:

[0052] 3.3.1 The signature verification module parses the identifier of the data sandbox image to be downloaded from the "Download Data Sandbox Image Request" parameter and searches the image repository for the image based on this identifier. If the image is found in the image repository, proceed to 3.3.2. If not, proceed to 3.3.6.

[0053] 3.3.2 The signature verification module downloads the data sandbox image corresponding to the identifier from the image repository according to the data sandbox image identifier. If the download is successful, go to 3.3.3. If the download fails, go to 3.3.5.

[0054] 3.3.3 At this point, the data sandbox image is downloaded successfully. The signature verification module uses the TEE_VerifySignature interface of TEE to verify the signature of the downloaded data sandbox image to verify whether the image signature is correct. If the verification passes, go to 3.3.4. If the verification fails, go to 3.3.5.

[0055] 3.3.4 The signature verification module sends the data sandbox image download success information and the downloaded data sandbox image to the data sandbox management module. The data sandbox management module stores the downloaded data sandbox image in the data sandbox image pool and returns the data sandbox image download success information to the user. Go to 2.1.4.

[0056] 3.3.5 The signature verification module deletes the downloaded data sandbox image and sends a message indicating that the data sandbox image download has failed to be downloaded to the data sandbox management module. The data sandbox management module returns the message indicating that the data sandbox image download has failed to be downloaded to the user and proceeds to 2.1.4.

[0057] In the fourth step, the data sandbox trusted startup module receives the "start data sandbox request" parameter from the data sandbox management module and performs trusted startup. The method is:

[0058] 4.1 The data sandbox trusted startup module builds the corresponding data sandbox in the data sandbox layer through the data sandbox image according to the data sandbox image identifier to be started in the "Start data sandbox request" parameter. After construction, the identifier of the data sandbox is sent to the data security storage module, and then goes to step 6.

[0059] 4.2 The data sandbox trusted startup module obtains the complete file system of the data sandbox based on the storage path of the data sandbox in the data sandbox layer, and measures the complete file system of the data sandbox using the SM3 national cryptographic algorithm (the SM3 algorithm is a commercial cryptographic algorithm released by the China National Cryptography Administration in 2010, belongs to the national cryptographic standard (GM / T 0004-2012), and was officially released as a national standard (GB / T 32905-2016) in 2016). After the measurement is completed, the first data sandbox measurement value t1 is generated and sent to the data security storage module, and then the process goes to step 6.

[0060] 4.3 The Data Sandbox Trusted Startup Module receives the "Startup Permission Information" from the Data Security Module and, based on the data sandbox identifier, starts the corresponding data sandbox within the data sandbox layer. The data sandbox then runs in the data sandbox layer. The Data Sandbox Trusted Startup Module sends a data sandbox startup success signal to the Data Sandbox Management Module and sends the data sandbox identifier indicating the startup completion to the Client Runtime Measurement Module. The Client Runtime Measurement Module stores the data sandbox identifier and uses it to subsequently verify the trustworthiness of the data sandbox. Proceed to 2.1.4.

[0061] 4.4 The data sandbox trusted startup module receives the "startup prohibition information" from the data security module and sends the data sandbox startup failure information to the data sandbox management module. The data sandbox management module feeds back the startup failure information to the data user and goes to 2.1.4.

[0062] 4.5 The data sandbox management module obtains the complete file system of the data sandbox according to the storage path of the data sandbox in the data sandbox layer. The data sandbox trusted startup module uses the SM3 national encryption algorithm to measure the complete file system of the data sandbox, generates a second data sandbox measurement value t2, and sends the measurement value t2 to the data security storage module, and goes to step 6.

[0063] In the fifth step, the server-side runtime measurement module monitors and measures the running data sandbox in real time, stores the execution commands and measurement values of each data sandbox in the runtime measurement log file, ensures the security and credibility of the data sandbox operation status, and provides proof to the client. The method is:

[0064] 5.1 The server-side runtime measurement module parses the "Prove Data Sandbox Trust Request" parameter sent by the client-side runtime measurement module to obtain the data sandbox identifier to be proven. It then checks, within the data sandbox layer, whether the target data sandbox identified by the data sandbox identifier to be proven trustworthy exists and is operational. If the target data sandbox exists and is operational, it sends a confirmation response to the client-side runtime measurement module and proceeds to 5.2. If the target data sandbox does not exist or is not operational, it returns an error message to the client-side runtime measurement module and proceeds to 2.1.4.

[0065] 5.2 The server-side runtime measurement module filters out the data sandbox execution command sequence from the IMA and reads the runtime measurement log file. It traverses the runtime measurement log file in the IMA according to the data sandbox execution command sequence and matches the log entry C containing the complete command string, C = {c1, c2, ..., c i ,...,c I}, where c iRepresents the i-th log entry. The server-side runtime measurement module performs a chain hash operation H = Hash(…Hash(Hash(0||c1)||c2)…||c i ), where the Hash() operation hashes the data within the brackets, and the || symbol is a data concatenation operator. The hash calculation result H is concatenated with the filtered data sandbox execution command sequence, and the concatenated string is hashed to generate an integrity metric. The server-side runtime measurement module concatenates the integrity metric with an arbitrary random number and digitally signs it using its pre-set proof key to generate tamper-resistant signature data. This signature is then saved in the response data and sent to the client-side runtime measurement module.

[0066] 5.3 The client runtime measurement module receives the response data from the server runtime measurement module and performs triple checks on the response data:

[0067] 5.3.1 The client runtime measurement module verifies the validity of the signature using the public key of the server runtime measurement module's attestation key stored in it. If valid, go to 5.3.2; if invalid, go to 5.3.5.

[0068] 5.3.2 The client runtime metric module calculates the chain hash of the metric log entry and compares it with the chain hash returned by the server. If the comparison is successful, go to 5.3.3. If the comparison is unsuccessful, go to 5.3.5.

[0069] 5.3.3 The client runtime measurement module verifies each metric value in the returned log entries one by one to see if it is completely consistent with the client's pre-stored data sandbox image execution command sequence baseline value. If they are consistent, it means that all three verifications have passed. Go to 5.3.4. If not, go to 5.3.5.

[0070] 5.3.4 The client runtime measurement module determines that the data sandbox operation status is credible and sends the data sandbox credibility information to the user, and then go to 2.1.4.

[0071] 5.3.5 The client runtime measurement module determines that the data sandbox operation status is untrustworthy and sends the data sandbox untrustworthy information to the user, and then go to 2.1.4.

[0072] In the sixth step, if the data security storage module receives the user "registration request" parameter from the data sandbox management module, it executes 6.1 to securely store the account and password to be registered in the "registration request" parameter. If the data security storage module receives the "login request" parameter from the data sandbox management module, it executes 6.2 to verify the login account and password in the "login request" parameter. If the data security storage module receives the data sandbox identifier from the data sandbox trusted startup module, it executes 6.3 to perform corresponding checks, storage, and verification. If the data security storage module receives the first data sandbox measurement value t1 from the data sandbox trusted startup module, it executes 6.4 to store the first data sandbox measurement value t1. If the data security storage module receives the second data sandbox measurement value t2 from the data sandbox trusted startup module, it executes 6.5 to store the second data sandbox measurement value t2. The specific method is as follows:

[0073] 6.1 The data security storage module securely stores the account and password to be registered in the user's "registration request" parameters, as follows:

[0074] 6.1.1 The data security storage module calls the TEE_StoreEncryptedData interface to send the account and password to be registered in the user's "registration request" parameter to TEE.

[0075] 6.1.2 TEE checks the received account number in the current secure storage area to see if the account number already exists. If it does, registration has failed and the process goes to 6.1.4. Otherwise, the process goes to 6.1.3.

[0076] 6.1.3 TEE encrypts the registered account and password and stores it in a secure storage area. If successful, the data security storage module sends a registration success message to the data sandbox management module, which returns the registration success message to the user. Go to 2.1.4. If the storage fails, go to 6.1.5.

[0077] 6.1.4 If registration fails, the data security storage module will send the registration failure information to the data sandbox management module, which will then return the registration failure information to the user and go to 2.1.4.

[0078] 6.1.5 If storage fails, the data security storage module sends the storage failure information to the data sandbox management module, which then returns the registration failure information to the user and goes to 2.1.4.

[0079] 6.2 The data security storage module verifies the login account and password in the "Login Request" parameter as follows:

[0080] 6.2.1 The data security storage module calls the TEE_AccessEncryptedData interface of TEE to send the account and password in the "login request" parameter to TEE.

[0081] 6.2.2 The TEE reads the corresponding secure storage data from the secure storage area based on the account number in the "Login Request" parameter, finds the password for the corresponding account, and verifies it within the TEE. The TEE compares the password in the "Login Request" with the password in the secure storage area. If the comparison is consistent, it means that the user login information is correct and a login success message is sent to the data security storage module, and go to 6.2.3. If the comparison is inconsistent, it means that the user login information is incorrect and a login failure message is sent to the data security storage module, and go to 6.2.4.

[0082] 6.2.3 If the login is successful, the data security storage module will send the login success information to the data sandbox management module, which will return the login success information to the user and go to 2.1.4.

[0083] 6.2.4 If the login fails, the data security storage module will send the login failure information to the data sandbox management module, which will return the login failure information to the user and go to 2.1.1.

[0084] 6.3 The data security storage module queries the secure storage area for a data sandbox measurement value corresponding to the data sandbox image identifier (the data sandbox measurement value is an identifier generated by the data sandbox trusted startup module after measuring the file system in the data sandbox. Any changes to the file system in the data sandbox will cause the measurement value to change, thereby determining whether the data sandbox has been tampered with). If the secure storage area does not have a data sandbox measurement value corresponding to the data sandbox identifier, it is confirmed that this is the first startup, and go to 4.2. If the data sandbox measurement value corresponding to the data sandbox identifier is found in the secure storage area, it is confirmed that this is a second startup, and go to 4.5.

[0085] 6.4 The data security storage module stores the first data sandbox metric value t1, as follows:

[0086] 6.4.1 The data security storage module binds the received data sandbox identifier (received in step 4.1) and the data sandbox metric value t1 and stores them in the secure storage area. If the storage is successful, go to 6.4.2; if the storage fails, go to 6.4.3.

[0087] 6.4.2 The data security storage module sends the "startup permission information" to the data sandbox trusted startup module, and then go to 4.3.

[0088] 6.4.3 The data security storage module sends the "startup failure information" to the data sandbox trusted startup module, and then go to 4.4.

[0089] 6.5 The data security storage module stores the second data sandbox metric value t2, as follows:

[0090] 6.5.1 The data security storage module retrieves the corresponding first data sandbox measurement value t1 in the secure storage area through the data sandbox identifier and decrypts t1 within the TEE. The TEE compares t1 with t2. If t1 = t2, go to 6.5.2; if t1 ≠ t2, go to 6.5.3.

[0091] 6.5.2 t1 = t2, indicating that the data sandbox has not been tampered with. The data security storage module sends a startup permission message to the data sandbox trusted startup module. Go to 4.3.

[0092] 6.5.3 If t1≠t2, the data sandbox has been tampered with. A startup prohibition message is sent to the data sandbox trusted startup module. Go to 4.4.

[0093] Since the present invention is a process of constantly waiting for user commands and constantly performing data sandbox management, startup, verification, and storage, it will continue to run as long as the data sandbox security management system is not powered off, so the present invention is an infinite loop.

[0094] The present invention can achieve the following technical effects:

[0095] 1. This invention provides a systematic trusted data space security solution. By combining the hardware isolation characteristics of the Trusted Execution Environment (TEE) and the software isolation characteristics of the data sandbox, a multi-level secure isolation operating environment is constructed to ensure the isolated use of data.

[0096] 2. This invention not only realizes the trusted construction, signing and verification of data sandbox images, ensuring the integrity and authenticity of data during transmission and loading, but also uses the Integrity Measurement Architecture (IMA) to monitor and measure the running data sandbox in real time, further improving the security and credibility of the data sandbox.

[0097] 3. The present invention supports secure computing and trusted verification of data, and can flexibly adjust security policies according to the sensitivity of the data and usage scenarios, effectively ensuring the security and credibility of data during sharing.

[0098] The present invention provides a more comprehensive and in-depth solution in terms of the security, reliability and efficiency of the trusted data space, and is particularly suitable for complex scenarios involving the participation of multiple parties and cross-platform data sharing. BRIEF DESCRIPTION OF THE DRAWINGS

[0099] Figure 1 This is the logical structure diagram of the data sandbox security management system constructed in the first step of the present invention.

[0100] Figure 2 It is the overall flow chart of the present invention.

[0101] Figure 3 This is the result displayed by the terminal when the user is registered in steps 2.1.2 and 6.1.3 of the embodiment of the present invention.

[0102] Figure 4 This is a diagram showing the effect of verifying the user password in step 2.1.3 of Example 2 of the present invention.

[0103] Figure 5 This is a schematic diagram of image push when uploading a data sandbox image to an image repository in step 3.2.2 of an embodiment of the present invention.

[0104] Figure 6 This is a diagram showing the actual effect when the data sandbox is successfully started in step 4.3 of Example 4 of the present invention.

[0105] Figure 7 This is the terminal output diagram when entering the activated data sandbox in step 4.3 of the embodiment of the present invention.

[0106] Figure 8 This is a measured effect diagram of the trusted startup failure after the data sandbox is tampered with in step 4.4 of Example 4 of the present invention.

[0107] Figure 9 This is a schematic diagram of the interaction process between the runtime measurement modules of the server and the client in the fifth step of the embodiment of the present invention.

[0108] Figure 10 This is a diagram showing the actual measurement effect when the client runtime measurement module verifies that the data sandbox is trustworthy in the fifth step of an embodiment of the present invention. DETAILED DESCRIPTION

[0109] The present invention will be further described below with reference to the accompanying drawings and examples. In order to verify the effect of the present invention, the rights confirmation of a student achievement database is used as an example for description.

[0110] like Figure 2 As shown, the technical solution of the present invention includes the following steps:

[0111] The first step is to build a data sandbox security management system. Figure 1As shown, it consists of a data sandbox management module, a signature verification module, a data sandbox trusted startup module, a runtime measurement module, a data security storage module, a data sandbox layer, an image warehouse, a secure storage area, and a data sandbox image pool. Among them, the image warehouse stores signed data sandbox images and data sandbox image identifiers. The runtime measurement module is divided into a server side and a client side. The server side runtime measurement module is deployed together with the data sandbox management module, the signature verification module, the data sandbox trusted startup module, the data security storage module, the data sandbox layer, the image warehouse, and the data sandbox image pool on a server running a trusted execution environment (including TEE and IMA). The client side runtime measurement module is deployed on any other client machine (the client machine does not need to have TEE and IMA installed).

[0112] The data sandbox layer is the environment in which the server-side operating system stores and runs data sandboxes. Each data sandbox in the data sandbox layer has a unique identifier: its serial number on the server to which it belongs. This serial number is generated when the data sandbox is built and is unique. A data sandbox is started by its corresponding data sandbox image. Similarly, each data sandbox image also has a unique identifier: its serial number on the server to which it belongs. This serial number is generated when the data sandbox image is built and is unique.

[0113] TEE and IMA are deployed at the bottom layer of the operating system of the server running the trusted execution environment.

[0114] The image repository stores and manages data sandbox images. It provides a centralized storage location for data sandbox images and image identifiers. These data sandbox images contain the files, dependencies, and configuration information required for data sandbox operation. The image repository supports uploading, downloading, and retrieving data sandbox images, allowing users to easily store data sandbox images in the repository and retrieve them from the image repository when needed. It also features image version management, allowing users to distinguish and manage different versions of data sandbox images. Furthermore, the data sandbox image repository can be deployed on a local server or hosted on a cloud platform to meet the needs of different users.

[0115] The Data Sandbox Security Management System has two types of users: data providers and data users. Data providers own data and can upload it to the Data Sandbox Security Management System to build a data sandbox. Data users, on the other hand, use the Data Sandbox Security Management System to access and use the data sandbox containing the data they need.

[0116] The secure storage area is a special storage space provided by the TEE, responsible for storing sensitive information and data, including user accounts, passwords, and data sandbox metrics. The secure storage area is isolated from the ordinary storage space and can only be accessed by authorized trusted applications (TAs). The secure storage area has high security and confidentiality, preventing data from being accessed and tampered with by malware or unauthorized users. The TEE's secure storage area supports multiple access control mechanisms to ensure that data can only be accessed and operated in a specific secure environment. In addition, the TEE's secure storage area also provides data integrity and confidentiality protection, preventing data leakage and tampering through encryption and authentication technologies. In short, the TEE's secure storage area is an important part of the TEE security mechanism, providing reliable protection for sensitive information and data.

[0117] A data sandbox is essentially a container. A container is a lightweight, portable, self-contained software runtime environment with a complete file system. It allows developers to package applications and their dependencies together to ensure that applications run consistently across different environments. Containers are implemented through operating system-level virtualization technology, sharing the host machine's operating system kernel and providing each container with an independent runtime space, including a file system, network interfaces, and process space. The core advantages of container technology lie in its fast startup, efficient resource utilization, and good isolation, enabling applications to maintain consistent behavior across development, testing, and production environments. Containers are typically built from container images, which are read-only templates that include everything needed to run an application. Container technology is widely used in cloud computing, microservices architecture, and continuous integration / continuous deployment (CI / CD), greatly simplifying application deployment and management.

[0118] The data sandbox management module is connected to the signature verification module, the data sandbox trusted startup module, and the data security storage module. When a data provider builds a data sandbox on the data sandbox security management system, the data sandbox management module receives the configuration information and the data sandbox base image (the data sandbox base image contains the necessary runtime environment for the data sandbox) provided by the data provider, generates a data sandbox image to be uploaded (the data sandbox image is an image designed for secure data processing, which is based on the data sandbox base image and produced according to user needs), and sends the data sandbox image to be uploaded to the signature verification module. When a "data sandbox startup request" is received from a data user, the data sandbox management module sends the "data sandbox startup request" parameters to the data sandbox trusted startup module. The data sandbox management module is also responsible for sending the user account and password of the data sandbox management system to the data security storage module. When a "data sandbox image download request" is received from a data user, the "data sandbox image download request" parameters are sent to the signature verification module.

[0119] The signature verification module is connected to the data sandbox management module and the image repository. It receives the data sandbox image to be uploaded from the data sandbox management module, uses the TEE to sign the uploaded data sandbox image, generates a signed data sandbox image, and sends the signed data sandbox image and the data sandbox image identifier to the image repository. When the data sandbox management module receives a "request to download a specified data sandbox image," the signature verification module performs a download and signature verification on the data sandbox image downloaded from the image repository, verifies the integrity and authenticity of the downloaded data sandbox image, and sends the verified data sandbox image and the data sandbox image signature to the data sandbox management module.

[0120] The data sandbox trusted startup module is connected to the data sandbox management module, the data security storage module, the data sandbox layer, and the runtime measurement module of the client. It receives the "start data sandbox request" parameter from the data sandbox management module, and starts the data sandbox in the data sandbox layer according to the identifier of the data sandbox image to be started in the "start data sandbox request" parameter, generates a data sandbox measurement value, sends the data sandbox measurement value to the data security storage module, sends the data sandbox startup success signal and the started data sandbox identifier or the data sandbox startup failure signal to the data sandbox management module, and sends the started data sandbox identifier to the client runtime measurement module.

[0121] The server-side runtime measurement module is connected to the client-side runtime measurement module. It receives the "Prove Data Sandbox Trust Request" from the client-side runtime measurement module and uses the integrity measurement architecture (IMA) in the operating system to monitor and measure the running data sandbox in the data sandbox layer corresponding to the data sandbox identifier to be proven trustworthy in the "Prove Data Sandbox Trust Request" in real time. The response data is then sent to the client-side runtime measurement module to ensure the security and trustworthiness of the data sandbox during operation. The server-side runtime measurement module is pre-configured with a proof key, the public key of which can be obtained and verified by the client-side runtime measurement module.

[0122] The runtime measurement module of the client is connected to the data sandbox trusted startup module and the runtime measurement module of the server. It receives and stores the startup data sandbox identifier sent by the data sandbox trusted startup module, selects the data sandbox to be proven trustworthy based on the startup data sandbox identifier, generates a "data sandbox trustworthiness certification request", sends the "data sandbox trustworthiness certification request" to the runtime measurement module of the server, and receives the measurement information in the response data returned by the runtime measurement module of the server to determine whether the data sandbox to be proven trustworthy. The runtime measurement module of the client stores the public key of the preset certification key of the server-side runtime measurement module and the relevant configuration information of the data sandbox base image corresponding to the startup data sandbox identifier. This configuration information includes the data sandbox image execution command sequence baseline value. The client can be a data provider or a data user and can operate any device, which may not have TEE and IMA.

[0123] The data security storage module is connected to the data sandbox management module and the data sandbox trusted startup module, receives the user account and password from the data sandbox management module, receives the data sandbox measurement value from the data sandbox trusted startup module, and securely stores and manages the user account, password and data sandbox measurement value to ensure the confidentiality and integrity of the user account, password and data sandbox measurement value.

[0124] In order to verify the effect of the present invention, the data sandbox security management system built in the embodiment is as follows: a Phytium ARMv8 host is used to build the server side. The server side is equipped with a data sandbox management module, a signature verification module, a data sandbox trusted startup module, a server-side runtime measurement module, a data security storage module, a data sandbox layer, a mirror warehouse, a secure storage area, and a data sandbox mirror pool. The server side has a trusted execution environment and a normal execution environment. Docker is used to conduct data sandbox trusted management experiments, running Linux 5.4.19 (including IMA), and the kernel version is OPTEE 3.2. Docker version 19.03.8 is installed on the server side, and the mirror warehouse uses the Docker official mirror warehouse, namely Docker Hub. The client also uses a server, which is equipped with a client runtime measurement module, runs Linux 5.4.19, and is connected to the server side via optical fiber.

[0125] In the second step, the data sandbox management module works together with the signature verification module, the data sandbox trusted startup module, and the data security storage module to reliably publish the data sandbox image, reliably start the data sandbox, and securely store the user account and password. This manages the life cycle of the data sandbox in the data sandbox layer and proves the trustworthiness of the data sandbox to the client. The method is:

[0126] 2.1 The data sandbox management module and the server-side runtime measurement module work in parallel to coordinate the full life cycle trusted management of the data sandbox image. The method is:

[0127] 2.1.1 The data sandbox management module receives a request from a non-logged-in user (including data providers and data users) or a client request. If the data sandbox management module receives a "registration request" from the user (parameters include the registration request flag and the account to be registered and the password), go to 2.1.2; if the data sandbox management module receives a "login request" from the user (parameters include the login request flag and the login account and password), go to 2.1.3; if the server-side runtime measurement module receives a "data sandbox credibility proof request" from the client (parameters include the data sandbox identifier to be proven credible and the data sandbox identifier to be proven), go to 2.1.8; if neither the data sandbox management module nor the server-side runtime measurement module receives a user request or client request, go to 2.1.1 and continue monitoring.

[0128] 2.1.2 The data sandbox management module sends the parameters in the user's "registration request" to the data security storage module and goes to step 6.

[0129] In this embodiment, the user is registered and the terminal displays the result as follows: Figure 3 As shown, the user ID of the user who successfully registered is 76 (as shown in Figure 3 The system will provide feedback to the user on the successful secure storage of the user account and password, i.e., "The password has been securely encrypted and stored. User creation completed successfully."

[0130] 2.1.3 The data sandbox management module sends the account and password in the user's "login request" to the data security storage module and goes to step 6.

[0131] In this embodiment, the data sandbox management module sends the user account password of user id 76 to the data security storage module, which reads the data and then verifies it. The effect is as follows: Figure 4 As shown, from Figure 4 As shown in red, the encrypted password for user ID 76 is "$2a$10$djcZG21Tf6U9B0SCe6M6b0vnhkjCrsks9ZHiNikjzNwHvBZqaKU", which is consistent with the stored password. After verification, the output is "Password verification successful. User authenticated successfully."

[0132] 2.1.4 The data sandbox management module receives a request from a logged-in user. If the data sandbox management module receives an "upload data sandbox image request" from the user (data provider) (parameters include a data sandbox construction flag and the basic image and configuration information provided by the user), go to 2.1.5; if the data sandbox management module receives a "download data sandbox image request" from the user (data user) (parameters include a download image request flag and the identifier of the data sandbox image to be downloaded), go to 2.1.6; if the data sandbox management module receives a "start data sandbox request" from the user (parameters include a start data sandbox request flag and the identifier of the data sandbox image to be started), go to 2.1.7; if the server-side runtime measurement module receives a "certify data sandbox trustworthiness request" from the client (parameters include the identifier of the data sandbox to be proven trustworthy and the identifier of the data sandbox to be proven), go to 2.1.8; if the data sandbox management module receives a "logout" request from the user (parameters include a logout request flag), go to 2.1.9; if no user request is received, go to 2.1.4 and continue monitoring.

[0133] 2.1.5 The data sandbox management module sends the parameters of the "upload data sandbox image request" to the signature verification module and goes to the third step.

[0134] 2.1.6 The data sandbox management module sends the parameters of the "download data sandbox image request" to the signature verification module and proceeds to the third step.

[0135] 2.1.7 The data sandbox management module sends the request parameters of the "Start Data Sandbox Request" to the data sandbox trusted startup module and goes to step 4.

[0136] 2.1.8 The server-side runtime measurement module receives the client's "Prove Data Sandbox Trust Request" and proceeds to step 5.

[0137] 2.1.9 The user logs out and goes to 2.1.1.

[0138] In the third step, if the signature verification module receives the "upload data sandbox image request" parameter from the data sandbox management module, it executes 3.1-3.2 to build the data sandbox image to be uploaded and performs the upload operation; if the signature verification module receives the "download data sandbox image request" parameter from the data sandbox management module, it executes 3.3 to verify the signature of the data sandbox image to be downloaded and then downloads it. The specific method is:

[0139] 3.1 Build a data sandbox image according to the parameters of the "Upload Data Sandbox Image Request" by:

[0140] 3.1.1 The data sandbox management module generates a container file Dockerfile based on the configuration information in the "Upload data sandbox image request" parameters. This Dockerfile defines the environment and tools required for the data sandbox to run.

[0141] 3.1.2 The data sandbox management module calls the Docker toolchain to execute the docker build command, constructing a data sandbox image based on the Dockerfile. It also determines the data sandbox image identifier based on the data sandbox flag. The data sandbox image identifier is stored within the data sandbox image. This data sandbox image is the data sandbox image to be uploaded. After construction is complete, the data sandbox management module sends the uploaded data sandbox image to the signature verification module.

[0142] 3.2 The signature verification module receives the data sandbox image to be uploaded from the data sandbox management module, and signs and uploads the uploaded data sandbox image. The method is:

[0143] 3.2.1 The signature verification module calculates the hash value of the received data sandbox image to be uploaded, and then uses the TEE_SignData interface of TEE to sign the hash value of the uploaded data sandbox image to obtain the data sandbox image signature, and adds this data sandbox image signature to the data sandbox image to obtain the signed data sandbox image.

[0144] 3.2.2 The signature verification module pushes the signed data sandbox image to the image repository. If the push is successful, go to 3.2.3. If the push fails, go to 3.2.4.

[0145] In this embodiment, the image is pushed to the image warehouse after signing. The image push example is as follows: Figure 5 As shown, the signature success information is displayed, such as Figure 5 The red area "Image is signed successfully" indicates that the image has been successfully uploaded to the image repository.

[0146] 3.2.3 The signature verification module sends the data sandbox image signature and the information that the data sandbox image is successfully uploaded to the data sandbox management module. After receiving the signature, the data sandbox management module feeds back the data sandbox image signature and the information that the data sandbox image is successfully uploaded to the user (data provider), and then go to 2.1.4.

[0147] 3.2.4 The signature verification module sends a message to the data sandbox management module indicating that the data sandbox image upload has failed. After receiving the message, the data sandbox management module returns the message to the user (data provider) indicating that the data sandbox image upload has failed. Go to 2.1.4.

[0148] 3.3 The signature verification module verifies the signature of the data sandbox image to be downloaded according to the "Download Data Sandbox Image Request" parameters and then downloads it. The specific method is:

[0149] 3.3.1 The signature verification module parses the identifier of the data sandbox image to be downloaded from the "Download Data Sandbox Image Request" parameter and searches the image repository for the image based on this identifier. If the image is found in the image repository, proceed to 3.3.2. If not, proceed to 3.3.6.

[0150] 3.3.2 The signature verification module downloads the data sandbox image corresponding to the identifier from the image repository according to the data sandbox image identifier. If the download is successful, go to 3.3.3. If the download fails, go to 3.3.5.

[0151] 3.3.3 At this point, the data sandbox image is downloaded successfully. The signature verification module uses the TEE_VerifySignature interface of TEE to verify the signature of the downloaded data sandbox image to verify whether the image signature is correct. If the verification passes, go to 3.3.4. If the verification fails, go to 3.3.5.

[0152] 3.3.4 The signature verification module sends the data sandbox image download success information and the downloaded data sandbox image to the data sandbox management module. The data sandbox management module stores the downloaded data sandbox image in the data sandbox image pool and returns the data sandbox image download success information to the user. Go to 2.1.4.

[0153] 3.3.5 The signature verification module deletes the downloaded data sandbox image and sends a message indicating that the data sandbox image download has failed to be downloaded to the data sandbox management module. The data sandbox management module returns the message indicating that the data sandbox image download has failed to be downloaded to the user and proceeds to 2.1.4.

[0154] In the fourth step, the data sandbox trusted startup module receives the parameters of the "start data sandbox request" from the data sandbox management module and performs the trusted startup. The method is:

[0155] 4.1 The data sandbox trusted startup module builds the corresponding data sandbox in the data sandbox layer through the data sandbox image according to the data sandbox image identifier to be started in the "Start data sandbox request" parameter. After construction, the identifier of the data sandbox is sent to the data security storage module, and then goes to step 6.

[0156] 4.2 The data sandbox trusted startup module obtains the complete file system of the data sandbox based on the storage path of the data sandbox in the data sandbox layer, and measures the complete file system using the SM3 national cryptographic algorithm (the SM3 algorithm is a commercial cryptographic algorithm released by the China National Cryptography Administration in 2010. It belongs to the national cryptographic standard (GM / T 0004-2012) and was officially released as a national standard (GB / T 32905-2016) in 2016). After the measurement is completed, the first data sandbox measurement value t1 is generated and sent to the data security storage module, and then the process goes to step 6.

[0157] 4.3 The Data Sandbox Trusted Startup Module receives the "Startup Permission Information" from the Data Security Module and, based on the data sandbox identifier, starts the corresponding data sandbox within the data sandbox layer. The data sandbox then runs in the data sandbox layer. The Data Sandbox Trusted Startup Module sends a data sandbox startup success signal to the Data Sandbox Management Module and sends the data sandbox identifier indicating the startup completion to the Client Runtime Measurement Module. The Client Runtime Measurement Module stores the data sandbox identifier and uses it to subsequently verify the trustworthiness of the data sandbox. Proceed to 2.1.4.

[0158] In this example, the container ec047089ac2e is started according to the image localhost:5000 / ubuntu, and the system measured effect is as follows Figure 6 As shown, Figure 6 The result of hash calculation for the data sandbox file system can be seen at the red mark. The hash value is as follows: Figure 6 The black mark in the middle shows "e06b07029d8e25446450bad490143da83210f87430e260d324d3d6122fa00e4c".

[0159] The final result of the trusted startup is as follows Figure 7 As shown, Figure 7 The red part shows that you have entered the started container.

[0160] 4.4 The data sandbox trusted startup module receives the "startup prohibition information" from the data security module and sends a data sandbox startup failure signal to the data sandbox management module. The data sandbox management module feeds back the startup failure information to the data user and goes to 2.1.4.

[0161] In this embodiment, the data sandbox ec047089ac2e fails to start after being tampered with. Figure 8 As shown, the data sandbox fails to start after verification. Figure 8 The red area shows "Container verification failed, terminating the container", triggering a kill event to stop the container.

[0162] 4.5 The data sandbox management module obtains the complete file system of the data sandbox according to the storage path of the data sandbox in the data sandbox layer. The data sandbox trusted startup module uses the SM3 national encryption algorithm to measure the data sandbox, generates a second data sandbox measurement value t2, and sends the measurement value t2 to the data security storage module, and goes to step 6.

[0163] In the fifth step, the runtime measurement module on the server side monitors and measures the running data sandbox in real time, and stores the execution commands and measurement values of each data sandbox in the runtime measurement log file to ensure the security and credibility of the running status of the data sandbox and provide proof to the client. The method is: (the request parameters include the data sandbox credibility request flag and the data sandbox identifier to be proven)

[0164] 5.1 The server-side runtime measurement module parses the "Prove Data Sandbox Trust Request" parameter sent by the client-side runtime measurement module to obtain the data sandbox identifier to be proven. It then checks, within the data sandbox layer, whether the target data sandbox identified by the data sandbox identifier to be proven trustworthy exists and is operational. If the target data sandbox exists and is operational, it sends a confirmation response to the client-side runtime measurement module and proceeds to 5.2. If the target data sandbox does not exist or is not operational, it returns an error message to the client-side runtime measurement module and proceeds to 2.1.4.

[0165] 5.2 The server-side runtime measurement module filters out the data sandbox execution command sequence from the IMA and reads the runtime measurement log file. It traverses the runtime measurement log file in the IMA according to the data sandbox execution command sequence and matches the log entry C containing the complete command string, C = {c1, c2, ..., c i ,...,c I}, where c i Represents the i-th log entry. The server-side runtime measurement module performs a chain hash operation H = Hash(…Hash(Hash(0||c1)||c2)…||c i ), where the Hash() operation hashes the data within the brackets, and the || symbol is a data concatenation operator. The hash calculation result H is concatenated with the filtered data sandbox execution command sequence, and the concatenated string is hashed to generate an integrity metric. The server-side runtime measurement module concatenates the integrity metric with an arbitrary random number. After concatenation, it is digitally signed using the server-side runtime measurement module's preset proof key to generate tamper-resistant signature data. This signature is then saved in the response data and sent to the client-side runtime measurement module.

[0166] 5.3 The client runtime measurement module receives the response data from the server runtime measurement module and performs three checks on the response data in sequence:

[0167] 5.3.1 The client runtime measurement module verifies the validity of the signature using the public key of the server runtime measurement module stored in it. If valid, go to 5.3.2; if not, go to 5.3.5.

[0168] 5.3.2 During the client runtime, the metrics module calculates the chained hash of the metrics log entry and compares it with the chained hash returned by the server. If the comparison is successful, go to 5.3.3. If the comparison is unsuccessful, go to 5.3.5.

[0169] 5.3.3 The client runtime measurement module verifies each metric value in the returned log entries one by one to see if it is completely consistent with the client's pre-stored data sandbox image execution command sequence baseline value. If they are consistent, it means that all three verifications have passed. Go to 5.3.4. If not, go to 5.3.5.

[0170] 5.3.4 The client runtime measurement module determines that the data sandbox operation status is credible and sends the data sandbox credibility information to the user, and then go to 2.1.4.

[0171] 5.3.5 The client runtime measurement module determines that the data sandbox operation status is untrustworthy. The client sends the data sandbox untrustworthy information to the user and goes to 2.1.4.

[0172] In this embodiment, the interaction process between the runtime measurement module of the server and the client is as follows: Figure 9 and Figure 10 As shown, Figure 9 The server-side runtime is shown in the Server-Side Runtime Metrics module. Figure 9 The red area shows the request information from the client and the IMA measurement log entry information, which is the output information "---IMA log:---" followed by three lines of information.

[0173] Figure 10 The diagram shows the effect of the client runtime measurement module verifying the trustworthiness of the data sandbox. Figure 10The red mark in the winning part performs a triple check on the response information. After verification, the following are displayed: "Signature verification succeeded!", "PCR verification succeeded!", and "IMA Logs verification succeeded!", where PCR represents the chain hash calculation result. Step 6: If the data security storage module receives the user's "registration request" parameter from the data sandbox management module, it executes 6.1 to securely store the account and password to be registered in the "registration request" parameter; if the data security storage module receives the "login request" parameter from the data sandbox management module, it executes 6.2 to verify the login account and password in the "login request" parameter; if the data security storage module receives the data sandbox identifier from the data sandbox trusted startup module, it executes 6.3 to perform the corresponding checks, storage, and verification; if the data security storage module receives the first data sandbox measurement value t1 from the data sandbox trusted startup module, it executes 6.4 to store the first data sandbox measurement value t1; if the data security storage module receives the second data sandbox measurement value t2 from the data sandbox trusted startup module, it executes 6.5 to store the second data sandbox measurement value t2, as follows:

[0174] 6.1.1 The data security storage module calls the TEE_StoreEncryptedData interface to send the account and password to be registered in the parameters of the user's "registration request" to TEE.

[0175] 6.1.2 TEE checks the received account number to see if it already exists in the current secure storage area. If it does, registration has failed and the process goes to 6.1.4. Otherwise, the process goes to 6.1.3.

[0176] 6.1.3 TEE encrypts the registered account and password and stores it in a secure storage area. If successful, the data security storage module sends a registration success message to the data sandbox management module, which returns the registration success message to the user. Go to 2.1.4. If the storage fails, go to 6.1.5.

[0177] In the embodiment, the storage success example is as follows Figure 3 Marked in red.

[0178] 6.1.4 If registration fails, the data security storage module will send the registration failure information to the data sandbox management module, which will return the registration failure information to the user and go to 2.1.4.

[0179] 6.1.5 If storage fails, the data security storage module sends the storage failure information to the data sandbox management module, which then returns the registration failure information to the user and goes to 2.1.4.

[0180] 6.2 The data security storage module securely stores the "login request" parameters, as follows:

[0181] 6.2.1 The data security storage module calls the TEE_AccessEncryptedData interface of TEE to send the account and password in the "login request" parameter to TEE.

[0182] 6.2.2 The TEE reads the corresponding secure storage data from the secure storage area based on the account number in the "Login Request" parameter, finds the password for the corresponding account, and verifies it within the TEE. The TEE compares the password in the "Login Request" with the password in the secure storage area. If the comparison is consistent, it means that the user login information is correct and a login success message is sent to the data security storage module, and go to 6.2.3. If the comparison is inconsistent, it means that the user login information is incorrect and a login failure message is sent to the data security storage module, and go to 6.2.4.

[0183] 6.2.3 If the login is successful, the data security storage module will send the login success information to the data sandbox management module, which will return the login success information to the user and go to 2.1.4.

[0184] 6.2.4 If the login fails, the data security storage module will send the login failure information to the data sandbox management module, which will return the login failure information to the user and go to 2.1.1.

[0185] 6.3 The data security storage module queries the secure storage area for a data sandbox measurement value corresponding to the data sandbox image identifier (the data sandbox measurement value is an identifier generated by the data sandbox trusted startup module after measuring the file system in the data sandbox. Any changes to the file system in the data sandbox will cause the measurement value to change, thereby determining whether the data sandbox has been tampered with). If the secure storage area does not have a data sandbox measurement value corresponding to the data sandbox identifier, it is confirmed that this is the first startup, and go to 4.2. If the data sandbox measurement value corresponding to the data sandbox identifier is found in the secure storage area, it is confirmed that this is a second startup, and go to 4.5.

[0186] 6.4 The data security storage module stores the first data sandbox metric value t1, as follows:

[0187] 6.4.1 The data security storage module binds the received data sandbox identifier (received in step 4.1) and the data sandbox metric value t1 and stores them in the secure storage area. If the storage is successful, go to 6.4.2; if the storage fails, go to 6.4.3.

[0188] 6.4.2 The data security storage module sends the "startup permission information" to the data sandbox trusted startup module, and then go to 4.3.

[0189] 6.4.3 The data security storage module sends the "startup failure information" to the data sandbox trusted startup module, and then go to 4.4.

[0190] 6.5 The second data sandbox metric value t2 of the data security storage module is as follows:

[0191] 6.5.1 The data security storage module retrieves the corresponding first data sandbox measurement value t1 in the secure storage area through the data sandbox identifier and decrypts t1 within the TEE. The TEE compares t1 with t2. If t1 = t2, go to 6.5.2; if t1 ≠ t2, go to 6.5.3.

[0192] 6.5.2 t1 = t2, indicating that the data sandbox has not been tampered with. The data security storage module sends a startup permission message to the data sandbox trusted startup module. Go to 4.3.

[0193] 6.5.3 If t1≠t2, the data sandbox has been tampered with. A startup prohibition message is sent to the data sandbox trusted startup module. Go to 4.4.

[0194] The above embodiments illustrate how the present invention, through the management of the data sandbox management module and the isolation characteristics of the TEE and container, achieves trusted upload and download of data sandbox images, trusted startup of the data sandbox, runtime measurement of data sandbox applications, and secure data storage. The present invention can achieve comprehensive trust enhancement for the data sandbox, from image publishing and startup to the runtime operation of the data sandbox application. This ensures the security of data in the data sandbox as it flows from the hardware to the underlying operating system and then to the trusted data space, effectively guaranteeing the trusted flow of data in the trusted data space.

Claims

1. A TEE-based data sandbox shared isolation trust assurance method, characterized by The following steps are involved: The first step is to build a data sandbox security management system, which consists of a data sandbox management module, a signature verification module, a data sandbox trusted startup module, a runtime measurement module, a data security storage module, a data sandbox layer, an image warehouse, a secure storage area, and a data sandbox image pool. The image warehouse stores signed data sandbox images and data sandbox image identifiers. The runtime measurement module is divided into a server and a client. The server-side runtime measurement module is deployed together with the data sandbox management module, the signature verification module, the data sandbox trusted startup module, the data security storage module, the data sandbox layer, the image warehouse, and the data sandbox image pool on a server running the Trusted Execution Environment (TEE) and the Linux Kernel Integrity Measurement Architecture (IMA). The client-side runtime measurement module is deployed on any other client machine. The data sandbox layer is the environment where the server-side operating system stores and runs the data sandbox; The image repository stores and manages data sandbox images; The users of the data sandbox security management system are divided into data providers and data users. Data providers own data and upload their data to the data sandbox security management system and build a data sandbox. Data users access and use the data sandbox to which the required data belongs through the data sandbox security management system. The secure storage area is responsible for storing sensitive information and data, including user accounts, passwords, and data sandbox metrics. Only authorized and trusted applications can access the secure storage area. The data sandbox management module is connected to the signature verification module, the data sandbox trusted startup module, and the data security storage module. When a data provider builds a data sandbox on the data sandbox security management system, the data sandbox management module receives the configuration information provided by the data provider and the data sandbox base image containing the necessary runtime environment of the data sandbox, generates the data sandbox image to be uploaded, and sends the data sandbox image to be uploaded to the signature verification module. When a "data sandbox startup request" is received from a data user, the data sandbox management module sends the "data sandbox startup request" parameters to the data sandbox trusted startup module. The data sandbox management module is also responsible for sending the user account and password of the data sandbox management system to the data security storage module. When a "data sandbox image download request" is received from a data user, the module sends the "data sandbox image download request" parameters to the signature verification module. The signature verification module is connected to the data sandbox management module and the image warehouse. It receives the data sandbox image to be uploaded from the data sandbox management module, uses TEE to sign the uploaded data sandbox image, generates a signed data sandbox image, and sends the signed data sandbox image and the data sandbox image identifier to the image warehouse. When receiving a "request to download a specified data sandbox image" from the data sandbox management module, the signature verification module performs a download verification operation on the data sandbox image downloaded from the image warehouse to verify the integrity and authenticity of the downloaded data sandbox image, and sends the verified data sandbox image and the data sandbox image signature to the data sandbox management module. The data sandbox trusted startup module is connected to the data sandbox management module, the data security storage module, the data sandbox layer, and the runtime measurement module of the client. It receives the "start data sandbox request" parameter from the data sandbox management module, starts the data sandbox in the data sandbox layer according to the identifier of the data sandbox image to be started in the "start data sandbox request" parameter, generates a data sandbox measurement value, sends the data sandbox measurement value to the data security storage module, sends a data sandbox startup success signal and the started data sandbox identifier or a data sandbox startup failure signal to the data sandbox management module, and sends the started data sandbox identifier to the client runtime measurement module; The server-side runtime measurement module is connected to the client-side runtime measurement module, receives the "data sandbox trustworthiness certification request" from the client-side runtime measurement module, uses IMA to monitor and measure the running data sandbox in the data sandbox layer corresponding to the data sandbox identifier to be certified in the "data sandbox trustworthiness certification request", and sends the response data to the client-side runtime measurement module to ensure the security and credibility of the data sandbox during operation; the server-side runtime measurement module is pre-set with a certification key, and the client-side runtime measurement module obtains the public key of the certification key for verification; The runtime measurement module of the client is connected to the data sandbox trusted startup module and the runtime measurement module of the server, receives and stores the startup data sandbox identifier sent by the data sandbox trusted startup module, selects the data sandbox to be proven trustworthy based on the startup data sandbox identifier, generates a "data sandbox trustworthiness certification request", sends the "data sandbox trustworthiness certification request" to the runtime measurement module of the server, and receives the response data returned by the runtime measurement module of the server to determine whether the data sandbox to be proven trustworthy; the runtime measurement module of the client stores the public key of the preset certification key of the runtime measurement module of the server and the relevant configuration information of the data sandbox basic image corresponding to the startup data sandbox identifier, which includes the data sandbox image execution command sequence baseline value; the client is any device that can be operated by either the data provider or the data user; The data security storage module is connected to the data sandbox management module and the data sandbox trusted startup module, receives the user account and password from the data sandbox management module, receives the data sandbox measurement value from the data sandbox trusted startup module, and securely stores and manages the user account, password and data sandbox measurement value; In the second step, the data sandbox management module works together with the signature verification module, the data sandbox trusted startup module, and the data security storage module to reliably publish the data sandbox image, reliably start the data sandbox, and securely store the user account and password. This manages the life cycle of the data sandbox in the data sandbox layer and proves the trustworthiness of the data sandbox to the client. The method is: 2.1 The data sandbox management module and the server-side runtime measurement module work in parallel to coordinate the full life cycle trusted management of the data sandbox image. The method is: 2.1.1 The Data Sandbox Management Module receives a request from a non-logged-in user or client. If the Data Sandbox Management Module receives a "Registration Request" from the user, the "Registration Request" parameter includes the registration request flag and the account to be registered and password. Go to 2.1.

2. If the Data Sandbox Management Module receives a "Login Request" from the user, the "Login Request" parameter includes the login request flag and the login account and password. Go to 2.1.

3. If the Server-Side Runtime Metrics Module receives a "Data Sandbox Credibility Verification Request" from the client, the "Data Sandbox Credibility Verification Request" parameter includes the data sandbox identifier to be verified and the data sandbox identifier to be verified. Go to 2.1.

8. If neither the Data Sandbox Management Module nor the Server-Side Runtime Metrics Module receives a user request or client request, go to 2.1.1 and continue monitoring. 2.1.2 The data sandbox management module sends the "registration request" parameters to the data security storage module and goes to step 6; 2.1.3 The data sandbox management module sends the login account and password in the "login request" parameter to the data security storage module and goes to step 6; 2.1.4 The data sandbox management module receives a request from a logged-in user. If the data sandbox management module receives an "upload data sandbox image request" from the user, the parameters of the "upload data sandbox image request" include the data sandbox construction flag and the basic image and configuration information provided by the user, and then go to 2.1.

5. If the data sandbox management module receives a "download data sandbox image request" from the user, the parameters of the "download data sandbox image request" include the download image request flag and the identifier of the data sandbox image to be downloaded, and then go to 2.1.

6. If the data sandbox management module receives a "start data sandbox request" from the user, the parameters of the "download data sandbox image request" include the download image request flag and the identifier of the data sandbox image to be downloaded, and then go to 2.1.

6. The "Start Data Sandbox Request" parameter includes the "Start Data Sandbox Request Flag" and the ID of the data sandbox image to be started. Go to 2.1.

7. If the server-side runtime measurement module receives a "Prove Data Sandbox Trust Request" from the client, the "Prove Data Sandbox Trust Request" parameter includes the ID of the data sandbox to be proven trustworthy and the ID of the data sandbox to be proven. Go to 2.1.

8. If the data sandbox management module receives a "Logout Request" from the user, the "Logout Request" parameter includes the "Logout Request Flag." Go to 2.1.

9. If no user request is received, go to 2.1.4 and continue monitoring. 2.1.5 The data sandbox management module sends the "upload data sandbox image request" parameters to the signature verification module and proceeds to step 3; 2.1.6 The data sandbox management module sends the "download data sandbox image request" parameter to the signature verification module and proceeds to step 3; 2.1.7 The data sandbox management module sends the "Start Data Sandbox Request" parameter to the data sandbox trusted startup module, and then goes to step 4. 2.1.8 The server-side runtime measurement module receives the client's "Prove Data Sandbox Trust Request" and proceeds to step 5; 2.1.9 The user logs out and goes to 2.1.1; In the third step, if the signature verification module receives the "Upload Data Sandbox Image Request" parameter from the data sandbox management module, the data sandbox management module constructs the data sandbox image to be uploaded based on the "Upload Data Sandbox Image Request" parameter. The signature verification module pushes the signed data sandbox image to the image repository and feeds back information about the upload success or failure to the user. Go to 2.1.

4. If the signature verification module receives the "Download Data Sandbox Image Request" parameter from the data sandbox management module, the signature verification module verifies the data sandbox image to be downloaded based on the "Download Data Sandbox Image Request" parameter and downloads it. It then returns information about the data sandbox image download success or failure to the user. Go to 2.1.

4. In the fourth step, the data sandbox trusted startup module receives the "start data sandbox request" parameter from the data sandbox management module and performs trusted startup. The method is: 4.1 The data sandbox trusted startup module builds the corresponding data sandbox in the data sandbox layer using the data sandbox image according to the data sandbox image identifier to be started in the "Start Data Sandbox Request" parameter. After the construction, the data sandbox identifier is sent to the data security storage module, and then the process goes to step 6. 4.2 The data sandbox trusted startup module obtains the complete file system of the data sandbox according to the storage path of the data sandbox in the data sandbox layer, measures the complete file system, generates a first data sandbox measurement value t1, sends t1 to the data security storage module, and goes to step 6; 4.3 The data sandbox trusted startup module receives the "startup permission information" from the data security module and starts the corresponding data sandbox in the data sandbox layer based on the data sandbox identifier. The data sandbox will then run in the data sandbox layer. The data sandbox trusted startup module sends a data sandbox startup success signal to the data sandbox management module and sends the startup completed data sandbox identifier to the client runtime measurement module. The client runtime measurement module stores the data sandbox identifier and proceeds to 2.1.

4. 4.4 The data sandbox trusted startup module receives the "startup prohibition information" from the data security module and sends the data sandbox startup failure information to the data sandbox management module. The data sandbox management module feeds back the startup failure information to the data user and goes to 2.1.

4. 4.5 The data sandbox management module obtains the complete file system of the data sandbox based on the storage path of the data sandbox in the data sandbox layer. The data sandbox trusted startup module measures the complete file system of the data sandbox, generates a second data sandbox measurement value t2, and sends t2 to the data security storage module, then proceeds to step 6. In the fifth step, the server-side runtime measurement module monitors and measures the running data sandbox in real time, stores the execution commands and measurement values of each data sandbox in the runtime measurement log file, ensures the security and credibility of the data sandbox operation status, and provides proof to the client. The method is: 5.1 The server-side runtime measurement module parses the "Prove Data Sandbox Trust Request" parameter sent by the client-side runtime measurement module to obtain the data sandbox identifier to be proven, and checks in the data sandbox layer whether the target data sandbox indicated by the data sandbox identifier to be proven trustworthy exists and is in a running state. If the target data sandbox exists and is in a running state, it sends a confirmation response to the client-side runtime measurement module and goes to 5.

2. If the target data sandbox does not exist or is not in a running state, it returns an error message to the client-side runtime measurement module and goes to 2.1.

4. 5.2 The server-side runtime measurement module filters out the data sandbox execution command sequence from the IMA and reads the runtime measurement log file. It traverses the runtime measurement log file in the IMA according to the data sandbox execution command sequence, matches the log entry C containing the complete command string, performs a chain hash operation on the matched log entry, generates tamper-proof signature data, saves it to the response data, and sends the response data to the client-side runtime measurement module. 5.3 The client runtime measurement module receives the response data from the server runtime measurement module and performs a triple check on the response data. If all three checks pass, it indicates that the data sandbox is in a trustworthy state. The data sandbox certification information is sent to the user and the process goes to 2.1.

4. If any of the three checks fails, it indicates that the data sandbox is in an untrustworthy state. The data sandbox certification information is sent to the user and the process goes to 2.1.

4. In step 6, if the data security storage module receives the user "registration request" parameter from the data sandbox management module, it executes step 6.1 to securely store the account and password to be registered in the "registration request" parameter. If the data security storage module receives the "login request" parameter from the data sandbox management module, it executes step 6.2 to verify the login account and password in the "login request" parameter. If the data security storage module receives the data sandbox identifier from the data sandbox trusted startup module, it executes step 6.3 to perform corresponding checks, storage, and verification. If the data security storage module receives the first data sandbox metric value t1 from the data sandbox trusted startup module, it executes step 6.4 to store the first data sandbox metric value t1. If the data security storage module receives the second data sandbox metric value t2 from the data sandbox trusted startup module, it executes step 6.5 to store the second data sandbox metric value t2. The specific method is as follows: 6.1 The Data Security Storage Module securely stores the account and password to be registered in the user's "Registration Request" parameter. If storage is successful, registration is successful. The Data Security Storage Module sends a registration success message to the Data Sandbox Management Module, which returns a registration success message to the user. Go to 2.1.

4. If registration fails, the Data Security Storage Module sends a registration failure message to the Data Sandbox Management Module, which returns a registration failure message to the user. Go to 2.1.

4. 6.2 The Data Security Storage Module verifies the login account and password in the "Login Request" parameter. If the login is successful, the Data Security Storage Module sends a login success message to the Data Sandbox Management Module, which then returns a login success message to the user. Go to 2.1.

4. If the login fails, the Data Security Storage Module sends a login failure message to the Data Sandbox Management Module, which then returns a login failure message to the user. Go to 2.1.

1. 6.3 The data security storage module queries whether the data sandbox measurement value corresponding to the data sandbox image identifier already exists in the security storage area. If the data sandbox measurement value corresponding to the data sandbox identifier does not exist in the security storage area, it is confirmed that this is the first startup, and the process goes to 4.

2. If the data sandbox measurement value corresponding to the data sandbox identifier is found in the security storage area, it is confirmed that this is a second startup, and the process goes to 4.

5. 6.4 The data security storage module stores the first data sandbox metric value t1, as follows: 6.4.1 The data security storage module binds the received data sandbox identifier and the data sandbox metric value t1 and stores it in the secure storage area. If the storage is successful, proceed to 6.4.

2. If the storage fails, proceed to 6.4.

3. 6.4.2 The data security storage module sends the "startup permission information" to the data sandbox trusted startup module, and then go to 4.

3. 6.4.3 The data security storage module sends the "startup failure information" to the data sandbox trusted startup module, and then go to 4.

4. 6.5 The data security storage module stores the second data sandbox metric value t2 by: 6.5.1 The data security storage module retrieves the corresponding first data sandbox metric value t1 from the secure storage area using the data sandbox identifier and decrypts t1 within the TEE. The TEE compares t1 with t2. If t1 = t2, proceed to 6.5.

2. If t1 ≠ t2, proceed to 6.5.

3. 6.5.2 If t1 = t2, the data sandbox has not been tampered with. The data security storage module sends a startup permission message to the data sandbox trusted startup module. Go to 4.

3. 6.5.3 If t1≠t2, the data sandbox has been tampered with. A startup prohibition message is sent to the data sandbox trusted startup module. Go to 4.

4.

2. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that Each data sandbox in the data sandbox layer has an independent identifier, which is the serial number of the data sandbox on the server to which it belongs. This serial number is generated when the data sandbox is built and is unique; the data sandbox is started by the corresponding data sandbox image, and each data sandbox image also has an independent identifier, which is the serial number of the data sandbox image on the server to which it belongs. This serial number is generated when the data sandbox image is built and is unique; TEE and IMA are deployed at the bottom layer of the operating system of the server running the trusted execution environment; the secure storage area is the storage space provided by TEE, which supports multiple access control mechanisms and is isolated from ordinary storage space to ensure that data can only be accessed and operated in a specific security environment, and the secure storage area provides data integrity and confidentiality protection, and prevents data leakage and tampering through encryption and authentication technology.

3. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that The image warehouse provides a centralized storage location for storing data sandbox images and image identifiers; the data sandbox image contains the files, dependencies, and configuration information required for the data sandbox to run; the image warehouse supports the upload, download, and retrieval functions of the data sandbox image, allowing users to store the data sandbox image in the warehouse and retrieve the data sandbox image from the image warehouse when needed; It also has image version management capabilities, allowing users to distinguish and manage different versions of data sandbox images; the data sandbox image repository is deployed on a local server or hosted on a cloud platform.

4. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that In the third step, the data sandbox management module constructs the data sandbox image to be uploaded according to the "upload data sandbox image request" parameters, and the signature verification module pushes the signed data sandbox image to the image warehouse in the following manner: 3.1 The data sandbox management module builds a data sandbox image according to the "upload data sandbox image request" parameters. The method is: 3.1.1 The data sandbox management module generates a container file Dockerfile based on the configuration information in the "Upload data sandbox image request" parameters. This Dockerfile defines the environment and tools required for the data sandbox to run; 3.1.2 The data sandbox management module calls the Docker tool chain to execute the docker build command, builds a data sandbox image according to the Dockerfile, determines the data sandbox image identifier according to the data sandbox flag, and stores the data sandbox image identifier in the data sandbox image; the data sandbox image is the data sandbox image to be uploaded. After the construction is completed, the data sandbox management module sends the data sandbox image to be uploaded to the signature verification module; 3.2 The signature verification module receives the data sandbox image to be uploaded from the data sandbox management module, signs and uploads the uploaded data sandbox image, and the method is: 3.2.1 The signature verification module calculates the hash value of the received data sandbox image to be uploaded, and then uses the TEE_SignData interface of TEE to sign the hash value of the uploaded data sandbox image to obtain the data sandbox image signature, and adds this data sandbox image signature to the data sandbox image to obtain the signed data sandbox image; 3.2.2 The signature verification module pushes the signed data sandbox image to the image repository. If the push is successful, go to 3.2.3; if the push fails, go to 3.2.4; 3.2.3 The signature verification module sends the data sandbox image signature and the information that the data sandbox image has been successfully uploaded to the data sandbox management module. After receiving the signature, the data sandbox management module returns the data sandbox image signature and the information that the data sandbox image has been successfully uploaded to the user. Go to 2.1.

4. 3.2.4 The signature verification module sends a message to the data sandbox management module indicating that the data sandbox image upload has failed. After receiving the message, the data sandbox management module returns the message to the user indicating that the data sandbox image upload has failed. Go to 2.1.

4.

5. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that In the third step, the signature verification module verifies the signature of the data sandbox image to be downloaded according to the "download data sandbox image request" parameter and then downloads it in the following way: 3.3.1 The signature verification module parses the "Download Data Sandbox Image Request" parameter to obtain the identifier of the data sandbox image to be downloaded and searches the image repository for the image based on this identifier. If the image is found in the image repository, proceed to 3.3.

2. If not, proceed to 3.3.

6. 3.3.2 The signature verification module downloads the data sandbox image corresponding to the identifier from the image repository based on the data sandbox image identifier. If the download is successful, proceed to 3.3.

3. If the download fails, proceed to 3.3.

5. 3.3.3 At this point, the data sandbox image is downloaded successfully. The signature verification module uses the TEE_VerifySignature interface of TEE to verify the signature of the downloaded data sandbox image to verify whether the image signature is correct. If the verification passes, go to 3.3.

4. If the verification fails, go to 3.3.

5. 3.3.4 The signature verification module sends the data sandbox image download success information and the downloaded data sandbox image to the data sandbox management module. The data sandbox management module stores the downloaded data sandbox image in the data sandbox image pool and returns the data sandbox image download success information to the user. Go to 2.1.

4. 3.3.5 The signature verification module deletes the downloaded data sandbox image and sends a message indicating that the data sandbox image download has failed to be downloaded to the data sandbox management module. The data sandbox management module returns the message indicating that the data sandbox image download has failed to be downloaded to the user and proceeds to 2.1.

4.

6. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that The data sandbox trusted startup module described in steps 4.2 and 4.5 uses the SM3 national encryption algorithm to measure the complete file system of the data sandbox.

7. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that The server-side runtime measurement module in step 5.2 performs a chain hash operation on the matched log entry to generate tamper-proof signature data and save it to the response data. The method is as follows: the server-side runtime measurement module performs a chain hash operation H = Hash(…Hash(Hash(0||c1)||c2)…||c i ), where the Hash() operation represents hashing the data in the brackets, and the || symbol is a data concatenation operator; the hash calculation result H is concatenated with the filtered data sandbox execution command sequence, and the concatenated string is hashed to generate an integrity measurement value; c1, c2, ..., c i ,...,c I is an element in log entry C, c i Represents the i-th log entry; the server-side runtime measurement module concatenates the integrity measurement value with an arbitrary random number, and after the concatenation is completed, uses the proof key preset by the server-side runtime measurement module to digitally sign it to generate tamper-proof signature data, and saves it to the response data.

8. A TEE-based data sandbox shared isolation trust assurance method as claimed in claim 1, characterized in that The method by which the client runtime measurement module performs triple verification on the response data described in step 5.3 is: 5.3.1 The client runtime measurement module verifies the validity of the signature using the public key of the server runtime measurement module's attestation key stored in it. If valid, proceed to 5.3.2; if not, proceed to 5.3.

5. 5.3.2 The client runtime metric module calculates the chained hash of the metric log entry and compares it with the chained hash returned by the server. If the comparison is successful, go to 5.3.3; if the comparison is unsuccessful, go to 5.3.

5. 5.3.3 The client runtime measurement module verifies each metric value in the returned log entry to ensure it is completely consistent with the client's pre-stored data sandbox image execution command sequence benchmark value. If they are consistent, all three verifications have passed, and go to 5.3.

4. If not, go to 5.3.

5. 5.3.4 The client runtime measurement module determines that the data sandbox operation status is credible and sends the data sandbox credibility information to the user. Go to 2.1.

4. 5.3.5 The client runtime measurement module determines that the data sandbox operation status is untrustworthy and sends the data sandbox untrustworthy information to the user, and then go to 2.1.

4.

9. A TEE-based data sandbox shared isolation trust assurance method as described in claim 1, characterized in that The method by which the data security storage module in step 6.1 securely stores the user's "registration request" parameters is: 6.1.1 The data security storage module calls the TEE_StoreEncryptedData interface to send the user's account and password to be registered in the "registration request" parameter to the TEE; 6.1.2 TEE checks the received account number in the current secure storage area to see if the account number already exists. If it does, registration has failed and the process goes to 6.1.

4. Otherwise, the process goes to 6.1.

3. 6.1.3 TEE encrypts the registered account and stores the encrypted password of the account to be registered in a secure storage area; If the storage is successful, the data security storage module sends the registration success information to the data sandbox management module, which returns the registration success information to the user and goes to 2.1.4; If the storage fails, go to 6.1.5; 6.1.4 If registration fails, the Data Security Storage Module will send the registration failure information to the Data Sandbox Management Module, which will then return the registration failure information to the user and proceed to 2.1.

4. 6.1.5 If storage fails, the data security storage module sends the storage failure information to the data sandbox management module, which then returns the registration failure information to the user and goes to 2.1.

4.

10. A TEE-based data sandbox shared isolation trust assurance method as claimed in claim 1, characterized in that The method by which the data security storage module in step 6.2 securely stores the "login request" parameters is as follows: 6.2.1 The data security storage module calls the TEE_AccessEncryptedData interface of the TEE to send the account and password in the "login request" parameter to the TEE; 6.2.2 The TEE reads the corresponding secure storage data from the secure storage area based on the account number in the "Login Request" parameter, finds the password for the corresponding account, and verifies it within the TEE. The TEE compares the password in the "Login Request" with the password in the secure storage area. If they match, the user login information is correct and a login success message is sent to the data security storage module. Go to 6.2.

3. If they do not match, the user login information is incorrect and a login failure message is sent to the data security storage module. Go to 6.2.

4. 6.2.3 If the login is successful, the Data Security Storage Module will send the login success information to the Data Sandbox Management Module, which will then return the login success information to the user and proceed to 2.1.

4. 6.2.4 If the login fails, the data security storage module will send the login failure information to the data sandbox management module, which will return the login failure information to the user and go to 2.1.1.

Citation Information

Patent Citations

  • Preparation method of composite nano lubricating oil for steel-steel friction pair

    CN116925837A

  • Public data development method and device based on data sandbox

    CN119089487A