Data processing method
By establishing a trusted connection between the computing device and the confidential virtual machine at the control end, a direct communication link and key negotiation between the devices are realized, which solves the transmission delay problem and improves the communication efficiency between computing devices.
Patent Information
- Application Number
- CN202511493102.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-20
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-10-20
AI Technical Summary
Communication between different computing devices requires forwarding through confidential virtual machines or third-party devices, which increases transmission latency and affects task processing efficiency.
The control terminal determines the trusted connection between the computing device and the confidential virtual machine, establishes a direct communication link between the computing devices, negotiates the communication key, records the interconnection information, and enables direct communication between the devices.
It reduces transmission latency, improves communication efficiency between different computing devices, and facilitates efficient processing of tasks on different computing devices.
Smart Images

Figure CN120973479A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a data processing method. BACKGROUND
[0002] Currently, a confidential virtual machine can perform a task by using multiple computing devices. If different computing devices need to communicate, the confidential virtual machine needs to be used as a data forwarding station between different computing devices or other third-party devices are used to realize data forwarding between different computing devices. This forwarding communication mode increases transmission delay, which is not conducive to efficient processing of the task.
[0003] Therefore, how to improve the communication efficiency between different computing devices is a problem to be solved by those skilled in the art. SUMMARY
[0004] Therefore, how to improve the communication efficiency between different computing devices is a problem to be solved by those skilled in the art.
[0005] In a first aspect, the present application provides a data processing method applied to a control terminal, the control terminal being connected to a confidential virtual machine and multiple computing devices, and the method comprises the following steps: receiving a target request sent by the confidential virtual machine, the target request being used to make at least two computing devices directly connected; judging whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending directly-connectable information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other; and after confirming that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other, recording interconnection information of each direct communication link.
[0006] In a second aspect, the present application provides a data processing method applied to a confidential virtual machine, and the method comprises the following steps: sending a target request to a control terminal, the target request being used to make at least two computing devices directly connected, so that the control terminal judges whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending directly-connectable information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other; and after confirming that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other, recording interconnection information of each direct communication link. The confidential virtual machine is connected to the control terminal, the control terminal is connected to multiple computing devices, and the at least two computing devices are part of the multiple computing devices or all of the multiple computing devices.
[0007] In a third aspect, the present application provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the data processing method disclosed above.
[0008] In a fourth aspect, the present application provides a non-volatile storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the data processing method disclosed above.
[0009] In a fifth aspect, the present application provides a computer program product, comprising computer programs / instructions, which, when executed by a processor, implement the steps of the data processing method disclosed above.
[0010] According to the above scheme, the present application provides a data processing method, applied to a control terminal connected to a confidential virtual machine and a plurality of computing devices, comprising: receiving a target request for direct connection of at least two computing devices sent by the confidential virtual machine; determining whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other; and after confirming that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other, recording interconnection information of each direct communication link.
[0011] It can be seen that the present application has the following beneficial effects: the control terminal can establish direct communication links between different computing devices connected to the confidential virtual machine in a trusted manner based on the target request for direct connection of at least two computing devices sent by the confidential virtual machine, and record the corresponding interconnection information. Thus, different computing devices connected to the same confidential virtual machine in a trusted manner can communicate directly through the direct communication links connected to each other, without the need for data forwarding through the confidential virtual machine or other third-party devices, which can reduce transmission delay and improve communication efficiency between different computing devices, and is conducive to efficient processing of tasks on different computing devices.
[0012] Correspondingly, the electronic device, medium and program product provided by the present application also have the above technical effects. BRIEF DESCRIPTION OF DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.
[0014] Figure 1 A data processing method flow chart disclosed by the present application; Figure 2 A data processing system schematic diagram disclosed by the present application; Figure 3 An equipment information representation diagram disclosed by the present application; Figure 4 Another data processing system schematic diagram disclosed by the present application; Figure 5 An electronic equipment schematic diagram disclosed by the present application; Figure 6 A server structure diagram provided by the present application; Figure 7 A terminal structure diagram provided by the present application. DETAILED DESCRIPTION
[0015] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the protection scope of the present application.
[0016] It should be noted that, in the description of the present application, the terms "comprise", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. The terms "first", "second" and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence.
[0017] In order for those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the drawings and specific embodiments.
[0018] At present, a confidential virtual machine can perform a task by using multiple computing devices. If different computing devices need to communicate, the confidential virtual machine needs to be used as a data forwarding station between different computing devices or other third-party devices are used to realize data forwarding between different computing devices; this forwarding communication mode increases transmission delay, which is not conducive to efficient processing of tasks. Therefore, the present application provides a data processing scheme, which can reduce the transmission delay between different computing devices, improve the communication efficiency between different computing devices, and is conducive to efficient processing of tasks on different computing devices.
[0019] Referring to Figure 1As shown, the embodiment of the present application discloses a data processing method, applied to a control terminal, the control terminal is connected with a confidential virtual machine and a plurality of computing devices, comprising: S101, receiving a target request sent by the confidential virtual machine, the target request is used to make at least two computing devices directly connected.
[0020] It should be noted that the confidential virtual machine is any one of the confidential virtual machines connected with the control terminal. That is, the control terminal is connected with at least one confidential virtual machine. The computing device can be a CPU computing card, an FPGA board card or other acceleration device. In the target request, the IP address, model, manufacturer, type and other identification information of the computing device to be directly connected can be specified.
[0021] S102, judging whether the at least two computing devices are all connected with the confidential virtual machine to establish a trusted communication connection; if yes, executing S103; otherwise, executing S105.
[0022] In the embodiment, the process of establishing a trusted communication connection between the confidential virtual machine and any computing device includes: in an embodiment, further comprising: receiving a device connection request sent by the confidential virtual machine; determining the connection requirement of the confidential virtual machine according to the device connection request; selecting a target device matching the connection requirement from the computing devices connected with the control terminal and not allocated to any confidential virtual machine; after recording the label of the confidential virtual machine and the allocation information allocated to the confidential virtual machine in the device information of the target device, sending the device information of the target device to the confidential virtual machine, so that the confidential virtual machine establishes a trusted communication connection with the target device with the control terminal as a communication relay station, and negotiates a communication key; the communication key is used for the confidential virtual machine and the target device to communicate in cipher text, that is, the confidential virtual machine and the target device encrypt any data to be transmitted by using the communication key, to realize the cipher text communication between the two, and the communication process does not need to involve the control terminal. The connection requirement can include the device type, device manufacturer, and performance parameters such as the size of the device memory and the size of the device computing power.
[0023] It should be noted that after the confidential virtual machine and the target device establish a trusted communication connection and negotiate a communication key, the control terminal also needs to be reported to the control terminal, and the specific process includes: receiving a trusted confirmation message of the target device sent by the confidential virtual machine and the target device after completing the negotiation of the communication key; in response to the trusted confirmation message, recording the confirmation information trusted by the confidential virtual machine in the device information of the target device.
[0024] In this embodiment, the control terminal is trusted by the confidential virtual machine and the plurality of computing devices connected thereto, and thus the control terminal can record: which computing devices are connected to a confidential virtual machine, and which of these computing devices have a direct communication link; the IP address, label and other identification information of each confidential virtual machine; the IP address, model, manufacturer, type and other identification information of each computing device. Further, in order to more orderly and accurately implement the management of the devices and connections, the control terminal records a set of device information for each computing device, including: the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, the interconnection information field, etc. For example: computing device 1 is allocated to confidential virtual machine 1 and trusted by confidential virtual machine 1, and thus the device information of computing device 1 can record: the label of confidential virtual machine 1, the time allocated to confidential virtual machine 1 and the allocated flag as allocation information, the trusted flag and the trusted time as confirmation information; if computing device 1 is directly connected to computing device 2 trusted by confidential virtual machine 1, then the device information of computing device 1 also records: the identification information (such as the IP address or other field capable of uniquely identifying the computing device) of computing device 2 as the interconnection information field. A computing device is trusted by confidential virtual machine 1, meaning that the computing device has a trusted communication connection with confidential virtual machine 1.
[0025] In an example, the process of negotiating the communication key between the confidential virtual machine and the arbitrary computing device includes: receiving the encrypted ciphertext, the first signature information and the label of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is encrypted by the confidential virtual machine using the device public key of the target device on the first random value; the first signature information is signed by the confidential virtual machine using its own private key on the encrypted ciphertext and the label of the confidential virtual machine; forwarding the encrypted ciphertext, the first signature information and the label of the confidential virtual machine to the target device; receiving the combined data ciphertext and the second signature information sent by the target device; the combined data ciphertext is encrypted by the target device using the public key of the confidential virtual machine after verifying that the first signature information is passed, using its own private key to decrypt the encrypted ciphertext, combining the second random value with the decrypted first random value, and then encrypting the combined data using the public key of the confidential virtual machine; the second signature information is signed by the target device using its own private key on the combined data ciphertext; the target device performs key calculation on the second random value and the first random value using the first key algorithm to obtain the communication key negotiated with the confidential virtual machine; the combined data ciphertext and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine verifies that the second signature information is passed using the device public key of the target device, then decrypts the combined data ciphertext using its own private key to obtain the second random value and the first random value, and when the decrypted first random value is consistent with the first random value stored by itself, performs key calculation on the second random value and the first random value using the first key algorithm to obtain the communication key negotiated with the target device, and then sends the trusted confirmation message of the target device to the control end. As can be seen, the confidential virtual machine and the computing device perform key calculation on the second random value and the first random value using the same first key algorithm, so as to obtain the same communication key, and thus the key negotiation between the two is completed. After the negotiation is completed, the trusted confirmation message of the target device is sent to the control end, so that the control end responds to the trusted confirmation message and records the confirmation information that has been trusted by the confidential virtual machine in the device information of the target device, such as recording: the trust flag bit trusted by the confidential virtual machine and the confirmation trust time (which can be the time when the control end receives the trusted confirmation message, or the time when the confidential virtual machine sends the trusted confirmation message).
[0026] In an embodiment, determining whether at least two computing devices are both in trusted communication connection with the confidential virtual machine includes: querying the device information of the at least two computing devices respectively; if the device information of any computing device records the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine and the confirmation information trusted by the confidential virtual machine, it is confirmed that the computing device is in trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device is not in trusted communication connection with the confidential virtual machine.
[0027] S103, if the at least two computing devices are all connected with the confidential virtual machine through the trusted communication connection, sending the direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish the direct communication link and negotiate the communication key respectively.
[0028] S104, after confirming that the at least two computing devices establish the direct communication link and negotiate the communication key respectively, recording the interconnection information of each direct communication link.
[0029] In an embodiment, recording the interconnection information of each direct communication link comprises: taking two computing devices connected by each direct communication link as a first device and a second device; recording the identification information of the second device in the device information of the first device as the interconnection information field of the corresponding direct communication link; recording the identification information of the first device in the device information of the second device as the interconnection information field of the corresponding direct communication link.
[0030] Correspondingly, if the confidential virtual machine wants to disconnect the trusted communication connection with a certain computing device, the implementation process can include: the control end receiving the device unbinding request sent by the confidential virtual machine; determining the unbinding device to be unbound by the confidential virtual machine according to the device unbinding request; if the identification information of another device as the interconnection information field is not recorded in the device information of the unbinding device, deleting the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine in the device information of the unbinding device; sending an unbinding success message to the confidential virtual machine. Correspondingly, if the identification information of another device as the interconnection information field is recorded in the device information of the unbinding device, it means that the unbinding device has established a direct communication link with another computing device, then disconnecting the direct communication link between the unbinding device and another device; deleting the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, the confirmation information trusted by the confidential virtual machine, and the identification information of another device as the interconnection information field in the device information of the unbinding device; deleting the identification information of the unbinding device as the interconnection information field in the device information of another device; sending an unbinding success message to the confidential virtual machine.
[0031] S105, if there is at least one computing device in the at least two computing devices that does not establish a trusted communication connection with the confidential virtual machine, sending a corresponding notification message to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that does not establish a trusted communication connection.
[0032] In this embodiment, the notification message prompting the confidential virtual machine to establish a trusted communication connection with the computing device that does not establish a trusted communication connection can carry the device identification information of the computing device to be connected, such as IP address, etc.
[0033] In this embodiment, the control end can establish a direct connection communication link between different computing devices that are trusted to connect to the confidential virtual machine based on a target request sent by the confidential virtual machine to make at least two computing devices directly connected, and record the corresponding interconnection information. Thus, different computing devices that are trusted to connect to the same confidential virtual machine can directly communicate through the direct connection communication link interconnecting them, without the need for data forwarding through the confidential virtual machine or other third-party devices, which can reduce transmission delay, improve communication efficiency between different computing devices, and facilitate efficient processing of tasks on different computing devices.
[0034] The application further discloses another data processing method, applied to a confidential virtual machine, including: sending a target request to make at least two computing devices directly connected to a control end, so that the control end judges whether the at least two computing devices are both trusted to connect to the confidential virtual machine; if the at least two computing devices are both trusted to connect to the confidential virtual machine, sending direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish a direct connection communication link and negotiate a communication key with each other; after confirming that the at least two computing devices establish a direct connection communication link and negotiate a communication key with each other, recording the interconnection information of each direct connection communication link; wherein the confidential virtual machine is connected to the control end, the control end is connected to a plurality of computing devices, and the at least two computing devices are part of the devices or all of the devices in the plurality of computing devices.
[0035] In an embodiment, the confidential virtual machine sends target task ciphertext to a corresponding computing device through an arbitrary trusted communication connection, so that the computing device receiving the target task ciphertext executes the target task. Wherein, the confidential virtual machine and any computing device communicate in ciphertext with a communication key negotiated by the two, so that the confidential virtual machine sends target task ciphertext through an arbitrary trusted communication connection.
[0036] In an embodiment, the computing device receiving the target task ciphertext transmits task processing data ciphertext to other computing devices through a direct connection communication link. Wherein, different computing devices communicate in ciphertext with a communication key negotiated by the two, so that the computing device receiving the target task ciphertext transmits task processing data ciphertext through a direct connection communication link.
[0037] This embodiment can thus achieve direct ciphertext communication between the confidential virtual machine and any computing device realized by a symmetric key, and direct ciphertext communication between different computing devices connected to the same confidential virtual machine realized by a symmetric key, which can reduce transmission delay between different computing devices, improve communication efficiency between different computing devices, and facilitate efficient processing of tasks on different computing devices.
[0038] Please refer to Figure 2 , Figure 2A data processing system is illustrated, including: a security control module (i.e., a control end), a confidential virtual machine and n heterogeneous devices (i.e., n computing devices). The security control module is a secure hardware and can maintain a device information table. The confidential virtual machine and the heterogeneous devices can be directly connected after establishing a trust relationship between them and between different heterogeneous devices. The two can protect the confidentiality of data by negotiating a symmetric key and protect the integrity of data by digital signature. The security control module can enumerate all the heterogeneous devices to obtain basic information of each heterogeneous device, such as IP address, type, performance parameters, etc.
[0039] In an example, the virtual machine certificate management module maintains a virtual machine public key certificate list. The confidential virtual machine establishes trust with the device based on the public key and protects the transmission data through symmetric encryption and digital signature. The trusted devices can also establish trust based on the public key and protect the transmission data through symmetric encryption and digital signature.
[0040] The security control module needs to authenticate the virtual machine public key. The specific process includes: the virtual machine management program creates a virtual machine and assigns a virtual machine tag VMID. The virtual machine generates a pair of public and private keys (pk1, sk1), and the virtual machine signs the VMID using the private key sk1 and sends the signature, VMID and public key pk1 to the virtual machine certificate management module. The virtual machine certificate management module verifies the signature about VMID using pk1, and sends a random value r1 to the virtual machine. The virtual machine signs the random value r1 using sk1 and sends the signature to the virtual machine certificate management module. The virtual machine certificate management module verifies the signature about the random value r1 using pk1. If the verification is passed, the virtual machine certificate management module issues a certificate for pk1 to the virtual machine and adds the certificate to the virtual machine certificate list. The virtual machine certificate management module can be set in the security control module or in other devices trusted by the security control module and the virtual machine.
[0041] The security control module also sets up a confidential virtual machine. The specific process includes that the virtual machine sends a virtual machine label VMID and a public key pk1 to the security control module and requests to be set up as a confidential virtual machine. The security control module retrieves a virtual machine certificate list and confirms whether pk1 is a legal public key corresponding to VMID. If pk1 is a legal public key corresponding to VMID, the security control module sends a random value r2 to the virtual machine and requests the virtual machine to sign the random value with a private key. The random value r2 can be generated by using any random function or algorithm. The virtual machine signs the random value r2 from the security control module with sk1 and sends the signature to the security control module. The security control module verifies the signature on the random value r2 with pk1, and if the verification is passed, the security control module marks the virtual machine as a confidential virtual machine. The security control module generates an encryption key (a key for the virtual machine to encrypt its own memory) of the secure virtual machine, encrypts the encryption key with pk1, signs the ciphertext with the private key of the security control module, and finally sends the ciphertext and the signature to the confidential virtual machine. After receiving the signature from the security control module, the confidential virtual machine verifies the signature with the public key of the security control module. If the verification is passed, the confidential virtual machine decrypts the ciphertext with the private key sk1 to obtain the encryption key.
[0042] The confidential virtual machine applies to the security control module for binding a heterogeneous device. The specific process includes that the security control module maintains a device information table, as shown in Table 1. Figure 3 As shown in Table 1, the fields in the device information table can include device type, device public key pk2, device certificate, manufacturer information, etc. as device self-provided information; the allocation bit is a flag bit indicating whether the device is allocated to a confidential virtual machine; the confirmation bit is a flag bit indicating whether the confidential virtual machine includes the device in the trusted boundary; the VMID field stores the confidential virtual machine label VMID; the allocation time and the confirmation time respectively represent the time when the device is allocated to the confidential virtual machine and the time when the confidential virtual machine confirms the trusted device. The interconnection information between devices represents the interconnection state between devices, i.e. the interconnection information field. The confidential virtual machine sends a request to the security control module, requesting direct connection with a certain type of device, and the request can specify device type, performance, etc. The security control module retrieves the device information table and finds a device that meets the type requirements of the confidential virtual machine and has not been allocated to any confidential virtual machine. The security control module sets the allocation bit of the selected device information entry to 1, indicating that the device has been allocated to the confidential virtual machine. The security control module supplements the VMID field and the allocation time field of the corresponding device entry in the device information table. The security control module sends the device information (device type, manufacturer, allocation time) to the confidential virtual machine.
[0043] The security control module as a transit station makes the confidential virtual machine and the heterogeneous device establish a trusted connection, specifically including: the confidential virtual machine receives the device information of a certain heterogeneous device from the security control module, and selects a random value r3. The confidential virtual machine encrypts the random value r3 by using the public key pk2 of the heterogeneous device, and then signs the ciphertext and the VMID by using the private key sk1. The confidential virtual machine sends the ciphertext, the VMID and the signature to the security control module, and the security control module sends the ciphertext, the VMID and the signature to the heterogeneous device. After receiving the ciphertext, the VMID and the signature from the security control module, the heterogeneous device verifies whether the signature about the ciphertext and the VMID is valid by using the public key pk1 of the confidential virtual machine. After verification, the heterogeneous device decrypts the ciphertext by using its private key to obtain the random value r3. The heterogeneous device selects a random value r4, encrypts r3|r4 by using the public key pk1 of the confidential virtual machine, wherein | represents splicing two strings. Then, the heterogeneous device signs the ciphertext by using the private key of the heterogeneous device. Finally, the heterogeneous device sends the ciphertext and the signature to the security control module, and the security control module sends the ciphertext and the signature to the confidential virtual machine. The heterogeneous device calculates the private key sk3 (any kind of key generation algorithm) for communication between the confidential virtual machine and the heterogeneous device by using r3 and r4. After receiving the ciphertext and the signature from the heterogeneous device, the confidential virtual machine verifies whether the signature is a valid signature of the ciphertext by using the public key pk2 of the heterogeneous device. After verification, the confidential virtual machine decrypts the ciphertext by using the private key sk1. For the plaintext obtained by decryption, the confidential virtual machine compares whether the first half of the plaintext is consistent with r3. If consistent, the confidential virtual machine reads r4 in the second half, calculates the private key for communication between the confidential virtual machine and the heterogeneous device by using r3 and r4, and the private key is consistent with sk3. The confidential virtual machine sends a confirmation request to the security control module, confirming that the heterogeneous device is included in its trusted boundary, and the heterogeneous device is considered as: a trusted device of the confidential virtual machine. The security control module sets the confirmation bit field of the corresponding device entry in the device information table to 1, and supplements the time field.
[0044] The process of secure communication between the confidential virtual machine and the trusted device includes: when the trusted device sends data to the confidential virtual machine, the data is encrypted by using the private key sk3, and then the hash value of the ciphertext is signed by using the device private key sk2. The device sends the ciphertext and the signature to the confidential virtual machine. After receiving the message from the device, the confidential virtual machine calculates the hash value of the ciphertext, and then verifies the validity of the signature by using the public key pk2 of the device. If the verification is passed, the confidential virtual machine decrypts the ciphertext by using sk3 to obtain the corresponding plaintext, i.e. the data sent by the trusted device to the confidential virtual machine. When the confidential virtual machine sends data to the trusted device, the data is encrypted by using the private key sk3, and then the hash value of the ciphertext is signed by using the confidential virtual machine private key sk1. The confidential virtual machine sends the ciphertext and the signature to the device. After receiving the message from the confidential virtual machine, the device calculates the hash value of the ciphertext, and then verifies the validity of the signature by using the public key pk1 of the confidential virtual machine. If the verification is passed, the device decrypts the ciphertext by using sk3 to obtain the corresponding plaintext, i.e. the data sent by the confidential virtual machine to the trusted device.
[0045] It can be seen that the virtual machine certificate management module maintains a virtual machine public key certificate list, and the virtual machine can prove identity to the security control module and obtain an encryption key by using the public key. The security control module maintains a device information table, and binds the confidential virtual machine and the trusted device through corresponding fields to realize isolation protection of the trusted device. The confidential virtual machine and the trusted device construct a symmetric encryption private key through interaction, and protect the confidentiality of transmitted data by using the private key. The confidential virtual machine and the trusted device encrypt the transmitted data, calculate the hash value of the ciphertext, and then sign the hash value by using the private key to protect the integrity of the transmitted data.
[0046] The process of establishing a trusted connection between different heterogeneous devices connected to the same confidential virtual machine includes: the confidential virtual machine sending a request to the security control module, requesting a direct connection between trusted devices, the request including basic information of the devices that need to be connected to each other. The security control module retrieves the device information table, and confirms whether the VMID field of the corresponding device entry in the device information table is consistent with the VMID of the confidential virtual machine sending the request and whether the allocation bit and the confirmation bit are both 1, to confirm whether the devices that need to be connected to each other are connected to the same virtual machine. If the VMID field of the corresponding device entry in the device information table is consistent with the VMID of the confidential virtual machine sending the request and the allocation bit and the confirmation bit are both 1, the security control module configures the inter-device interconnection information field of the corresponding device entry in the device information table, that is, marks the other device information allowed to be directly connected with the device. The security control module sends the device information of the other trusted device allowed to be directly connected to the two trusted devices that need to be connected, and the devices perform connection according to the message. The memories of the two devices connected to each other are mapped to each other, and can communicate in a DMA manner. The communication key between different heterogeneous devices is negotiated according to the key negotiation method between the confidential virtual machine and a single heterogeneous device described above, specifically including: the trusted device 1 selects a random value r6, encrypts r6 using the public key of the trusted device 2, and then signs the ciphertext and the device information of the trusted device 1 using the private key of the trusted device 1. The trusted device 1 sends the ciphertext, the device information of the trusted device 1, and the signature to the trusted device 2. After receiving the ciphertext, the device information of the trusted device 1, and the signature from the trusted device 1, the trusted device 2 confirms whether the trusted device 1 is in its inter-device interconnection information field. If the trusted device 2 confirms that the trusted device 1 is in its inter-device interconnection information field, the trusted device 2 verifies whether the signature is a valid signature of the ciphertext and the device information of the trusted device 1 using the public key of the trusted device 1. If the verification is passed, the trusted device 2 decrypts the ciphertext using its private key to obtain the random value r6. The trusted device 2 selects a random value r7, encrypts r6|r7 using the public key of the trusted device 1. Then, the trusted device 2 signs the ciphertext using the private key of the trusted device 2. The trusted device 2 sends the ciphertext and the signature to the trusted device 1. The trusted device 2 calculates the private key sk4 for communication between the trusted device 1 and the trusted device 2 using r6 and r7. After receiving the ciphertext and the signature from the trusted device 2, the trusted device 1 verifies whether the signature is a valid signature of the ciphertext using the public key of the trusted device 2. If the verification is passed, the trusted device 1 decrypts the ciphertext using its private key. For the plaintext obtained by decryption, the trusted device 1 compares whether the first half of the plaintext is consistent with r6. If consistent, the trusted device 1 receives the second half of the plaintext r7, calculates the private key for communication between the trusted device 1 and the trusted device 2 using r6 and r7, which is consistent with sk4.
[0047] The process of secure communication between different heterogeneous devices includes: when the trusted device 1 sends data to the trusted device 2, the private key sk4 is used for encryption, and then the hash value of the ciphertext is signed by the private key of the trusted device 1. The trusted device 1 sends the ciphertext and the signature to the trusted device 2. After receiving the message from the trusted device 1, the trusted device 2 calculates the hash value of the ciphertext, and then verifies the validity of the signature by using the public key of the trusted device 1. If the verification is passed, the trusted device 2 decrypts the ciphertext by using sk4 to obtain the corresponding plaintext, that is, the data sent by the trusted device 1 to the trusted device 2. When the trusted device 2 sends data to the trusted device 1, the private key sk4 is used for encryption, and then the hash value of the ciphertext is signed by the private key of the trusted device 2. The trusted device 2 sends the ciphertext and the signature to the trusted device 1. After receiving the message from the trusted device 2, the trusted device 1 calculates the hash value of the ciphertext, and then verifies the validity of the signature by using the public key of the trusted device 3. If the verification is passed, the trusted device 1 decrypts the ciphertext by using sk4 to obtain the corresponding plaintext, that is, the data sent by the trusted device 2 to the trusted device 1.
[0048] It can be seen that the symmetric encryption private key is constructed by interaction between the trusted devices, and the private key is used to protect the confidentiality of the transmitted data. The trusted device calculates the hash value of the encrypted data, and then digitally signs the hash value by using the private key of the trusted device, to protect the integrity of the transmitted data. The direct connection between the devices improves the data transmission efficiency and reduces the load of the confidential virtual machine.
[0049] The process of unbinding any heterogeneous device and the confidential virtual machine includes: the confidential virtual machine sends an unbinding request to the security control module, and the request includes device information. The security control module searches the device information table, clears the allocation bit, the confirmation position 0, the VMID, the allocation time and the confirmation time of the corresponding device entry in the device information table. For the inter-device interconnection information field, if it is not empty, the security control module modifies the inter-device interconnection information field corresponding to the device corresponding entry in the inter-device interconnection field, and clears the corresponding device information (first disconnect the devices having direct communication connection with the unbound device). Finally, the security control module clears the inter-device interconnection information field.
[0050] In this embodiment, each heterogeneous computing device can receive the model inference task sent by the confidential virtual machine, and implement corresponding confidential computing. Confidential computing is a computing paradigm aimed at protecting the security of data in use, and is an important technology for solving the security of data in use under the constraint of computing efficiency. Based on the trusted execution environment, the security of data and code is realized through hardware-level system isolation. By setting the confidential computing based on TEE to the heterogeneous device, the efficient processing of data on the accelerator can be protected from external threats, and it is ensured that the task being executed will not be disturbed by malicious software.
[0051] In this embodiment, the virtual machine establishes a secure connection with the security control module, the security control module marks the virtual machine as a confidential virtual machine, and sends the memory encryption key of the confidential virtual machine to the confidential virtual machine in a secure manner. Then, the confidential virtual machine establishes a secure connection with the device, the security control module marks the device as a trusted device corresponding to the confidential virtual machine, and realizes the direct connection between the confidential virtual machine and the trusted device by maintaining the device information table. The confidential virtual machine and the trusted device protect the confidentiality and integrity of data transmission through symmetric encryption and digital signature. The security control module also marks the direct connection relationship between the trusted devices in the corresponding field of the device information table. Then, the trusted devices establish a secure connection, protect the confidentiality and integrity of data transmission through symmetric encryption and digital signature, and improve the data transmission efficiency. The trusted device can only interconnect with a unique confidential virtual machine, and realizes device isolation protection.
[0052] A data processing system according to an embodiment of the present application is described below. The data processing system described below can be referred to in conjunction with other embodiments described herein.
[0053] Referring to Figure 4 As shown in the figure, the embodiment of the present application discloses a data processing system, which comprises a control terminal, a confidential virtual machine and a plurality of computing devices, and the control terminal is connected with the confidential virtual machine and the plurality of computing devices. The control terminal can also be connected with more confidential virtual machines.
[0054] The control terminal is configured to: receive a target request for direct connection of at least two computing devices sent by the confidential virtual machine; determine whether the at least two computing devices are both connected with the confidential virtual machine in a trusted communication connection; if the at least two computing devices are both connected with the confidential virtual machine in a trusted communication connection, send direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other; and after confirming that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other, record interconnection information of each direct communication link.
[0055] In an embodiment, the control terminal is configured to: query device information of the at least two computing devices respectively; if the device information of any computing device records a label of the confidential virtual machine, allocation information allocated to the confidential virtual machine and confirmation information trusted by the confidential virtual machine, it is confirmed that the computing device is connected with the confidential virtual machine in a trusted communication connection; otherwise, it is confirmed that the computing device is not connected with the confidential virtual machine in a trusted communication connection.
[0056] In an embodiment, the control terminal is configured to: if there is at least one computing device in the at least two computing devices that is not connected with the confidential virtual machine in a trusted communication connection, send a corresponding notification message to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device not connected in a trusted communication connection.
[0057] In an embodiment, the control terminal is configured to: receive a device connection request sent by the confidential virtual machine; determine a connection requirement of the confidential virtual machine according to the device connection request; select a target device matching the connection requirement from the unassigned computing devices; send the device information of the target device to the confidential virtual machine after recording the label of the confidential virtual machine and the assignment information assigned to the confidential virtual machine in the device information of the target device, so that the confidential virtual machine establishes a trusted communication connection with the target device through the control terminal as a communication relay station and negotiates a communication key.
[0058] In an embodiment, the control terminal is configured to: receive a trusted confirmation message of the target device sent by the confidential virtual machine after the confidential virtual machine and the target device complete the communication key negotiation; and record the confirmation information trusted by the confidential virtual machine in the device information of the target device in response to the trusted confirmation message.
[0059] In an embodiment, the control terminal is configured to: receive an encrypted ciphertext, first signature information and a label of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is obtained by encrypting a first random value with a device public key of the target device by the confidential virtual machine; the first signature information is obtained by signing the encrypted ciphertext and the label of the confidential virtual machine with a private key of the confidential virtual machine; forward the encrypted ciphertext, the first signature information and the label of the confidential virtual machine to the target device; receive a combined data ciphertext and second signature information sent by the target device; the combined data ciphertext is obtained by the target device after verifying that the first signature information is passed by verifying the first signature information with a public key of the confidential virtual machine, decrypting the encrypted ciphertext with a private key of the target device, combining a second random value with the decrypted first random value, and encrypting the combined data with the public key of the confidential virtual machine; the second signature information is obtained by signing the combined data ciphertext with the private key of the target device; the target device performs key calculation on the second random value and the first random value with a first key algorithm to obtain the communication key negotiated with the confidential virtual machine; and forward the combined data ciphertext and the second signature information to the confidential virtual machine, so that the confidential virtual machine verifies that the second signature information is passed by verifying the second signature information with the device public key of the target device, decrypts the combined data ciphertext with the private key of the confidential virtual machine to obtain the second random value and the first random value, and performs key calculation on the second random value and the first random value with the first key algorithm when the decrypted first random value is consistent with the stored first random value to obtain the communication key negotiated with the target device, and then sends a trusted confirmation message of the target device to the control terminal.
[0060] In an embodiment, the control terminal is configured to: take two computing devices connected by each direct communication link as a first device and a second device; record the identification information of the second device in the device information of the first device as interconnection information of the corresponding direct communication link; and record the identification information of the first device in the device information of the second device as interconnection information of the corresponding direct communication link.
[0061] In an embodiment, the control end is configured to: receive a device unbinding request sent by the confidential virtual machine; determine, according to the device unbinding request, an unbinding device to be unbound by the confidential virtual machine; delete the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine in the device information of the unbinding device, if the identification information of another device as the interconnection information field is not recorded in the device information of the unbinding device; and send an unbinding success message to the confidential virtual machine.
[0062] In an embodiment, the control end is configured to: if the identification information of another device as the interconnection information field is recorded in the device information of the unbinding device, disconnect the direct communication link between the unbinding device and the another device; delete the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, the confirmation information trusted by the confidential virtual machine, and the identification information of another device as the interconnection information field in the device information of the unbinding device; delete the identification information of the unbinding device as the interconnection information field in the device information of the another device; and send an unbinding success message to the confidential virtual machine.
[0063] In an embodiment, the confidential virtual machine sends a target request for direct connection of at least two computing devices to the control end, so that the control end judges whether the at least two computing devices are both connected to the confidential virtual machine to establish a trusted communication connection; if the at least two computing devices are both connected to the confidential virtual machine to establish a trusted communication connection, the control end sends direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link and negotiate a communication key with each other; after confirming that the at least two computing devices establish a direct communication link and negotiate a communication key with each other, the control end records the interconnection information of each direct communication link; wherein the confidential virtual machine is connected to the control end, the control end is connected to a plurality of computing devices, and the at least two computing devices are part of the devices or all of the devices in the plurality of computing devices.
[0064] In an embodiment, the confidential virtual machine sends a target task ciphertext to a corresponding computing device through an arbitrary trusted communication connection, so that the computing device receiving the target task ciphertext executes a target task.
[0065] In an embodiment, the computing device receiving the target task ciphertext transmits task processing data ciphertext to other computing devices through a direct communication link.
[0066] In an embodiment, the control end is configured to: receive a device unbinding request sent by the confidential virtual machine; determine, according to the device unbinding request, an unbinding device to be unbound by the confidential virtual machine; delete the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine in the device information of the unbinding device, if the identification information of another device as the interconnection information field is not recorded in the device information of the unbinding device; and send an unbinding success message to the confidential virtual machine.
[0067] It can be seen that the embodiment provides a data processing apparatus, which can reduce transmission delay between different computing devices, improve communication efficiency between different computing devices, and facilitate efficient processing of tasks on different computing devices.
[0068] An electronic device provided by an embodiment of the present application is described below, and the electronic device described below can be referred to with other embodiments described herein.
[0069] Referring to Figure 5 As shown in the figure, the electronic device disclosed by the embodiment of the present application comprises: a memory 501 configured to save a computer program; and a processor 502 configured to execute the computer program to implement the method disclosed by any of the above embodiments.
[0070] In the embodiment, when the processor executes the computer program saved in the memory, the following steps can be specifically implemented: receiving a target request for direct connection of at least two computing devices sent by a confidential virtual machine; judging whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other; and after confirming that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other, recording interconnection information of each direct communication link.
[0071] In the embodiment, when the processor executes the computer program saved in the memory, the following steps can be specifically implemented: querying device information of the at least two computing devices respectively; if the device information of any computing device records a label of the confidential virtual machine, allocation information allocated to the confidential virtual machine, and confirmation information trusted by the confidential virtual machine, it is confirmed that the computing device is connected to the confidential virtual machine in a trusted manner; otherwise, it is confirmed that the computing device is not connected to the confidential virtual machine in a trusted manner.
[0072] In the embodiment, when the processor executes the computer program saved in the memory, the following steps can be specifically implemented: if there is at least one computing device in the at least two computing devices that is not connected to the confidential virtual machine in a trusted manner, sending a corresponding notification message to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that is not connected in a trusted manner.
[0073] In the embodiment, the processor, when executing the computer program stored in the memory, can specifically implement the following steps: receiving a device connection request sent by the confidential virtual machine; determining the connection requirement of the confidential virtual machine according to the device connection request; selecting a target device matching the connection requirement from the unallocated computing devices; and after recording the label of the confidential virtual machine and the allocation information allocated to the confidential virtual machine in the device information of the target device, sending the device information of the target device to the confidential virtual machine, so that the confidential virtual machine establishes a trusted communication connection with the target device by taking the control terminal as a communication relay station and negotiates a communication key.
[0074] In the embodiment, the processor, when executing the computer program stored in the memory, can specifically implement the following steps: receiving a trusted confirmation message of the target device sent by the confidential virtual machine after the confidential virtual machine and the target device complete the communication key negotiation; and in response to the trusted confirmation message, recording the confirmation information trusted by the confidential virtual machine in the device information of the target device.
[0075] In the embodiment, the processor, when executing the computer program stored in the memory, can specifically implement the following steps: receiving an encrypted ciphertext, first signature information and a label of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is obtained by encrypting a first random value by the confidential virtual machine using the device public key of the target device; the first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the label of the confidential virtual machine using its own private key; forwarding the encrypted ciphertext, the first signature information and the label of the confidential virtual machine to the target device; receiving a combined data ciphertext and second signature information sent by the target device; the combined data ciphertext is obtained by the target device after verifying that the first signature information passes the verification using the public key of the confidential virtual machine, decrypting the encrypted ciphertext using its own private key, combining a second random value with the decrypted first random value, and encrypting the combined data using the public key of the confidential virtual machine; the second signature information is obtained by the target device signing the combined data ciphertext using its own private key; the target device performs key calculation on the second random value and the first random value using a first key algorithm to obtain the communication key negotiated with the confidential virtual machine; and forwarding the combined data ciphertext and the second signature information to the confidential virtual machine, so that the confidential virtual machine, after verifying that the second signature information passes the verification using the device public key of the target device, decrypts the combined data ciphertext using its own private key to obtain the second random value and the first random value, and when the decrypted first random value is consistent with the first random value stored by itself, performs key calculation on the second random value and the first random value using the first key algorithm to obtain the communication key negotiated with the target device, and then sends a trusted confirmation message of the target device to the control terminal.
[0076] In the embodiment, the processor, when executing the computer program stored in the memory, can implement the following steps: taking two computing devices connected by each direct communication link as a first device and a second device; recording the identification information of the second device in the device information of the first device as the interconnection information field of the corresponding direct communication link; and recording the identification information of the first device in the device information of the second device as the interconnection information field of the corresponding direct communication link.
[0077] In the embodiment, the processor, when executing the computer program stored in the memory, can implement the following steps: receiving the device unbinding request sent by the confidential virtual machine; determining the unbinding device to be unbound by the confidential virtual machine according to the device unbinding request; if the identification information of another device as the interconnection information field is not recorded in the device information of the unbinding device, deleting the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine and the confirmation information trusted by the confidential virtual machine in the device information of the unbinding device; and sending the unbinding success message to the confidential virtual machine.
[0078] In the embodiment, the processor, when executing the computer program stored in the memory, can implement the following steps: if the identification information of another device as the interconnection information field is recorded in the device information of the unbinding device, disconnecting the direct communication link between the unbinding device and the another device; deleting the label of the confidential virtual machine, the allocation information allocated to the confidential virtual machine, the confirmation information trusted by the confidential virtual machine and the identification information of another device as the interconnection information field in the device information of the unbinding device; deleting the identification information of the unbinding device as the interconnection information field in the device information of the another device; and sending the unbinding success message to the confidential virtual machine.
[0079] In the embodiment, the processor, when executing the computer program stored in the memory, can implement the following steps: sending the target request for directly connecting at least two computing devices to the control end.
[0080] In the embodiment, the processor, when executing the computer program stored in the memory, can implement the following steps: sending the target task ciphertext to the corresponding computing device through any trusted communication connection, so that the computing device receiving the target task ciphertext executes the target task.
[0081] Further, the embodiment of the application further provides an electronic device. Figure 6 The electronic device can be a server as shown in Figure 7 or a terminal. Figure 6 and Figure 7 are structural diagrams of electronic devices according to an example embodiment, and the contents in the diagrams cannot be considered as any limitation on the use range of the application.
[0082] Figure 6 A structural schematic diagram of a server is provided in the embodiment. The server can specifically include at least one processor, at least one memory, a power supply, a communication interface, an input / output interface and a communication bus. The memory is configured to store a computer program, the computer program is loaded and executed by the processor to implement the related steps in the data processing disclosed in any of the foregoing embodiments.
[0083] In the embodiment, the power supply is configured to provide working voltage for each hardware device on the server; the communication interface is configured to create a data transmission channel between the server and external devices, and the communication protocol followed by the communication interface is any communication protocol applicable to the technical solution of the present application, which is not specifically limited herein; the input / output interface is configured to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not specifically limited herein.
[0084] In addition, the memory as a carrier for resource storage can be a read-only memory, a random access memory, a magnetic disk or an optical disk, etc., and the resources stored thereon include an operating system, a computer program and data, etc., and the storage mode can be temporary storage or permanent storage.
[0085] The operating system is configured to manage and control each hardware device and the computer program on the server, so as to implement the operation and processing of the processor on the data in the memory, and the operating system can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of completing the data processing method disclosed in any of the foregoing embodiments, the computer program can further include a computer program capable of completing other specific work. In addition to the data such as update information of the application program, the data can further include the data such as the developer information of the application program.
[0086] Figure 7 A structural schematic diagram of a terminal is provided in the embodiment, and the terminal can specifically include but is not limited to a smart phone, a tablet computer, a notebook computer or a desktop computer, etc.
[0087] Generally, the terminal in the embodiment includes a processor and a memory.
[0088] The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor can be implemented using at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor may also include a main processor and coprocessors. The main processor, also known as the CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which handles computational operations related to machine learning.
[0089] The memory may include one or more computer non-volatile storage media, which may be non-transitory. The memory may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory is used to store at least the following computer program, which, after being loaded and executed by the processor, is capable of implementing the relevant steps in the data processing method executed by the terminal side as disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory may also include operating systems and data, and the storage method may be temporary or permanent storage. The operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, application update information.
[0090] In some embodiments, the terminal may further include a display screen, an input / output interface, a communication interface, a sensor, a power supply, and a communication bus.
[0091] Those skilled in the art will understand that Figure 7 The structure shown does not constitute a limitation on the terminal and may include more or fewer components than illustrated.
[0092] The following describes a non-volatile storage medium provided in an embodiment of this application. The non-volatile storage medium described below can be referred to in conjunction with other embodiments described herein.
[0093] A non-volatile storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the data processing method disclosed in the foregoing embodiments. The non-volatile storage medium is a computer-readable non-volatile storage medium, and serves as a carrier for storing resources. The non-volatile storage medium can be a read-only memory, a random access memory, a magnetic disk, an optical disk, or the like. The resources stored on the non-volatile storage medium include an operating system, a computer program, data, and the like. The storage manner can be temporary storage or permanent storage.
[0094] A computer program product is introduced below. The computer program product described below can be combined with other embodiments described herein.
[0095] A computer program product includes computer programs / instructions, which, when executed by a processor, implement the steps of the data processing method disclosed above.
[0096] Another computer program product is provided in the embodiments of the present application. The computer program product includes a non-volatile computer-readable storage medium, which is used to store a computer program. The computer program, when executed by a processor, implements the steps in any of the above embodiments.
[0097] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be combined with each other.
[0098] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of non-volatile storage medium known in the art.
[0099] The principles and implementation manners of the present application are described by using specific examples. The above descriptions of the embodiments are only used to help understand the method and core idea of the present application; for those skilled in the art, the specific implementation manners and application ranges can be changed according to the idea of the present application. In summary, the content of the specification should not be understood as a limitation of the present application.
Claims
1. A data processing method, characterized in that, It is used as a control terminal, which connects a confidential virtual machine and multiple computing devices, including: Receive the target request sent by the confidential virtual machine to enable direct connection between at least two computing devices; Determine whether both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine; If both computing devices have established trusted communication connections with the confidential virtual machine, then a direct connection information is sent to each of the at least two computing devices to enable them to establish direct communication links and negotiate communication keys. After confirming that the at least two computing devices have established direct communication links in pairs and negotiated communication keys in pairs, the interconnection information of each direct communication link is recorded.
2. The method according to claim 1, characterized in that, Determining whether both of the at least two computing devices have established trusted communication connections with the confidential virtual machine includes: Query the device information of each of the at least two computing devices; If any computing device's device information records the tag of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, and the confirmation information that it has been trusted by the confidential virtual machine, then it is confirmed that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device has not established a trusted communication connection with the confidential virtual machine.
3. The method according to claim 1, characterized in that, Also includes: If at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, a corresponding notification message is sent to the confidential virtual machine to prompt it to establish a trusted communication connection with the computing device that has not established a trusted communication connection.
4. The method according to claim 1, characterized in that, Also includes: Receive the device connection request sent by the confidential virtual machine; The connection requirements of the confidential virtual machine are determined based on the device connection request. Select a target device that matches the connectivity requirements from the unassigned computing devices; After recording the tag of the confidential virtual machine and the allocation information assigned to the confidential virtual machine in the device information of the target device, the device information of the target device is sent to the confidential virtual machine, so that the confidential virtual machine can use the control terminal as a communication relay station to establish a trusted communication connection with the target device and negotiate a communication key.
5. The method according to claim 4, characterized in that, Also includes: After the confidential virtual machine and the target device complete the communication key negotiation, the target device sends a trusted confirmation message from the target device. In response to the trusted confirmation message, confirmation information that has been trusted by the confidential virtual machine is recorded in the device information of the target device.
6. The method according to claim 4, characterized in that, Also includes: Receive encrypted ciphertext, first signature information, and the tag of the confidential virtual machine sent by the confidential virtual machine; The encrypted ciphertext is obtained by the confidential virtual machine encrypting a first random value using the device public key of the target device; The first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the label of the confidential virtual machine using its own private key; The encrypted ciphertext, the first signature information, and the label of the confidential virtual machine are forwarded to the target device; The system receives a combined encrypted data and a second signature information sent by the target device. The combined encrypted data is obtained by the target device verifying the first signature information using the public key of the confidential virtual machine, then decrypting the encrypted data using its own private key, combining a second random value with the decrypted first random value, and then encrypting the combined data using the public key of the confidential virtual machine. The second signature information is obtained by the target device signing the combined encrypted data using its own private key. The target device uses a first key algorithm to perform key calculation on the second random value and the first random value to obtain a communication key negotiated with the confidential virtual machine; The combined encrypted data and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine can verify the second signature information using the public key of the target device, and then decrypt the combined encrypted data using its own private key to obtain a second random value and a first random value. When the first random value obtained by decryption is consistent with the first random value stored by itself, the first key algorithm is used to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the target device. Then, a trusted confirmation message from the target device is sent to the control terminal.
7. The method according to any one of claims 1 to 6, characterized in that, Record the interconnection information of each directly connected communication link, including: The two computing devices connected by each direct communication link are designated as the first device and the second device. The identification information of the second device is recorded in the device information of the first device as the interconnection information field of the corresponding direct communication link; The identification information of the first device is recorded in the device information of the second device as the interconnection information field of the corresponding direct communication link.
8. The method according to any one of claims 1 to 6, characterized in that, Also includes: Receive the device unbinding request sent by the confidential virtual machine; The device to be unbound from the confidential virtual machine is determined based on the device unbinding request; If the device information of the unbound device does not record the identification information of another device as an interconnection information field, then delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, and the confirmation information that the confidential virtual machine has been trusted from the device information of the unbound device. Send a message indicating successful unbinding to the confidential virtual machine.
9. The method according to claim 8, characterized in that, Also includes: If the device information of the unbound device contains the identification information of another device as an interconnection information field, then the direct communication link between the unbound device and the other device is disconnected. Delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, the confirmation information that has been trusted by the confidential virtual machine, and the identification information of another device as an interconnection information field from the device information of the unbound device; Remove the identifier information of the unbound device from the interconnection information field of the device information of another device; Send a message indicating successful unbinding to the confidential virtual machine.
10. A data processing method, characterized in that, Applied to confidential virtual machines, including: A target request to enable direct connection between at least two computing devices is sent to the control terminal, so that the control terminal can determine whether both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine; if both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine, then a direct connection information is sent to each of the at least two computing devices, so that the at least two computing devices establish direct connection communication links in pairs and negotiate communication keys in pairs; after confirming that the at least two computing devices have established direct connection communication links in pairs and negotiated communication keys in pairs, the interconnection information of each direct connection communication link is recorded; The confidential virtual machine is connected to the control terminal, which is connected to multiple computing devices. The at least two computing devices are some or all of the multiple computing devices.
Citation Information
Patent Citations
Virtual machine credibility guaranteeing method in cloud environment
CN103888251A
Multi-party cooperation method and related device
CN115550070A
Data encryption protection method based on trusted virtualization environment
CN117519900A
Application client execution system
CN120415776A
Internet connection setup between computing devices using blockchains
EP3367289A1