Remote attestation method and device based on trusted execution environment, medium, equipment and product
By remotely proving and enhancing the security of the collection service in a confidential cloud computing environment, the issue of whether the collection service collects data in accordance with user rules is resolved, the credibility and security of operation and maintenance data are ensured, and the credibility verification of the collection service and the security of the data are achieved.
Patent Information
- Application Number
- CN202511028226.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-07-24
AI Technical Summary
In a confidential cloud computing environment, how to verify whether the collection service collects and processes operation and maintenance data according to user-specified rules to ensure the credibility and security of the data.
By deploying the collection service in a trusted execution environment, obtaining the measurement values of the loaded collection rules and the measurement baseline values of the configured collection rules, remote attestation is performed to determine whether the collection service is trustworthy, including credibility verification of the collection service and its image, and security enhancement processing of operation and maintenance data.
Ensuring that the collection service collects data according to the rules set by the user improves the credibility and security of operation and maintenance data, prevents data leakage and tampering, and realizes the credibility verification of services in confidential virtual machines.
Smart Images

Figure CN120602215A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a remote attestation method, apparatus, medium, device, and product based on a trusted execution environment. Background Art
[0002] Confidential cloud computing is a technology that efficiently processes sensitive data within a secure, hardware-protected, isolated environment. The confidentiality and integrity of the contents within this isolated environment (the processed data and the code used to process it) are guaranteed, and other entities, including the Basic Input Output System (BIOS) and the operating system, cannot access the contents within the isolated environment. Confidential cloud computing leverages a Trusted Execution Environment (TEE) to ensure data privacy and security during computing. This means that only authorized applications can securely access sensitive data, while unauthorized applications cannot spy on or steal sensitive data.
[0003] With the continued development of confidential cloud computing infrastructure and the services running on it, maintaining the services running within confidential virtual machines (VMs) is becoming increasingly important. Providers of confidential cloud computing infrastructure require maintenance capabilities to monitor resource allocation and promptly identify potential performance bottlenecks and security risks. Users of confidential cloud computing services, on the other hand, urgently need maintenance data to conduct in-depth analysis of the actual usage of leased resources and ensure the stable operation of their own services. Related technologies typically utilize collection services deployed on confidential cloud computing to collect maintenance data, which raises the question of how to verify the trustworthiness and security of these collection services. Summary of the Invention
[0004] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] In a first aspect, the present disclosure provides a remote attestation method based on a trusted execution environment, comprising: Receiving a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; Obtaining a first metric value of a first collection rule loaded by the first collection service, and obtaining a first metric reference value of a configured collection rule of the first collection service; wherein the configured collection rule is a collection rule pre-configured for the first collection service, and the first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule; The first collection rule is remotely proven based on the first metric value and the first metric reference value to determine whether the first collection service is trustworthy.
[0006] In a second aspect, the present disclosure provides a remote attestation device based on a trusted execution environment, comprising: A receiving module, configured to receive a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; a first acquisition module, configured to acquire a first metric value of a first acquisition rule loaded by the first acquisition service, and to acquire a first metric reference value of a configured acquisition rule of the first acquisition service; wherein the configured acquisition rule is a collection rule pre-configured for the first acquisition service, and the first acquisition service is configured to collect operation and maintenance data of the first service in the virtual machine based on the first acquisition rule; The first remote attestation module is configured to remotely attest to the first collection rule based on the first metric value and the first metric reference value, so as to determine whether the first collection service is trustworthy.
[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the remote attestation method based on a trusted execution environment provided in the first aspect of the present disclosure.
[0008] In a fourth aspect, the present disclosure provides an electronic device comprising: a storage device storing a computer program; and a processing device for executing the computer program in the storage device to implement the steps of the remote attestation method based on a trusted execution environment provided in the first aspect of the present disclosure.
[0009] In a fifth aspect, the present disclosure provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the remote attestation method based on a trusted execution environment provided in the first aspect of the present disclosure.
[0010] In the above technical solution, a remote attestation request is received for a first collection service, where the first collection service is deployed in a virtual machine (i.e., a confidential virtual machine) in a trusted execution environment. Then, a first metric value of a first collection rule loaded by the first collection service and a first metric baseline value of a configuration collection rule of the first collection service are obtained. The first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule. Finally, based on the first metric value and the first metric baseline value, the first collection rule is remotely attested to determine whether the first collection service is trustworthy. In this way, remote attestation technology can be combined to verify the credibility of whether the collection service used to collect the operation and maintenance data of the first service has indeed loaded the user-configured collection rules, thereby proving that the collection service running in the confidential virtual machine is trustworthy, thereby ensuring the credibility of the exposed operation and maintenance data.
[0011] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1 The present invention is a flowchart showing a remote attestation method based on a trusted execution environment according to an exemplary embodiment.
[0013] Figure 2 The figure is a flowchart showing a method for collecting service metrics according to an exemplary embodiment.
[0014] Figure 3 The figure is a flowchart showing a method for collecting service metrics according to an exemplary embodiment.
[0015] Figure 4 The figure is a schematic diagram showing a security design framework for a confidential virtual machine according to an exemplary embodiment.
[0016] Figure 5 The figure is a schematic diagram showing a security design framework for a confidential virtual machine according to another exemplary embodiment.
[0017] Figure 6 The present invention is a block diagram showing a remote attestation device based on a trusted execution environment according to an exemplary embodiment.
[0018] Figure 7 The figure is a schematic structural diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0019] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0020] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0021] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.
[0022] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0023] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0024] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0025] It is understandable that before using the technical solutions disclosed in the various embodiments of the present disclosure, the type, scope of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to relevant users and authorization should be obtained from relevant users in an appropriate manner in accordance with relevant laws and regulations. The relevant users may include any type of right holders, such as individuals, enterprises, and groups.
[0026] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can independently choose whether to provide information to the software or hardware such as the electronic device, application, server or storage medium that executes the operation of the technical solution of the present disclosure based on the prompt message.
[0027] As an optional but non-limiting implementation, in response to receiving an active request from a relevant user, a prompt message may be sent to the relevant user in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide information to the electronic device.
[0028] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0029] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0030] Figure 1 FIG. 1 is a flow chart showing a remote certification method based on a trusted execution environment according to an exemplary embodiment. Figure 1 As shown, the remote attestation method based on a trusted execution environment may include the following S101 to S103.
[0031] In S101 , a remote attestation request for a first acquisition service is received, where the first acquisition service is deployed in a virtual machine in a trusted execution environment.
[0032] In S102 , a first metric value of a first collection rule loaded by a first collection service is obtained, and a first metric reference value of a configured collection rule of the first collection service is obtained.
[0033] In this disclosure, a configured collection rule is a collection rule pre-configured for a first collection service. The first collection rule is the collection rule actually used by the first collection service when collecting operation and maintenance data for the first service. The first collection service is used to collect operation and maintenance data of the first service in a confidential virtual machine (i.e., a virtual machine deployed in a TEE) based on the first collection rule. The configured collection rule is used to instruct the first collection service on which business services in the confidential virtual machine to collect which data. For example, the configured collection rule is used to instruct the first collection service to collect log data from the first service in the confidential virtual machine.
[0034] The first metric reference value of the configuration rule of the first collection service may be a hash value of the configuration collection rule of the first collection service, and the first metric value of the first collection rule loaded by the first collection service may be a hash value of the first collection rule loaded by the first collection service.
[0035] The first service is deployed in a virtual machine and may include one or more business services in the virtual machine. The operation and maintenance data of the first service may include at least one of log data, event data, and indicator data (e.g., CPU occupancy). Different types of operation and maintenance data of the first service may be collected by different types of collection services (collectors). Multiple collection services may be deployed in a confidential virtual machine. The types of operation and maintenance data collected by some of the multiple collection services may be the same, or multiple collection services may be used to collect different types of operation and maintenance data. The first collection service is any collection service deployed in the confidential virtual machine and may be used to collect one of log data, event data, and indicator data.
[0036] In S103 , the first collection rule is remotely proven based on the first metric value and the first metric reference value to determine whether the first collection service is trustworthy.
[0037] In this disclosure, remote attestation is designed for the transparent verification of TEE. It integrates the full-link capabilities of environmental measurement, attestation report acquisition, and attestation verification, helping cloud users to complete the security verification of TEE and load quickly and conveniently.
[0038] When a user wants to verify whether the first collection service running in a confidential virtual machine collects the operation and maintenance data of the corresponding business service in accordance with the collection rules specified by the user, in order to verify whether the first collection service will maliciously collect, forward, modify or lose the operation and maintenance data of the business service, a remote attestation instruction for the first collection service can be initiated through an application deployed in a non-TEE. After receiving the remote attestation instruction, the application sends a remote attestation request for the first collection service to the remote attestation service deployed in the confidential virtual machine; after receiving the remote attestation request, the remote attestation service can remotely attest that the collection service has actually loaded the collection rules set by the user to verify the credibility of the first collection service, that is, the credibility verification of the first collection service may include at least one of the verifications of whether the first collection service has indeed loaded the collection rules set by the user.
[0039] After obtaining the first metric value and the first metric reference value, the two can be compared for consistency to remotely prove the first collection rule, thereby determining whether the first collection rule is credible, and thus determining whether the first collection service is credible. Specifically, if the first metric value and the first metric reference value are consistent, then the first collection rule is determined to be credible, that is, the first collection service has indeed loaded the collection rule set by the user. At this time, it can be determined that the first collection service is credible; if the first metric value and the first metric reference value are inconsistent, then the first collection rule is determined to be untrustworthy, that is, the first collection service has not correctly loaded the collection rule set by the user, for example, the collection rule is missed, the collection rule is loaded more than once, or the collection rule is modified. At this time, it can be determined that the first collection service is untrustworthy.
[0040] In the above technical solution, a remote attestation request is received for a first collection service, where the first collection service is deployed in a virtual machine (i.e., a confidential virtual machine) in a trusted execution environment. Then, a first metric value of a first collection rule loaded by the first collection service and a first metric baseline value of a configuration collection rule of the first collection service are obtained. The first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule. Finally, based on the first metric value and the first metric baseline value, the first collection rule is remotely attested to determine whether the first collection service is trustworthy. In this way, remote attestation technology can be combined to verify the credibility of whether the collection service used to collect the operation and maintenance data of the first service has indeed loaded the user-configured collection rules, thereby proving that the collection service running in the confidential virtual machine is trustworthy, thereby ensuring the credibility of the exposed operation and maintenance data.
[0041] In one possible implementation, the credibility verification of the first acquisition service may include not only verifying whether the first acquisition service has actually loaded the acquisition rules set by the user, but also verifying the credibility of the image of the first acquisition service. This allows not only verification of whether the first acquisition service has actually loaded the acquisition rules set by the user, but also simultaneous credibility verification of the image of the first acquisition service, thereby enhancing the credibility of the first acquisition service. In this case, the remote attestation method based on a trusted execution environment, in addition to steps S101 to S103, may also include the following two steps: Obtain a second metric value and a second metric reference value of the first image of the first acquisition service; The first image is remotely certified according to the second measurement value and the second measurement reference value to determine whether the first acquisition service is trustworthy.
[0042] In the present disclosure, the second measurement value of the first image of the first acquisition service can be obtained by calculating the content of the first image using a hash algorithm. The second measurement reference value of the first image of the first acquisition service can be the baseline measurement value of the first image of the first acquisition service, which can be reproduced through the first image.
[0043] After obtaining the second metric value and the second metric reference value, the two can be compared for consistency to remotely attest the first image of the first acquisition service, thereby determining whether the first image of the first acquisition service is trustworthy, and further determining whether the first acquisition service is trustworthy. Specifically, if the second metric value and the second metric reference value are consistent, the first image of the first acquisition service is determined to be trustworthy; if the second metric value and the second metric reference value are inconsistent, the first image of the first acquisition service is determined to be untrustworthy.
[0044] Among them, when the first acquisition service does load the acquisition rules set by the user and the first image of the first acquisition service is trustworthy, it can be determined that the first acquisition service is trustworthy; if the first acquisition service does not correctly load the acquisition rules set by the user, or the first image of the first acquisition service is untrustworthy, it can be determined that the first acquisition service is untrustworthy.
[0045] The following describes in detail the specific implementation of obtaining the first measurement value of the first collection rule loaded by the first collection service in S102. Specifically, after the configuration collection rule of the first collection service is created, the first collection rule loaded by the first collection service can be measured to obtain the first measurement value. In this way, after receiving the remote attestation request, the pre-measured first measurement value can be directly obtained. Specifically, the above-mentioned remote attestation method based on the trusted execution environment can also include the following two steps: Use the detection service to check whether the configuration collection rules have been created; When the detection service detects that a configuration collection rule is created, the first collection rule is measured to obtain a first measurement value.
[0046] In this disclosure, the detection service is deployed in the above virtual machine, such as Figure 2 S201 and Figure 3 As shown in S301 in , a detection service can be created in the above virtual machine through kubernetes (K8s for short), and the detection service is used to detect whether the user has created the configuration collection rules of the first collection service; Figure 2 S204 and Figure 3 As shown in S305 , after the detection service detects that the user has created a configuration collection rule for the first collection service, the first collection rule loaded by the first collection service may be measured to obtain a first measurement value.
[0047] K8s is an open-source abbreviation for managing containerized applications across multiple hosts in a cloud platform.
[0048] In one possible implementation, the above-mentioned remote attestation method based on a trusted execution environment may further include the following three steps: Use the detection service to check whether the configuration collection rules are updated; When the detection service detects that the configuration collection rule is updated, re-measure the first collection rule loaded by the first collection service to obtain a new first metric value, and determine a new first metric reference value corresponding to the updated configuration collection rule; The first metric value is updated to a new first metric value, and the first metric reference value is updated to a new first metric reference value.
[0049] In the present disclosure, during the operation of the first collection service, the user can dynamically update the configuration collection rules of the first collection service, for example, add some collection rules, modify the configured collection rules or delete some collection rules. During this period, the detection service can be used to detect whether the configuration collection rules are updated; when the configuration collection rule update is detected by the detection service, in order to ensure the real-time accuracy of the first metric value and the first metric reference value, the first collection rule loaded by the first collection service can be re-measured to obtain a new first metric value, and the new first metric reference value corresponding to the updated configuration collection rule is determined, and the first metric value is updated to the new first metric value, and the first metric reference value is updated to the new first metric reference value.
[0050] In the above implementation, the collection rules of the first collection service can be dynamically updated during the operation of the first collection service, and the updated configuration collection rules can be dynamically loaded into the first collection service, thereby improving the flexibility of the configuration collection rules and supporting the verification of the dynamically updated collection rules.
[0051] In one possible implementation, in order to further enhance the credibility of the first acquisition service, in addition to verifying the credibility of the image and acquisition rules of the first acquisition service, the credibility of the detection service on which the first acquisition service relies can also be verified. Specifically, the remote attestation method based on a trusted execution environment can further include the following steps: Remotely attest the testing service to verify its credibility.
[0052] In one embodiment, the fifth metric value and the fifth metric reference value of the fourth image of the detection service may be obtained first, and then the fourth image may be remotely certified based on the fifth metric value and the fifth metric reference value to determine whether the fourth image is trustworthy.
[0053] After obtaining the fifth metric value and the fifth metric reference value, the two can be compared for consistency to remotely attest the fourth image of the detection service, thereby determining whether the fourth image of the detection service is trustworthy. Specifically, if the fifth metric value and the fifth metric reference value are consistent, the fourth image of the detection service is determined to be trustworthy; if the fifth metric value and the fifth metric reference value are inconsistent, the fourth image of the detection service is determined to be untrustworthy.
[0054] In the present disclosure, the fifth metric value of the fourth image of the detection service can be obtained by calculating the content of the fifth image using a hash algorithm. The fifth metric reference value of the fourth image of the detection service can be the baseline metric value of the fourth image of the detection service, which can be reproduced through the fourth image.
[0055] The following describes in detail the specific implementation method for obtaining the fifth metric value of the fourth image of the detection service. Specifically, Figure 2 S202 and Figure 3 As shown in S303, after the detection service is created, the fifth image of the detection service can be measured to obtain a fifth measurement value. In this way, after receiving the remote attestation request, the pre-measured fifth measurement value can be directly obtained. Specifically, the remote attestation method based on the trusted execution environment can also include the following steps: When the detection service is created, the fifth image of the detection service is measured to obtain a fifth measurement value.
[0056] The following describes in detail the specific implementation method for obtaining the second metric value of the first image of the first acquisition service. Figure 2 S202 and Figure 3 As shown in S303, after the first acquisition service is created, the first image of the first acquisition service can be measured to obtain a second measurement value. In this way, after receiving the remote attestation request, the pre-measured second measurement value can be directly obtained. Specifically, the remote attestation method based on the trusted execution environment can also include the following steps: When the first acquisition service is created, the first image of the first acquisition service is measured to obtain a second measurement value.
[0057] In the present disclosure, the first acquisition service can be created in a variety of ways. Figure 2 As shown in S201, the first collection service can be created while creating the detection service through K8s.
[0058] In another embodiment, Figure 3As shown, you can first create a detection service through K8s, and then use the detection service to detect whether the custom resource (CR) of the first collection service has been created. After the detection service detects that the CR of the first collection service has been created, you can create the first collection service based on the CR (as shown in Figure 3 ).
[0059] In addition to verifying the collection service in the confidential virtual machine, the number of all services in the confidential virtual machine can also be verified to prevent unintended services from maliciously collecting operation and maintenance data in the confidential virtual machine. The above-mentioned remote attestation method based on the trusted execution environment can also include the following two steps: Perform remote attestation on all services in the virtual machine and obtain remote attestation results; According to the remote certification result and the first information of the registered service in the virtual machine, it is determined whether there is an unregistered service deployed in the virtual machine.
[0060] In this disclosure, all of the above services include various services such as collection services, business services, detection services, and remote attestation services deployed in confidential virtual machines. All services include not only registered services but also unregistered services. Among them, registered services refer to services in confidential virtual machines that have been officially recorded and managed by confidential virtual machines. The configuration, operating status, and functions of these services are known and can be maintained. Unregistered services refer to services in confidential virtual machines that have not been officially recorded and managed by confidential virtual machines. These services are not included in the management scope and are difficult to manage uniformly.
[0061] In one embodiment, each of all services in a confidential virtual machine may be remotely attested to obtain a remote attestation result, wherein the remote attestation result includes at least one of a first service identifier of each service in all services, a third measurement value of a second image of each service in all services, and a third measurement reference value of a second image of each service in all services. The first information may include a second service identifier of a registered service, a fourth measurement value of a third image of a registered service, and a fourth measurement reference value of the third image, wherein the second service identifier of a registered service includes the service identifier of each registered service in the above-mentioned virtual machine, the fourth measurement value of the third image of a registered service includes the respective measurement value of the image of each registered service in the above-mentioned virtual machine, and the fourth measurement reference value of the third image of a registered service includes the respective measurement reference value of the image of each registered service in the above-mentioned virtual machine.
[0062] The following is a detailed description of the specific implementation method for determining whether an unregistered service is deployed in a virtual machine based on the remote attestation result and the first information of the registered service in the virtual machine. Specifically, it can be achieved through a variety of implementation methods. In one implementation method, when the remote attestation result includes the first service identifier of each service in all services, and the first information can include the second service identifier of the registered service, it can be determined whether an unregistered service is deployed in the virtual machine by comparing the remote attestation result with the service identifier in the first information. Specifically, if there is a first service identifier that is not included in the second service identifier, it is determined that an unregistered service is deployed in the virtual machine, wherein the service corresponding to the first service identifier that is not located in the second service identifier is an unregistered service; if all the first service identifiers are located in the second service identifier, it is determined that no unregistered service is deployed in the virtual machine, that is, all services deployed in the virtual machine are registered services.
[0063] In another embodiment, when the remote attestation result includes the third metric value of each service among all services, and the first information may include the fourth metric value of the registered service, it can be determined whether an unregistered service is deployed in the virtual machine by comparing the remote attestation result with the metric value in the first information. Specifically, if there is a third metric value that is not included in the fourth metric value, it is determined that an unregistered service is deployed in the virtual machine, wherein the service corresponding to the third metric value that is not included in the fourth metric value is an unregistered service; if all third metric values are included in the fourth metric value, it is determined that no unregistered service is deployed in the virtual machine, that is, all services deployed in the virtual machine are registered services.
[0064] In another embodiment, when the remote attestation result includes the third metric reference value of each service among all services, and the first information may include the fourth metric reference value of the registered service, it can be determined whether an unregistered service is deployed in the virtual machine by comparing the remote attestation result with the metric reference value in the first information. Specifically, if there is a third metric reference value that is not included in the fourth metric reference value, it is determined that an unregistered service is deployed in the virtual machine, wherein the service corresponding to the third metric reference value that is not in the fourth metric reference value is an unregistered service; if all the third metric reference values are in the fourth metric reference value, it is determined that no unregistered service is deployed in the virtual machine, that is, all services deployed in the virtual machine are registered services.
[0065] In addition to verifying the credibility of the collection service running in the confidential virtual machine to ensure the credibility of the exposed operation and maintenance data, it is also possible to perform security enhancement processing on the operation and maintenance data before it enters the non-TEE, thereby ensuring the observability of the operation and maintenance data while ensuring the security of the exposed operation and maintenance data. Specifically, the above-mentioned remote attestation method based on the trusted execution environment also includes the following two steps: Performing security enhancement processing on the operation and maintenance data of the first service in the virtual machine; The operation and maintenance data after security enhancement is stored in the database.
[0066] like Figure 4 and Figure 5 As shown, the database is deployed in a non-TEE. After obtaining security-enhanced operation and maintenance data through the first collection service, it can be stored in the database in the non-TEE to display this operation and maintenance data and generate alarm information based on this operation and maintenance data. For example, if the CPU occupancy rate of a confidential virtual machine exceeds a preset occupancy rate threshold, a first alarm information will be generated. Security enhancement processing can include noise addition and desensitization.
[0067] In one embodiment, the operation and maintenance data of the first service can be security-enhanced by calling a software development kit through business code. In this way, the operation and maintenance data of the first service has been security-enhanced before entering the collection service. Specifically, the operation and maintenance data of the first service is the first type of operation and maintenance data generated by the first service during operation. The first type is any one of logs, events, and indicators. The first service is integrated with a first software development kit (SDK). At this time, the above-mentioned security-enhanced processing of the operation and maintenance data of the first service in the virtual machine may include: after the first service obtains the operation and maintenance data, the first service performs security-enhanced processing on the operation and maintenance data through the first SDK, and sends the security-enhanced operation and maintenance data to the first collection service; the above-mentioned storage of the security-enhanced operation and maintenance data in the database may include: the first collection service stores the received security-enhanced operation and maintenance data in the database. As Figure 2 S203 and Figure 3 As shown in S304 , after measuring the first service, a first service may be created.
[0068] like Figure 4 As shown, after obtaining the operation and maintenance data, the first service can perform security enhancement processing on the operation and maintenance data through the first SDK, and send the operation and maintenance data after security enhancement processing to the first collection service; after receiving the operation and maintenance data after security enhancement processing, the first collection service can store it in a database deployed in the non-TEE.
[0069] When the first type is an indicator, the first SDK can be used to perform noise processing on the operation and maintenance data. In this case, the first SDK can be Figure 4 When the first type is log or event, the first SDK can be used to desensitize the operation and maintenance data. In this case, the first SDK can be Figure 4 The desensitization SDK shown in .
[0070] In another embodiment, the operation and maintenance data of the first service can be security-enhanced through the SDK integrated in the acquisition service, so that the operation and maintenance data of the first service are security-enhanced after entering the acquisition service and before leaving the TEE. Specifically, the operation and maintenance data of the first service generates a first type of operation and maintenance data during operation, and the first type is any one of logs, events, and indicators. The first acquisition service is integrated with a second SDK; at this time, the above-mentioned security-enhanced processing of the operation and maintenance data of the first service in the virtual machine may include: after the first service obtains the operation and maintenance data of the first service, the first service sends the operation and maintenance data of the first service to the first acquisition service; the first acquisition service performs security-enhanced processing on the received operation and maintenance data of the first service through the second software development kit. The above-mentioned storing the security-enhanced operation and maintenance data in the database may include: the first acquisition service stores the security-enhanced operation and maintenance data in the database.
[0071] like Figure 5 As shown, after obtaining the operation and maintenance data, the first service can send the operation and maintenance data to the first collection service; after receiving the operation and maintenance data, the first collection service can perform security enhancement processing on the operation and maintenance data through the internally integrated second SDK, and store the security-enhanced operation and maintenance data in the database in the non-TEE.
[0072] When the first type is an indicator, the second SDK can be used to perform noise processing on the operation and maintenance data. In this case, the second SDK can be Figure 5 The noise adding SDK shown in ; when the first type is log or event, the second SDK can be used to desensitize the operation and maintenance data. At this time, the second SDK can be Figure 5 The desensitization SDK shown in .
[0073] Figure 6 FIG is a block diagram of a remote certification device based on a trusted execution environment according to an exemplary embodiment. Figure 6 As shown, the remote attestation device 400 based on the trusted execution environment includes: A receiving module 401 is configured to receive a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; A first acquisition module 402 is configured to acquire a first metric value of a first collection rule loaded by the first collection service, and to acquire a first metric reference value of a configured collection rule of the first collection service; wherein the configured collection rule is a collection rule pre-configured for the first collection service, and the first collection service is configured to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule; The first remote certification module 403 is used to remotely certify the first collection rule according to the first metric value and the first metric reference value to determine whether the first collection service is trustworthy.
[0074] In the above technical solution, a remote attestation request is received for a first collection service, where the first collection service is deployed in a virtual machine (i.e., a confidential virtual machine) in a trusted execution environment. Then, a first metric value of a first collection rule loaded by the first collection service and a first metric baseline value of a configuration collection rule of the first collection service are obtained. The first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule. Finally, based on the first metric value and the first metric baseline value, the first collection rule is remotely attested to determine whether the first collection service is trustworthy. In this way, remote attestation technology can be combined to verify the credibility of whether the collection service used to collect the operation and maintenance data of the first service has indeed loaded the user-configured collection rules, thereby proving that the collection service running in the confidential virtual machine is trustworthy, thereby ensuring the credibility of the exposed operation and maintenance data.
[0075] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: A first detection module, configured to detect whether the configuration collection rule is created by using a detection service, wherein the detection service is deployed in the virtual machine; The first measurement module is configured to measure the first collection rule to obtain the first measurement value when the detection service detects that the configuration collection rule is created.
[0076] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: A second detection module, configured to detect whether the configuration collection rule is updated through the detection service; The first measurement module is further configured to, when the detection service detects that the configuration collection rule is updated, re-measure the first collection rule loaded by the first collection service to obtain a new first measurement value, and determine a new first measurement reference value corresponding to the updated configuration collection rule; An updating module is configured to update the first metric value to the new first metric value, and to update the first metric reference value to the new first metric reference value.
[0077] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: The second remote certification module is used to remotely certify the detection service to verify the credibility of the detection service.
[0078] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: A second acquisition module, configured to acquire a second metric value and a second metric reference value of the first image of the first acquisition service; The third remote attestation module is configured to remotely attest to the first image based on the second measurement value and the second measurement reference value to determine whether the first acquisition service is trustworthy.
[0079] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: a fourth remote attestation module, configured to remotely attest all services in the virtual machine to obtain a remote attestation result; wherein the remote attestation result includes at least one of a first service identifier of each of the services, a third metric value of the second image of each of the services, and a third metric reference value of the second image of each of the services; A determination module is used to determine whether an unregistered service is deployed in the virtual machine based on the remote certification result and the first information of the registered service in the virtual machine; the first information includes the second service identifier of the registered service, the fourth measurement value of the third image of the registered service, and at least one of the fourth measurement reference value of the third image.
[0080] Optionally, the determining module includes any one of the following: a first determining submodule, configured to determine that an unregistered service is deployed in the virtual machine if there is the first service identifier that is not included in the second service identifier; a second determining submodule, configured to determine that an unregistered service is deployed in the virtual machine if the third metric value not included in the fourth metric value exists; The third determining submodule is configured to determine that an unregistered service is deployed in the virtual machine if there is the third metric reference value that is not included in the fourth metric reference value.
[0081] Optionally, the remote attestation device 400 based on a trusted execution environment further includes: A security enhancement module, configured to perform security enhancement processing on the operation and maintenance data in the virtual machine; A storage module is used to store the operation and maintenance data after security enhancement processing in a database; wherein the database is deployed in a non-trusted execution environment.
[0082] Optionally, the operation and maintenance data is a first type of operation and maintenance data generated during the operation of the first service, the first type being any one of a log, an event, and an indicator, and a first software development kit is integrated into the first service; The security enhancement module is used for the first service to perform security enhancement processing on the operation and maintenance data through the first software development kit after obtaining the operation and maintenance data, and send the operation and maintenance data after the security enhancement processing to the first collection service; The storage module is used for the first collection service to store the received operation and maintenance data after security enhancement processing in the database.
[0083] Optionally, when the first type is the indicator, the first software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the first software development kit is used to perform desensitizing processing on the operation and maintenance data.
[0084] Optionally, the operation and maintenance data is a first type of operation and maintenance data generated during the operation of the first service, the first type being any one of a log, an event, and an indicator, and a second software development kit is integrated into the first collection service; The security enhancement module includes: a sending submodule, configured to send the operation and maintenance data to the first collection service after the first service obtains the operation and maintenance data; a security enhancement submodule, configured for the first collection service to perform security enhancement processing on the received operation and maintenance data through the second software development kit; The storage module is used by the first collection service to store the operation and maintenance data after the security enhancement processing in the database.
[0085] Optionally, when the first type is the indicator, the second software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the second software development kit is used to perform desensitization processing on the operation and maintenance data.
[0086] The present disclosure also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the above-mentioned remote attestation method based on a trusted execution environment provided by the present disclosure.
[0087] The present disclosure also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the above-mentioned remote attestation method based on a trusted execution environment provided by the present disclosure.
[0088] Reference below Figure 7 , which shows a schematic diagram of the structure of an electronic device (e.g., a terminal device or a server) 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0089] like Figure 7 As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 602 or programs loaded from a storage device 608 into a random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.
[0090] Typically, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Figure 7 The electronic device 600 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0091] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0092] It should be noted that the computer-readable medium described above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.
[0093] In some embodiments, the client and server can communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0094] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0095] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: receives a remote attestation request for a first acquisition service; wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; obtains a first metric value of a first acquisition rule loaded by the first acquisition service, and obtains a first metric reference value of a configuration acquisition rule of the first acquisition service; wherein the configuration acquisition rule is a collection rule pre-configured for the first acquisition service, and the first acquisition service is used to collect operation and maintenance data of the first service in the virtual machine based on the first acquisition rule; remotely attests the first acquisition rule based on the first metric value and the first metric reference value to determine whether the first acquisition service is trustworthy.
[0096] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0097] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0098] The modules described in the embodiments of the present disclosure may be implemented in software or hardware. The name of a module does not, in some cases, limit the module itself. For example, a receiving module may also be described as a "module for receiving a remote attestation request for a first acquisition service."
[0099] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0100] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0101] According to one or more embodiments of the present disclosure, Example 1 provides a remote attestation method based on a trusted execution environment, including: Receiving a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; Obtaining a first metric value of a first collection rule loaded by the first collection service, and obtaining a first metric reference value of a configured collection rule of the first collection service; wherein the configured collection rule is a collection rule pre-configured for the first collection service, and the first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule; The first collection rule is remotely proven based on the first metric value and the first metric reference value to determine whether the first collection service is trustworthy.
[0102] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, further comprising: detecting whether the configuration collection rule is created by a detection service, wherein the detection service is deployed in the virtual machine; When the detection service detects that the configuration collection rule is created, the first collection rule is measured to obtain the first measurement value.
[0103] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2, wherein the method further includes: Detecting whether the configuration collection rule is updated through the detection service; When the detection service detects that the configuration collection rule is updated, re-measure the first collection rule loaded by the first collection service to obtain a new first metric value, and determine a new first metric reference value corresponding to the updated configuration collection rule; The first metric value is updated to the new first metric value, and the first metric reference value is updated to the new first metric reference value.
[0104] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2, further comprising: The detection service is remotely certified to verify the credibility of the detection service.
[0105] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 1, further comprising: Obtain a second metric value and a second metric reference value of the first image of the first acquisition service; The first image is remotely certified according to the second metric value and the second metric reference value to determine whether the first acquisition service is trustworthy.
[0106] According to one or more embodiments of the present disclosure, Example 6 provides the method of any one of Examples 1 to 5, further comprising: remotely attesting all services in the virtual machine to obtain a remote attestation result; wherein the remote attestation result includes at least one of a first service identifier of each of the services, a third metric value of the second image of each of the services, and a third metric reference value of the second image of each of the services; Based on the remote attestation result and the first information of the registered service in the virtual machine, determine whether an unregistered service is deployed in the virtual machine; the first information includes the second service identifier of the registered service, the fourth measurement value of the third image of the registered service, and at least one of the fourth measurement reference value of the third image.
[0107] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 6, wherein determining whether an unregistered service is deployed in the virtual machine based on the remote attestation result and the first information of the registered service in the virtual machine includes any of the following: If there is the first service identifier that is not included in the second service identifier, determining that an unregistered service is deployed in the virtual machine; If the third metric value exists but is not included in the fourth metric value, determining that an unregistered service is deployed in the virtual machine; If the third metric reference value exists but is not included in the fourth metric reference value, it is determined that an unregistered service is deployed in the virtual machine.
[0108] According to one or more embodiments of the present disclosure, Example 8 provides the method of any one of Examples 1 to 5, further comprising: Performing security enhancement processing on the operation and maintenance data in the virtual machine; The operation and maintenance data after security enhancement processing is stored in a database; wherein the database is deployed in a non-trusted execution environment.
[0109] According to one or more embodiments of the present disclosure, Example 9 provides the method of Example 8, wherein the operation and maintenance data is a first type of operation and maintenance data generated during operation of the first service, wherein the first type is any one of a log, an event, and an indicator, and a first software development kit is integrated into the first service; The performing security enhancement processing on the operation and maintenance data in the virtual machine includes: After acquiring the operation and maintenance data, the first service performs security enhancement processing on the operation and maintenance data through the first software development kit, and sends the security-enhanced operation and maintenance data to the first collection service; Storing the security-enhanced operation and maintenance data in the database includes: The first collection service stores the received operation and maintenance data after the security enhancement processing in the database.
[0110] According to one or more embodiments of the present disclosure, Example 10 provides the method of Example 9, wherein when the first type is the indicator, the first software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the first software development kit is used to perform desensitizing processing on the operation and maintenance data.
[0111] According to one or more embodiments of the present disclosure, Example 11 provides the method of Example 8, wherein the operation and maintenance data is a first type of operation and maintenance data generated during operation of the first service, wherein the first type is any one of a log, an event, and an indicator, and a second software development kit is integrated into the first collection service; The performing security enhancement processing on the operation and maintenance data in the virtual machine includes: After acquiring the operation and maintenance data, the first service sends the operation and maintenance data to the first collection service; The first collection service performs security enhancement processing on the received operation and maintenance data through the second software development kit; Storing the security-enhanced operation and maintenance data in the database includes: The first collection service stores the operation and maintenance data after the security enhancement processing in the database.
[0112] According to one or more embodiments of the present disclosure, Example 12 provides the method of Example 11, wherein when the first type is the indicator, the second software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the second software development kit is used to perform desensitization processing on the operation and maintenance data.
[0113] According to one or more embodiments of the present disclosure, Example 13 provides a remote attestation device based on a trusted execution environment, including: A receiving module, configured to receive a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; a first acquisition module, configured to acquire a first metric value of a first acquisition rule loaded by the first acquisition service, and to acquire a first metric reference value of a configured acquisition rule of the first acquisition service; wherein the configured acquisition rule is a collection rule pre-configured for the first acquisition service, and the first acquisition service is configured to collect operation and maintenance data of the first service in the virtual machine based on the first acquisition rule; The first remote attestation module is configured to remotely attest to the first collection rule based on the first metric value and the first metric reference value, so as to determine whether the first collection service is trustworthy.
[0114] According to one or more embodiments of the present disclosure, Example 14 provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in any one of Examples 1-12 when executed by a processing device.
[0115] According to one or more embodiments of the present disclosure, Example 15 provides an electronic device, including: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method described in any one of Examples 1-12.
[0116] According to one or more embodiments of the present disclosure, Example 16 provides a computer program product, including a computer program, which implements the steps of any one of the methods of Examples 1-12 when executed by a processor.
[0117] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the present disclosure is not limited to technical solutions formed by specific combinations of the aforementioned technical features. It also encompasses other technical solutions formed by any combination of the aforementioned technical features or their equivalents, without departing from the scope of the above disclosure. For example, a technical solution formed by replacing the aforementioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0118] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0119] Although the subject matter has been described using language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above-described embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated upon here.
Claims
1. A remote attestation method based on a trusted execution environment, characterized in that: include: Receiving a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; Obtaining a first metric value of a first collection rule loaded by the first collection service, and obtaining a first metric reference value of a configured collection rule of the first collection service; wherein the configured collection rule is a collection rule pre-configured for the first collection service, and the first collection service is used to collect operation and maintenance data of the first service in the virtual machine based on the first collection rule; The first collection rule is remotely proven based on the first metric value and the first metric reference value to determine whether the first collection service is trustworthy.
2. The method according to claim 1, characterized in that The method further comprises: detecting whether the configuration collection rule is created by a detection service, wherein the detection service is deployed in the virtual machine; When the detection service detects that the configuration collection rule is created, the first collection rule is measured to obtain the first measurement value.
3. The method according to claim 2, characterized in that The method further comprises: Detecting whether the configuration collection rule is updated through the detection service; When the detection service detects that the configuration collection rule is updated, re-measure the first collection rule loaded by the first collection service to obtain a new first metric value, and determine a new first metric reference value corresponding to the updated configuration collection rule; The first metric value is updated to the new first metric value, and the first metric reference value is updated to the new first metric reference value.
4. The method according to claim 2, characterized in that The method further comprises: The detection service is remotely certified to verify the credibility of the detection service.
5. The method according to claim 1, wherein The method further comprises: Obtain a second metric value and a second metric reference value of the first image of the first acquisition service; The first image is remotely certified according to the second metric value and the second metric reference value to determine whether the first acquisition service is trustworthy.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: remotely attesting all services in the virtual machine to obtain a remote attestation result; wherein the remote attestation result includes at least one of a first service identifier of each of the services, a third metric value of the second image of each of the services, and a third metric reference value of the second image of each of the services; Based on the remote attestation result and the first information of the registered service in the virtual machine, determine whether an unregistered service is deployed in the virtual machine; the first information includes the second service identifier of the registered service, the fourth measurement value of the third image of the registered service, and at least one of the fourth measurement reference value of the third image.
7. The method according to claim 6, characterized in that The determining, based on the remote attestation result and the first information of the registered service in the virtual machine, whether an unregistered service is deployed in the virtual machine includes any one of the following: If there is the first service identifier that is not included in the second service identifier, determining that an unregistered service is deployed in the virtual machine; If the third metric value exists but is not included in the fourth metric value, determining that an unregistered service is deployed in the virtual machine; If the third metric reference value exists but is not included in the fourth metric reference value, it is determined that an unregistered service is deployed in the virtual machine.
8. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Performing security enhancement processing on the operation and maintenance data in the virtual machine; The operation and maintenance data after security enhancement processing is stored in a database; wherein the database is deployed in a non-trusted execution environment.
9. The method according to claim 8, characterized in that The operation and maintenance data is a first type of operation and maintenance data generated during the operation of the first service, wherein the first type is any one of a log, an event, and an indicator, and a first software development kit is integrated into the first service; The performing security enhancement processing on the operation and maintenance data in the virtual machine includes: After acquiring the operation and maintenance data, the first service performs security enhancement processing on the operation and maintenance data through the first software development kit, and sends the security-enhanced operation and maintenance data to the first collection service; Storing the security-enhanced operation and maintenance data in the database includes: The first collection service stores the received operation and maintenance data after the security enhancement processing in the database.
10. The method according to claim 9, characterized in that When the first type is the indicator, the first software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the first software development kit is used to perform desensitization processing on the operation and maintenance data.
11. The method according to claim 8, characterized in that The operation and maintenance data is a first type of operation and maintenance data generated during the operation of the first service, the first type being any one of logs, events, and indicators, and a second software development kit is integrated into the first collection service; The performing security enhancement processing on the operation and maintenance data in the virtual machine includes: After acquiring the operation and maintenance data, the first service sends the operation and maintenance data to the first collection service; The first collection service performs security enhancement processing on the received operation and maintenance data through the second software development kit; Storing the security-enhanced operation and maintenance data in the database includes: The first collection service stores the operation and maintenance data after the security enhancement processing in the database.
12. The method according to claim 11, characterized in that When the first type is the indicator, the second software development kit is used to perform noise processing on the operation and maintenance data; When the first type is the log or the event, the second software development kit is used to perform desensitization processing on the operation and maintenance data.
13. A remote attestation device based on a trusted execution environment, characterized in that: include: A receiving module, configured to receive a remote attestation request for a first acquisition service, wherein the first acquisition service is deployed in a virtual machine in a trusted execution environment; a first acquisition module, configured to acquire a first metric value of a first acquisition rule loaded by the first acquisition service, and to acquire a first metric reference value of a configured acquisition rule of the first acquisition service; wherein the configured acquisition rule is a collection rule pre-configured for the first acquisition service, and the first acquisition service is configured to collect operation and maintenance data of the first service in the virtual machine based on the first acquisition rule; The first remote attestation module is configured to remotely attest to the first collection rule based on the first metric value and the first metric reference value, so as to determine whether the first collection service is trustworthy.
14. A computer-readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 12 are implemented.
15. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 12.
16. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Data processing method, device and equipment
CN114553516A
Virtual machine measurement and confidential calculation authentication method, equipment, system and storage medium
CN117453343A
Remote attestation method and device, electronic equipment and storage medium
CN117834627A
Security verification method for large model service operation environment, medium, equipment and product
CN120354404A