Data processing method

By determining the trusted connection between the computing device and the confidential virtual machine at the control end, establishing a direct communication link and negotiating the key, the problem of communication latency between computing devices is solved, and efficient inter-device communication is achieved.

CN120973479BActive Publication Date: 2026-01-23LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511493102.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-01-23
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Communication between different computing devices requires forwarding through confidential virtual machines or third-party devices, which increases transmission latency and affects task processing efficiency.

Method used

The control terminal determines the trusted connection between the computing device and the confidential virtual machine, establishes a direct communication link between the computing devices, negotiates the communication key, records the interconnection information, and enables direct communication between the devices.

Benefits of technology

It reduces transmission latency, improves communication efficiency between different computing devices, and facilitates efficient processing of tasks on different devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120973479B_ABST
    Figure CN120973479B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method in the computer technical field. In the application, a control terminal establishes a direct connection communication link between different computing devices which are trusted to connect with a confidential virtual machine based on a target request sent by the confidential virtual machine, and records corresponding interconnection information. Thus, different computing devices which are trusted to connect with the same confidential virtual machine can directly communicate through the direct connection communication link interconnecting them, without the need of data forwarding by means of the confidential virtual machine or other third-party devices, so that the transmission delay can be reduced, the communication efficiency between different computing devices can be improved, and efficient processing of tasks on different computing devices is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a data processing method. BACKGROUND

[0002] Currently, a confidential virtual machine can perform a task by using multiple computing devices. If different computing devices need to communicate, the confidential virtual machine needs to be used as a data forwarding station between different computing devices or other third-party devices are used to realize data forwarding between different computing devices. This forwarding communication mode increases transmission delay, which is not conducive to efficient processing of the task.

[0003] Therefore, how to improve the communication efficiency between different computing devices is a problem to be solved by those skilled in the art. SUMMARY

[0004] Therefore, how to improve the communication efficiency between different computing devices is a problem to be solved by those skilled in the art.

[0005] In a first aspect, the present application provides a data processing method applied to a control terminal, the control terminal being connected to a confidential virtual machine and multiple computing devices, and the method comprises the following steps: receiving a target request sent by the confidential virtual machine, the target request being used to make at least two computing devices directly connected; judging whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending directly-connectable information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other; and after confirming that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other, recording interconnection information of each direct communication link.

[0006] In a second aspect, the present application provides a data processing method applied to a confidential virtual machine, and the method comprises the following steps: sending a target request to a control terminal, the target request being used to make at least two computing devices directly connected, so that the control terminal judges whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending directly-connectable information to the at least two computing devices respectively, so that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other; and after confirming that the at least two computing devices establish a direct communication link with each other and negotiate a communication key with each other, recording interconnection information of each direct communication link. The confidential virtual machine is connected to the control terminal, the control terminal is connected to multiple computing devices, and the at least two computing devices are part of the multiple computing devices or all of the multiple computing devices.

[0007] In a third aspect, the present application provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the data processing method disclosed above.

[0008] In a fourth aspect, the present application provides a non-volatile storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the data processing method disclosed above.

[0009] In a fifth aspect, the present application provides a computer program product, comprising computer programs / instructions, which, when executed by a processor, implement the steps of the data processing method disclosed above.

[0010] According to the above scheme, the present application provides a data processing method, applied to a control terminal connected to a confidential virtual machine and a plurality of computing devices, comprising: receiving a target request for direct connection of at least two computing devices sent by the confidential virtual machine; determining whether the at least two computing devices are both connected to the confidential virtual machine in a trusted manner; if the at least two computing devices are both connected to the confidential virtual machine in a trusted manner, sending direct connection information to the at least two computing devices respectively, so that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other; and after confirming that the at least two computing devices establish direct communication links with each other and negotiate communication keys with each other, recording interconnection information of each direct communication link.

[0011] It can be seen that the present application has the following beneficial effects: the control terminal can establish direct communication links between different computing devices connected to the confidential virtual machine in a trusted manner based on the target request for direct connection of at least two computing devices sent by the confidential virtual machine, and record the corresponding interconnection information. Thus, different computing devices connected to the same confidential virtual machine in a trusted manner can communicate directly through the direct communication links connected to each other, without the need for data forwarding through the confidential virtual machine or other third-party devices, which can reduce transmission delay and improve communication efficiency between different computing devices, and is conducive to efficient processing of tasks on different computing devices.

[0012] Correspondingly, the electronic device, medium and program product provided by the present application also have the above technical effects. BRIEF DESCRIPTION OF DRAWINGS

[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0014] Figure 1 This is a flowchart of a data processing method disclosed in this application;

[0015] Figure 2 This is a schematic diagram of a data processing system disclosed in this application;

[0016] Figure 3 This application discloses an intentional representation of device information.

[0017] Figure 4 This is a schematic diagram of another data processing system disclosed in this application;

[0018] Figure 5 This is a schematic diagram of an electronic device disclosed in this application;

[0019] Figure 6 A server architecture diagram provided in this application;

[0020] Figure 7 A terminal structure diagram provided for this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0022] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0023] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] Currently, confidential virtual machines can execute tasks using multiple computing devices. If different computing devices need to communicate, the confidential virtual machine must act as a data forwarding station between them, or other third-party devices must be used to forward data between them. This forwarding communication method increases transmission latency and is detrimental to efficient task processing. Therefore, this application provides a data processing scheme that can reduce transmission latency between different computing devices, improve communication efficiency between them, and facilitate efficient task processing across different computing devices.

[0025] See Figure 1 As shown in the figure, this application discloses a data processing method applied to a control terminal, wherein the control terminal is connected to a confidential virtual machine and multiple computing devices, including:

[0026] S101, Receive a target request sent by a confidential virtual machine to enable direct connection between at least two computing devices.

[0027] It should be noted that a confidential virtual machine refers to any confidential virtual machine connected to the control terminal. In other words, the control terminal is connected to at least one confidential virtual machine. The computing device can be a CPU card, FPGA board, or other acceleration device. The target request can specify the IP address, model, manufacturer, type, and other identifying information of the computing device to be directly connected.

[0028] S102. Determine whether at least two computing devices have established trusted communication connections with the confidential virtual machine; if so, proceed to S103; otherwise, proceed to S105.

[0029] In this embodiment, the process of establishing a trusted communication connection between a confidential virtual machine and any computing device includes: in one implementation, it further includes: receiving a device connection request sent by the confidential virtual machine; determining the connection requirements of the confidential virtual machine based on the device connection request; selecting a target device matching the connection requirements from among the multiple computing devices connected to the control terminal that have not been assigned to any confidential virtual machine; recording the confidential virtual machine's tag and the allocation information already assigned to the confidential virtual machine in the target device's device information, and then sending the target device's device information to the confidential virtual machine, so that the confidential virtual machine can establish a trusted communication connection with the target device using the control terminal as a communication relay station, and negotiate a communication key; this communication key is used for encrypted communication between the confidential virtual machine and the target device, that is: between the confidential virtual machine and the target device, this communication key is used to encrypt any data to be transmitted, realizing encrypted communication between the two, and the communication process does not require the participation of the control terminal. The connection requirements may include: device type, device manufacturer, and performance parameters such as device memory size and device computing power.

[0030] It should be noted that after the confidential virtual machine establishes a trusted communication connection with the target device and negotiates the communication key, it also needs to make a trusted report to the control end. The specific process includes: receiving a trusted confirmation message from the target device after the confidential virtual machine and the target device have completed the communication key negotiation; and in response to the trusted confirmation message, recording the confirmation information that has been trusted by the confidential virtual machine in the device information of the target device.

[0031] In this embodiment, the control terminal is trusted by the confidential virtual machine and the multiple computing devices connected to it. Therefore, the control terminal can record: which computing devices are trusted by a confidential virtual machine, and which of these computing devices have direct communication links; the IP address, tag, and other identification information of each confidential virtual machine; and the IP address, model, manufacturer, type, and other identification information of each computing device. Furthermore, to achieve more orderly and error-free management of devices and connections, the control terminal records a set of device information for each computing device, including: the tag of the confidential virtual machine, allocation information assigned to the confidential virtual machine, and interconnection information fields. For example, if computing device 1 is assigned to and trusted by confidential virtual machine 1, then the device information of computing device 1 can record: the tag of confidential virtual machine 1, the time of assignment to confidential virtual machine 1, and the assigned flag as allocation information; the trust flag indicating trust by the confidential virtual machine and the confirmation time as confirmation information; if computing device 1 is directly connected to computing device 2 trusted by confidential virtual machine 1, then the device information of computing device 1 also records: the identification information of computing device 2 (such as an IP address or other fields that can uniquely identify the computing device) as interconnection information fields. If a computing device is trusted by a confidential virtual machine 1, it means that the computing device has established a trusted communication connection with the confidential virtual machine 1.

[0032] In one example, the process of a confidential virtual machine negotiating a communication key with an arbitrary computing device includes: receiving encrypted ciphertext, first signature information, and a tag of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is obtained by the confidential virtual machine encrypting a first random value using the target device's public key; the first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the confidential virtual machine's tag using its own private key; forwarding the encrypted ciphertext, the first signature information, and the confidential virtual machine's tag to the target device; receiving combined data ciphertext and second signature information sent by the target device; after the target device verifies the first signature information using the confidential virtual machine's public key, it decrypts the encrypted ciphertext using its own private key, combines the second random value with the decrypted first random value, and then uses the confidential virtual machine's tag to communicate with the target device. The virtual machine's public key is used to encrypt the combined data; the second signature information is obtained by the target device signing the encrypted combined data using its own private key; the target device uses a first key algorithm to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the confidential virtual machine; the encrypted combined data and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine can verify the second signature information using the target device's public key, and then decrypt the encrypted combined data using its own private key to obtain the second random value and the first random value. If the decrypted first random value matches the first random value stored in the device, the first key algorithm is used to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the target device, and then a trusted confirmation message from the target device is sent to the control terminal. It can be seen that the confidential virtual machine and the computing device obtain the same communication key by using the same first key algorithm to perform key calculation on the second random value and the first random value, thus completing the key negotiation between them. After the negotiation is completed, a trusted confirmation message from the target device is sent to the control terminal, so that the control terminal responds to this trusted confirmation message and records the confirmation information that the confidential virtual machine has trusted it in the device information of the target device. For example, the trusted flag bit and the confirmation trust time (which can be the time when the control terminal receives the trusted confirmation message or the time when the confidential virtual machine sends the trusted confirmation message) are recorded.

[0033] In one implementation, determining whether at least two computing devices have established trusted communication connections with a confidential virtual machine includes: querying the device information of at least two computing devices respectively; if the device information of any computing device records a tag of the confidential virtual machine, allocation information that has been assigned to the confidential virtual machine, and confirmation information that it has been trusted by the confidential virtual machine, then it is confirmed that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device has not established a trusted communication connection with the confidential virtual machine.

[0034] S103. If at least two computing devices have established trusted communication connections with the confidential virtual machine, then send direct connection information to at least two computing devices respectively, so that at least two computing devices can establish direct communication links with each other and negotiate communication keys with each other.

[0035] S104. After confirming that at least two computing devices have established direct communication links and negotiated communication keys with each other, record the interconnection information of each direct communication link.

[0036] In one embodiment, recording the interconnection information of each directly connected communication link includes: designating two computing devices connected by each directly connected communication link as a first device and a second device; recording the identification information of the second device in the device information of the first device as an interconnection information field of the corresponding directly connected communication link; and recording the identification information of the first device in the device information of the second device as an interconnection information field of the corresponding directly connected communication link.

[0037] Accordingly, if a confidential virtual machine wants to disconnect its trusted communication connection with a computing device, the specific implementation process may include: the control terminal receiving a device unbinding request sent by the confidential virtual machine; determining the device to be unbound by the confidential virtual machine based on the device unbinding request; if the device information of the unbound device does not record the identification information of another device as an interconnection information field, then deleting the confidential virtual machine's tag, the allocation information assigned to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine from the device information of the unbound device; and sending a successful unbinding message to the confidential virtual machine. Conversely, if the device information of the unbound device records the identification information of another device as an interconnection information field, it indicates that the unbound device has established a direct communication link with another computing device, then the direct communication link between the unbound device and the other device is disconnected; the confidential virtual machine's tag, the allocation information assigned to the confidential virtual machine, the confirmation information trusted by the confidential virtual machine, and the identification information of another device as an interconnection information field are deleted from the device information of the unbound device; the identification information of the unbound device as an interconnection information field is deleted from the device information of the other device; and a successful unbinding message is sent to the confidential virtual machine.

[0038] S105. If at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, then a corresponding notification message is sent to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that has not established a trusted communication connection.

[0039] In this embodiment, the notification message prompting the confidential virtual machine to establish a trusted communication connection with the computing device that has not yet established a trusted communication connection may carry the device identification information of the computing device to which the trusted communication connection is to be established, such as the IP address.

[0040] In this embodiment, the control terminal can establish a direct communication link between different computing devices trusted by the confidential virtual machine based on the target request sent by the confidential virtual machine to enable direct connection between at least two computing devices, and record the corresponding interconnection information. Thus, different computing devices trusted by the same confidential virtual machine can communicate directly through their interconnected direct communication links without relying on the confidential virtual machine or other third-party devices for data forwarding. This reduces transmission latency, improves communication efficiency between different computing devices, and facilitates efficient task processing on different computing devices.

[0041] This application also discloses another data processing method applied to a confidential virtual machine, comprising: sending a target request to enable at least two computing devices to directly connect to a control terminal, so that the control terminal determines whether at least two computing devices have established trusted communication connections with the confidential virtual machine; if at least two computing devices have established trusted communication connections with the confidential virtual machine, sending direct connection information to each of the at least two computing devices, so that the at least two computing devices establish direct communication links in pairs and negotiate communication keys in pairs; after confirming that at least two computing devices have established direct communication links in pairs and negotiated communication keys in pairs, recording the interconnection information of each direct communication link; wherein, the confidential virtual machine is connected to the control terminal, the control terminal is connected to multiple computing devices, and the at least two computing devices are some or all of the multiple computing devices.

[0042] In one implementation, a confidential virtual machine sends ciphertext of a target task to a corresponding computing device via an arbitrary trusted communication connection, so that the computing device receiving the ciphertext executes the target task. The confidential virtual machine and the arbitrary computing device communicate using a negotiated communication key, thus the confidential virtual machine sends the ciphertext of the target task via the arbitrary trusted communication connection.

[0043] In one implementation, the computing device that receives the target task ciphertext transmits the task processing data ciphertext to other computing devices via a direct communication link. The different computing devices communicate using a mutually agreed-upon communication key, thus the computing device that receives the target task ciphertext transmits the task processing data ciphertext via the direct communication link.

[0044] This embodiment enables direct encrypted communication using a symmetric key between a confidential virtual machine and any computing device, as well as direct encrypted communication using a symmetric key between different computing devices connected to the same confidential virtual machine. This reduces transmission latency between different computing devices, improves communication efficiency between different computing devices, and facilitates efficient processing of tasks on different computing devices.

[0045] Please see Figure 2 , Figure 2This diagram illustrates a data processing system, comprising: a security control module (i.e., the control terminal), a confidential virtual machine, and n heterogeneous devices (i.e., n computing devices). The security control module is secure hardware capable of maintaining a device information table. After establishing trust relationships between the confidential virtual machine and the heterogeneous devices, and between different heterogeneous devices, direct connections can be achieved. Data confidentiality is protected through pairwise negotiation of symmetric keys, and data integrity is protected through digital signatures. The security control module can enumerate all heterogeneous devices to obtain basic information about each device, such as IP address, type, and performance parameters.

[0046] In one example, the virtual machine certificate management module maintains a list of virtual machine public key certificates. Confidential virtual machines establish trust with devices based on their public keys and protect transmitted data through symmetric encryption and digital signatures. Trusted devices can also establish trust based on their public keys and protect transmitted data through symmetric encryption and digital signatures.

[0047] The security control module requires authentication of the virtual machine's public key. The specific process includes: the hypervisor creates the virtual machine and assigns it a VMID tag. The virtual machine generates a public-private key pair (pk1, sk1). The virtual machine uses the private key sk1 to sign the VMID and sends the signature, VMID, and public key pk1 to the virtual machine certificate management module. The virtual machine certificate management module verifies the signature about the VMID using pk1 and then sends a random value r1 to the virtual machine. The virtual machine uses sk1 to sign the random value r1 and sends the signature to the virtual machine certificate management module. The virtual machine certificate management module verifies the signature about the random value r1 using pk1. If the verification is successful, the virtual machine certificate management module issues a certificate for pk1 to the virtual machine and adds the certificate to the virtual machine certificate list. The virtual machine certificate management module can be located within the security control module or on other devices trusted by both the security control module and the virtual machine.

[0048] The security control module also sets up a confidential virtual machine. The specific process includes: the virtual machine sends its virtual machine tag VMID and public key pk1 to the security control module, requesting to be designated as a confidential virtual machine. The security control module searches the virtual machine certificate list to confirm whether pk1 is a valid public key corresponding to the VMID. If pk1 is a valid public key corresponding to the VMID, the security control module sends a random value r2 to the virtual machine, requesting the virtual machine to sign the random value using its private key. The random value r2 can be generated using any random function or algorithm. The virtual machine signs the random value r2 from the security control module using sk1 and sends the signature to the security control module. The security control module verifies the signature of the random value r2 using pk1. If the verification is successful, the security control module marks the virtual machine as a confidential virtual machine. The security control module generates an encryption key for the secure virtual machine (the key used by the virtual machine to encrypt its own memory), encrypts the encryption key using pk1, signs the ciphertext using the security control module's private key, and finally sends the ciphertext and signature to the confidential virtual machine. After receiving the signature from the security control module, the confidential virtual machine verifies the signature using the security control module's public key. If the verification is successful, the confidential virtual machine then uses the private key sk1 to decrypt the ciphertext and obtain the encryption key.

[0049] The confidential virtual machine requests to bind to a heterogeneous device from the security control module. The specific process includes: the security control module maintaining a device information table, such as... Figure 3 As shown, the fields in the device information table can include: device type, device public key pk2, device certificate, vendor information, etc., which are inherent information of the device itself; the allocation bit is a flag indicating whether the device has been allocated to a confidential virtual machine; the confirmation bit is a flag indicating whether the confidential virtual machine has included the device in the trusted boundary; the VMID field stores the confidential virtual machine's tag VMID; the allocation time and confirmation time represent the time when the device was allocated to the confidential virtual machine and the time when the confidential virtual machine confirmed that it trusts the device, respectively. Inter-device interconnection information indicates the interconnection status between devices, i.e., the interconnection information field. The confidential virtual machine sends a request to the security control module, requesting direct connection to a certain type of device. The request can specify parameters such as device type and performance. The security control module searches the device information table and finds devices that meet the confidential virtual machine type requirements and have not been allocated to any confidential virtual machine. The security control module sets the allocation bit of the selected device information entry to 1, indicating that the device has been allocated to a confidential virtual machine. The security control module adds the VMID field and allocation time field to the corresponding device entry in the device information table. The security control module sends the device information (device type, vendor, allocation time) to the confidential virtual machine.

[0050] The security control module acts as an intermediary, enabling trusted connections between the confidential virtual machine and heterogeneous devices. Specifically, after receiving device information from a heterogeneous device via the security control module, the confidential virtual machine selects a random value r3. It then encrypts the random value r3 using the heterogeneous device's public key pk2, and signs the ciphertext and VMID using its private key sk1. The confidential virtual machine sends the ciphertext, VMID, and signature to the security control module, which in turn sends them to the heterogeneous device. Upon receiving the ciphertext, VMID, and signature from the security control module, the heterogeneous device verifies the validity of the signature regarding the ciphertext and VMID using the confidential virtual machine's public key pk1. If verification is successful, the heterogeneous device decrypts the ciphertext using its private key, obtaining the random value r3. The heterogeneous device then selects a random value r4 and encrypts r3|r4 using the confidential virtual machine's public key pk1, where | represents concatenating two strings. Finally, the heterogeneous device signs the ciphertext using its private key. Finally, the heterogeneous device sends the ciphertext and signature to the security control module, which then forwards them to the confidential virtual machine. The heterogeneous device uses r3 and r4, the private key sk3 (any key generation algorithm) used by the confidential virtual machine to communicate with it. Upon receiving the ciphertext and signature from the heterogeneous device, the confidential virtual machine uses the heterogeneous device's public key pk2 to verify if the signature is valid. If verification is successful, the confidential virtual machine decrypts the ciphertext using its private key sk1. For the decrypted plaintext, the confidential virtual machine compares the first half with r3. If they match, the confidential virtual machine reads the second half r4 and uses r3 and r4 to compute the private key used by the confidential virtual machine to communicate with the heterogeneous device, which matches sk3. The confidential virtual machine sends an acknowledgment request to the security control module, confirming that the heterogeneous device is included within its trust boundary; this heterogeneous device is then considered a trusted device of the confidential virtual machine. The security control module sets the acknowledgment bit field of the corresponding device entry in the device information table to 1 and adds an allocation time field.

[0051] The process of secure communication between a confidential virtual machine (VM) and a trusted device includes the following steps: When the trusted device sends data to the VM, it encrypts the data using its private key sk3 and then signs the hash value of the ciphertext using its private key sk2. The device sends the ciphertext and signature to the VM. Upon receiving the message from the device, the VM calculates the hash value of the ciphertext and then verifies the validity of the signature using the device's public key pk2. If the verification is successful, the VM decrypts the ciphertext using sk3 to obtain the corresponding plaintext, which is the data sent by the trusted device. Alternatively, when the VM sends data to the trusted device, it encrypts the data using its private key sk3 and then signs the hash value of the ciphertext using its private key sk1. The VM sends the ciphertext and signature to the device. Upon receiving the message from the VM, the device calculates the hash value of the ciphertext and then verifies the validity of the signature using its public key pk1. If the verification is successful, the device decrypts the ciphertext using sk3 to obtain the corresponding plaintext, which is the data sent by the VM to the trusted device.

[0052] As can be seen, the virtual machine certificate management module maintains a list of virtual machine public key certificates. Virtual machines can use these public keys to prove their identity to the security control module and obtain encryption keys. The security control module maintains a device information table, binding confidential virtual machines and trusted devices through corresponding fields to achieve trusted device isolation and protection. Confidential virtual machines and trusted devices interact to construct a symmetric encryption private key, which is used to protect the confidentiality of transmitted data. After encrypting the sent data, the confidential virtual machine and trusted device calculate the hash value of the ciphertext and then digitally sign the hash value using their own private keys, protecting the integrity of the transmitted data.

[0053] The process of establishing a trusted connection between different heterogeneous devices connected to the same confidential virtual machine includes: the confidential virtual machine sends a request to the security control module, requesting a direct connection between trusted devices. The request includes basic information about the devices that need to be connected. The security control module retrieves the device information table, confirming whether the VMID field of the corresponding device entry matches the VMID of the confidential virtual machine that sent the request, and whether both the allocation and acknowledgment bits are set to 1, to confirm whether the devices needing to be connected are connected to the same virtual machine. If the VMID field of the corresponding device entry in the device information table matches the VMID of the confidential virtual machine that sent the request, and both the allocation and acknowledgment bits are set to 1, the security control module configures the inter-device interconnection information field of the corresponding device entry in the device information table, marking other devices allowed to directly connect to the device. The security control module sends the device information of other trusted devices allowed to directly connect to the two trusted devices that need to establish a connection, and the devices establish a connection based on this message. The memory of the two interconnected devices is mutually mapped, enabling communication via DMA. The communication keys between different heterogeneous devices are negotiated using the key negotiation method described above for confidential virtual machines and single heterogeneous devices. Specifically, trusted device 1 selects a random value r6, encrypts r6 using the public key of trusted device 2, and then signs the ciphertext and trusted device 1's device information using the private key of trusted device 1. Trusted device 1 sends the ciphertext, trusted device 1's device information, and the signature to trusted device 2. Upon receiving the ciphertext, trusted device 1's device information, and the signature from trusted device 1, trusted device 2 verifies whether trusted device 1 is present in its inter-device interconnection information field. If trusted device 2 confirms that trusted device 1 is present in its inter-device interconnection information field, trusted device 2 uses the public key of trusted virtual machine 1 to verify whether the signature is a valid signature of the ciphertext and trusted device 1's device information. If the verification passes, trusted device 2 decrypts the ciphertext using its private key to obtain the random value r6. Trusted device 2 selects a random value r7 and encrypts r6|r7 using the public key of trusted device 1. Then, trusted device 2 signs the ciphertext using its private key. Trusted device 2 sends the ciphertext and the signature to trusted device 1. Trusted device 2 uses r6 and r7 to calculate the private key sk4 for communication between trusted device 1 and trusted device 2. After receiving the ciphertext and signature from trusted device 2, trusted device 1 uses trusted device 2's public key to verify if the signature is valid. If the verification passes, trusted device 1 decrypts the ciphertext using its private key. For the decrypted plaintext, trusted device 1 compares the first half of the plaintext with r6. If they match, trusted device 1 receives the second half of the plaintext, r7, and uses r6 and r7 to calculate the private key for communication between trusted device 1 and trusted device 2, which matches sk4.

[0054] The process of secure communication between different heterogeneous devices includes: When Trusted Device 1 sends data to Trusted Device 2, it encrypts the data using its private key sk4, and then signs the hash value of the ciphertext using its own private key. Trusted Device 1 sends the ciphertext and signature to Trusted Device 2. After receiving the message from Trusted Device 1, Trusted Device 2 calculates the hash value of the ciphertext and then verifies the validity of the signature using Trusted Device 1's public key. If the verification is successful, Trusted Device 2 decrypts the ciphertext using sk4 to obtain the corresponding plaintext, which is the data sent by Trusted Device 1 to Trusted Device 2. Alternatively, when Trusted Device 2 sends data to Trusted Device 1, it encrypts the data using its private key sk4, and then signs the hash value of the ciphertext using its own private key. Trusted Device 2 sends the ciphertext and signature to Trusted Device 1. After receiving the message from Trusted Device 2, Trusted Device 1 calculates the hash value of the ciphertext and then verifies the validity of the signature using Trusted Device 2's public key. If the verification is successful, Trusted Device 1 decrypts the ciphertext using sk4 to obtain the corresponding plaintext, which is the data sent by Trusted Device 2 to Trusted Device 1.

[0055] As can be seen, trusted devices interact to build a symmetric encryption private key, which is then used to protect the confidentiality of transmitted data. After encrypting the data to be sent, the trusted device calculates a hash value for the ciphertext and then uses its own private key to digitally sign the hash value, protecting the integrity of the transmitted data. Direct connection between devices improves data transmission efficiency and reduces the load on confidential virtual machines.

[0056] The process of unbinding any heterogeneous device from a confidential virtual machine includes: the confidential virtual machine sending an unbinding request to the security control module, the request containing device information. The security control module retrieves the device information table, sets the allocation bit and confirmation bit of the corresponding device entry to 0, and clears the VMID, allocation time, and confirmation time. For the inter-device interconnection information field, if it is not empty, the security control module modifies the inter-device interconnection information field of the corresponding device entry within the inter-device interconnection field, clearing the corresponding device information (first disconnecting devices with direct communication connections to the unbound device). Finally, the security control module clears the inter-device interconnection information field.

[0057] In this embodiment, each heterogeneous computing device can receive model inference tasks and other data sent by a confidential virtual machine, and perform corresponding confidential computation. Confidential computing is a computing paradigm designed to protect the security of data in use, and is an important technology for solving data security issues under computational efficiency constraints. This technology is based on a Trusted Execution Environment (TEE) and achieves data and code security through hardware-level system isolation. Setting up TEE-based confidential computing on heterogeneous devices can protect the efficient processing of data on the accelerator from external threats and ensure that the executed tasks are not interfered with by malware.

[0058] In this embodiment, the virtual machine establishes a secure connection with the security control module. The security control module marks the virtual machine as a confidential virtual machine and sends its memory encryption key to the confidential virtual machine in a secure manner. Then, the confidential virtual machine establishes a secure connection with the device. The security control module marks the device as a trusted device corresponding to the confidential virtual machine and achieves direct connection between the confidential virtual machine and the trusted device by maintaining a device information table. The confidential virtual machine and the trusted device protect the confidentiality and integrity of data transmission through symmetric encryption and digital signatures. The security control module also marks the direct connection relationship between trusted devices in the corresponding fields of the device information table. Then, a secure connection is established between trusted devices, and the confidentiality and integrity of data transmission are protected through symmetric encryption and digital signatures, improving data transmission efficiency. A trusted device can only interconnect with a unique confidential virtual machine, achieving device isolation protection.

[0059] The following describes a data processing system provided by an embodiment of this application. The data processing system described below can be referred to in conjunction with other embodiments described herein.

[0060] See Figure 4 As shown in the illustration, this application discloses a data processing system, including a control terminal, a confidential virtual machine, and multiple computing devices. The control terminal is connected to the confidential virtual machine and the multiple computing devices. The control terminal can also connect to more confidential virtual machines.

[0061] The control terminal is used to: receive a target request sent by a confidential virtual machine to enable direct connection between at least two computing devices; determine whether both computing devices have established trusted communication connections with the confidential virtual machine; if both computing devices have established trusted communication connections with the confidential virtual machine, send direct connection information to each of the at least two computing devices to enable them to establish direct communication links and negotiate communication keys; and after confirming that at least two computing devices have established direct communication links and negotiated communication keys, record the interconnection information of each direct communication link.

[0062] In one implementation, the control terminal is configured to: query the device information of at least two computing devices respectively; if the device information of any computing device records a tag of a confidential virtual machine, allocation information that has been assigned to a confidential virtual machine, and confirmation information that has been trusted by the confidential virtual machine, then confirm that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, confirm that the computing device has not established a trusted communication connection with the confidential virtual machine.

[0063] In one implementation, the control terminal is configured to: if at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, send a corresponding notification message to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that has not established a trusted communication connection.

[0064] In one implementation, the control terminal is used to: receive a device connection request sent by a confidential virtual machine; determine the connection requirements of the confidential virtual machine based on the device connection request; select a target device that matches the connection requirements from unassigned computing devices; record the label of the confidential virtual machine and the allocation information already assigned to the confidential virtual machine in the device information of the target device, and then send the device information of the target device to the confidential virtual machine, so that the confidential virtual machine can use the control terminal as a communication relay station to establish a trusted communication connection with the target device and negotiate a communication key.

[0065] In one implementation, the control terminal is configured to: receive a trusted confirmation message from the target device after the confidential virtual machine and the target device have completed communication key negotiation; and in response to the trusted confirmation message, record confirmation information trusted by the confidential virtual machine in the device information of the target device.

[0066] In one implementation, the control terminal is configured to: receive encrypted ciphertext, first signature information, and a tag of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is obtained by the confidential virtual machine encrypting a first random value using the public key of the target device; the first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the tag of the confidential virtual machine using its own private key; forward the encrypted ciphertext, the first signature information, and the tag of the confidential virtual machine to the target device; receive combined data ciphertext and second signature information sent by the target device; after the target device verifies the first signature information using the public key of the confidential virtual machine, it decrypts the encrypted ciphertext using its own private key, combines the second random value with the decrypted first random value, and then uses the public key of the confidential virtual machine to verify the combined data ciphertext. The data is encrypted; the second signature information is obtained by the target device signing the combined ciphertext using its own private key; the target device performs key calculation on the second random value and the first random value using the first key algorithm to obtain the communication key negotiated with the confidential virtual machine; the combined ciphertext and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine can verify the second signature information using the target device's device public key, and then decrypt the combined ciphertext using its own private key to obtain the second random value and the first random value. When the decrypted first random value is consistent with the first random value stored by itself, the first key algorithm is used to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the target device, and then a trusted confirmation message from the target device is sent to the control end.

[0067] In one embodiment, the control terminal is used to: designate two computing devices connected by each direct communication link as a first device and a second device; record the identification information of the second device in the device information of the first device as an interconnection information field of the corresponding direct communication link; and record the identification information of the first device in the device information of the second device as an interconnection information field of the corresponding direct communication link.

[0068] In one implementation, the control terminal is configured to: receive a device unbinding request sent by the confidential virtual machine; determine the device to be unbound by the confidential virtual machine based on the device unbinding request; if the device information of the unbound device does not record the identification information of another device as an interconnection information field, delete the label of the confidential virtual machine, the allocation information already assigned to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine from the device information of the unbound device; and send a successful unbinding message to the confidential virtual machine.

[0069] In one implementation, the control terminal is configured to: disconnect the direct communication link between the unbound device and the other device if the device information of the unbound device contains the identification information of another device as an interconnection information field; delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, the confirmation information that the confidential virtual machine has trusted, and the identification information of the other device as an interconnection information field from the device information of the unbound device; delete the identification information of the unbound device as an interconnection information field from the device information of the other device; and send a successful unbinding message to the confidential virtual machine.

[0070] In one implementation, the confidential virtual machine sends a target request to the control terminal to enable direct connection between at least two computing devices. The control terminal then determines whether both computing devices have established trusted communication connections with the confidential virtual machine. If both computing devices have established trusted communication connections with the confidential virtual machine, the control terminal sends direct connection information to each of the at least two computing devices, enabling them to establish direct communication links and negotiate communication keys. After confirming that at least two computing devices have established direct communication links and negotiated communication keys, the control terminal records the interconnection information of each direct communication link. The confidential virtual machine is connected to the control terminal, and the control terminal is connected to multiple computing devices. The at least two computing devices may be some or all of the multiple computing devices.

[0071] In one implementation, a confidential virtual machine sends a target task ciphertext to a corresponding computing device via any trusted communication connection, so that the computing device that receives the target task ciphertext executes the target task.

[0072] In one implementation, the computing device that receives the target task ciphertext transmits the task processing data ciphertext to other computing devices via a direct communication link.

[0073] For more detailed information on the working process of each terminal in this embodiment, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.

[0074] As can be seen, this embodiment provides a data processing device that can reduce transmission latency between different computing devices, improve communication efficiency between different computing devices, and facilitate efficient processing of tasks on different computing devices.

[0075] The following describes an electronic device provided by an embodiment of this application. The electronic device described below can be referred to in conjunction with other embodiments described herein.

[0076] See Figure 5 As shown in the figure, this application discloses an electronic device, including: a memory 501 for storing a computer program; and a processor 502 for executing the computer program to implement the method disclosed in any of the above embodiments.

[0077] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a target request sent by a confidential virtual machine to enable direct connection between at least two computing devices; determining whether both computing devices have established a trusted communication connection with the confidential virtual machine; if both computing devices have established a trusted communication connection with the confidential virtual machine, sending direct connection information to each of the at least two computing devices to enable them to establish direct communication links and negotiate communication keys; and recording the interconnection information of each direct communication link after confirming that at least two computing devices have established direct communication links and negotiated communication keys.

[0078] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: query the device information of at least two computing devices respectively; if the device information of any computing device records a tag of a confidential virtual machine, allocation information that has been assigned to a confidential virtual machine, and confirmation information that it has been trusted by the confidential virtual machine, then it is confirmed that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device has not established a trusted communication connection with the confidential virtual machine.

[0079] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: if at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, then a corresponding notification message is sent to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that has not established a trusted communication connection.

[0080] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a device connection request sent by a confidential virtual machine; determining the connection requirements of the confidential virtual machine based on the device connection request; selecting a target device that matches the connection requirements from unassigned computing devices; recording the label of the confidential virtual machine and the allocation information already assigned to the confidential virtual machine in the device information of the target device, and then sending the device information of the target device to the confidential virtual machine, so that the confidential virtual machine can establish a trusted communication connection with the target device using the control terminal as a communication relay station, and negotiate a communication key.

[0081] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a trusted confirmation message from the target device after the confidential virtual machine and the target device have completed communication key negotiation; and in response to the trusted confirmation message, recording confirmation information trusted by the confidential virtual machine in the device information of the target device.

[0082] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving encrypted ciphertext, first signature information, and a tag of the confidential virtual machine sent by the confidential virtual machine; the encrypted ciphertext is obtained by the confidential virtual machine encrypting a first random value using the public key of the target device; the first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the tag of the confidential virtual machine using its own private key; forwarding the encrypted ciphertext, the first signature information, and the tag of the confidential virtual machine to the target device; receiving combined data ciphertext and second signature information sent by the target device; after the target device verifies the first signature information using the public key of the confidential virtual machine, it decrypts the encrypted ciphertext using its own private key, and combines the second random value with the decrypted first random value. The combined data is encrypted using the public key of the confidential virtual machine; the second signature information is obtained by the target device signing the encrypted combined data using its own private key; the target device performs key calculation on the second random value and the first random value using the first key algorithm to obtain the communication key negotiated with the confidential virtual machine; the encrypted combined data and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine can verify the second signature information using the target device's device public key, and then decrypt the encrypted combined data using its own private key to obtain the second random value and the first random value. When the decrypted first random value is consistent with the first random value stored by itself, the first key algorithm is used to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the target device, and then a trusted confirmation message from the target device is sent to the control end.

[0083] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: designating the two computing devices connected by each direct communication link as a first device and a second device; recording the identification information of the second device in the device information of the first device as an interconnection information field of the corresponding direct communication link; and recording the identification information of the first device in the device information of the second device as an interconnection information field of the corresponding direct communication link.

[0084] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a device unbinding request sent by the confidential virtual machine; determining the unbinding device to be unbound by the confidential virtual machine based on the device unbinding request; if the device information of the unbinding device does not record the identification information of another device as an interconnection information field, then deleting the confidential virtual machine's tag, the allocation information already assigned to the confidential virtual machine, and the confirmation information trusted by the confidential virtual machine from the device information of the unbinding device; and sending a successful unbinding message to the confidential virtual machine.

[0085] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: if the device information of the unbinding device records the identification information of another device as an interconnection information field, then disconnect the direct communication link between the unbinding device and the other device; delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, the confirmation information that the confidential virtual machine has trusted, and the identification information of the other device as an interconnection information field from the device information of the unbinding device; delete the identification information of the unbinding device as an interconnection information field from the device information of the other device; and send a successful unbinding message to the confidential virtual machine.

[0086] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: sending a target request to directly connect at least two computing devices to the control terminal.

[0087] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: sending the target task ciphertext to the corresponding computing device through any trusted communication connection, so that the computing device that receives the target task ciphertext executes the target task.

[0088] Furthermore, embodiments of this application also provide an electronic device. The aforementioned electronic device can be, for example,... Figure 6 The server shown can also be as follows: Figure 7 The terminal shown. Figure 6 and Figure 7 These are all diagrams illustrating the structure of an electronic device according to an exemplary embodiment. The content in the diagrams should not be considered as any limitation on the scope of this application.

[0089] Figure 6 This is a schematic diagram of a server structure provided in an embodiment of this application. The server may specifically include: at least one processor, at least one memory, a power supply, a communication interface, an input / output interface, and a communication bus. The memory stores a computer program, which is loaded and executed by the processor to implement the relevant steps in the data processing disclosed in any of the foregoing embodiments.

[0090] In this embodiment, the power supply is used to provide operating voltage for each hardware device on the server; the communication interface can create a data transmission channel between the server and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0091] In addition, the memory, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored on it include operating system, computer programs and data, etc., and the storage method can be temporary storage or permanent storage.

[0092] The operating system manages and controls the various hardware devices and computer programs on the server to enable the processor to perform operations and processes on the data in the memory. It can be Windows Server, Netware, Unix, Linux, etc. In addition to computer programs capable of performing the data processing methods disclosed in any of the foregoing embodiments, the computer programs may further include computer programs capable of performing other specific tasks. The data may include application update information and application developer information.

[0093] Figure 7 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application. The terminal may include, but is not limited to, a smartphone, tablet computer, laptop computer, or desktop computer.

[0094] Typically, the terminal in this embodiment includes a processor and a memory.

[0095] The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor can be implemented using at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor may also include a main processor and coprocessors. The main processor, also known as the CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which handles computational operations related to machine learning.

[0096] The memory may include one or more computer non-volatile storage media, which may be non-transitory. The memory may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory is used to store at least the following computer program, which, after being loaded and executed by the processor, is capable of implementing the relevant steps in the data processing method executed by the terminal side as disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory may also include operating systems and data, and the storage method may be temporary or permanent storage. The operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, application update information.

[0097] In some embodiments, the terminal may further include a display screen, an input / output interface, a communication interface, a sensor, a power supply, and a communication bus.

[0098] Those skilled in the art will understand that Figure 7 The structure shown does not constitute a limitation on the terminal and may include more or fewer components than illustrated.

[0099] The following describes a non-volatile storage medium provided in an embodiment of this application. The non-volatile storage medium described below can be referred to in conjunction with other embodiments described herein.

[0100] A non-volatile storage medium is provided for storing a computer program, wherein the computer program, when executed by a processor, implements the data processing method disclosed in the foregoing embodiments. The non-volatile storage medium is a computer-readable non-volatile storage medium, which, as a carrier for resource storage, can be a read-only memory, random access memory, disk, or optical disk, etc. The resources stored thereon include an operating system, computer programs, and data, and the storage method can be temporary storage or permanent storage.

[0101] The following describes a computer program product provided by an embodiment of this application. The computer program product described below can be referred to in conjunction with other embodiments described herein.

[0102] A computer program product includes a computer program / instructions that, when executed by a processor, implement the steps of the aforementioned disclosed data processing method.

[0103] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the steps in any of the above embodiments.

[0104] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0105] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of non-volatile storage medium known in the art.

[0106] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only intended to help understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data processing method, characterized in that, It is used as a control terminal, which connects a confidential virtual machine and multiple computing devices, including: Receive the target request sent by the confidential virtual machine to enable direct connection between at least two computing devices; Determine whether both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine; If both computing devices have established trusted communication connections with the confidential virtual machine, then a direct connection information is sent to each of the at least two computing devices to enable them to establish direct communication links and negotiate communication keys. After confirming that the at least two computing devices have established direct communication links in pairs and negotiated communication keys in pairs, the interconnection information of each direct communication link is recorded. The determination of whether both computing devices have established trusted communication connections with the confidential virtual machine includes: Query the device information of each of the at least two computing devices; If any computing device's device information records the tag of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, and the confirmation information that it has been trusted by the confidential virtual machine, then it is confirmed that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device has not established a trusted communication connection with the confidential virtual machine. If at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, a corresponding notification message is sent to the confidential virtual machine to prompt it to establish a trusted communication connection with the computing device that has not established a trusted communication connection.

2. The method according to claim 1, characterized in that, Also includes: Receive the device connection request sent by the confidential virtual machine; The connection requirements of the confidential virtual machine are determined based on the device connection request. Select a target device that matches the connectivity requirements from the unassigned computing devices; After recording the tag of the confidential virtual machine and the allocation information assigned to the confidential virtual machine in the device information of the target device, the device information of the target device is sent to the confidential virtual machine, so that the confidential virtual machine can use the control terminal as a communication relay station to establish a trusted communication connection with the target device and negotiate a communication key.

3. The method according to claim 2, characterized in that, Also includes: After the confidential virtual machine and the target device complete the communication key negotiation, the target device sends a trusted confirmation message from the target device. In response to the trusted confirmation message, confirmation information that has been trusted by the confidential virtual machine is recorded in the device information of the target device.

4. The method according to claim 2, characterized in that, Also includes: Receive encrypted ciphertext, first signature information, and the tag of the confidential virtual machine sent by the confidential virtual machine; The encrypted ciphertext is obtained by the confidential virtual machine encrypting a first random value using the device public key of the target device; The first signature information is obtained by the confidential virtual machine signing the encrypted ciphertext and the label of the confidential virtual machine using its own private key; The encrypted ciphertext, the first signature information, and the label of the confidential virtual machine are forwarded to the target device; The system receives a combined encrypted data and a second signature information sent by the target device. The combined encrypted data is obtained by the target device verifying the first signature information using the public key of the confidential virtual machine, then decrypting the encrypted data using its own private key, combining a second random value with the decrypted first random value, and then encrypting the combined data using the public key of the confidential virtual machine. The second signature information is obtained by the target device signing the combined encrypted data using its own private key. The target device uses a first key algorithm to perform key calculation on the second random value and the first random value to obtain a communication key negotiated with the confidential virtual machine; The combined encrypted data and the second signature information are forwarded to the confidential virtual machine, so that the confidential virtual machine can verify the second signature information using the public key of the target device, and then decrypt the combined encrypted data using its own private key to obtain a second random value and a first random value. When the first random value obtained by decryption is consistent with the first random value stored by itself, the first key algorithm is used to perform key calculation on the second random value and the first random value to obtain the communication key negotiated with the target device. Then, a trusted confirmation message from the target device is sent to the control terminal.

5. The method according to any one of claims 1 to 4, characterized in that, Record the interconnection information of each directly connected communication link, including: The two computing devices connected by each direct communication link are designated as the first device and the second device. The identification information of the second device is recorded in the device information of the first device as the interconnection information field of the corresponding direct communication link; The identification information of the first device is recorded in the device information of the second device as the interconnection information field of the corresponding direct communication link.

6. The method according to any one of claims 1 to 4, characterized in that, Also includes: Receive the device unbinding request sent by the confidential virtual machine; The device to be unbound from the confidential virtual machine is determined based on the device unbinding request; If the device information of the unbound device does not record the identification information of another device as an interconnection information field, then delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, and the confirmation information that the confidential virtual machine has been trusted from the device information of the unbound device. Send a message indicating successful unbinding to the confidential virtual machine.

7. The method according to claim 6, characterized in that, Also includes: If the device information of the unbound device contains the identification information of another device as an interconnection information field, then the direct communication link between the unbound device and the other device is disconnected. Delete the label of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, the confirmation information that has been trusted by the confidential virtual machine, and the identification information of another device as an interconnection information field from the device information of the unbound device; Remove the identifier information of the unbound device from the interconnection information field of the device information of another device; Send a message indicating successful unbinding to the confidential virtual machine.

8. A data processing method, characterized in that, Applied to confidential virtual machines, including: A target request to enable direct connection between at least two computing devices is sent to the control terminal, so that the control terminal can determine whether both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine; if both of the at least two computing devices have established a trusted communication connection with the confidential virtual machine, then a direct connection information is sent to each of the at least two computing devices, so that the at least two computing devices establish direct connection communication links in pairs and negotiate communication keys in pairs; after confirming that the at least two computing devices have established direct connection communication links in pairs and negotiated communication keys in pairs, the interconnection information of each direct connection communication link is recorded; The confidential virtual machine is connected to the control terminal, and the control terminal is connected to multiple computing devices, wherein the at least two computing devices are some or all of the multiple computing devices; The determination of whether both computing devices have established trusted communication connections with the confidential virtual machine includes: Query the device information of each of the at least two computing devices; If any computing device's device information records the tag of the confidential virtual machine, the allocation information assigned to the confidential virtual machine, and the confirmation information that it has been trusted by the confidential virtual machine, then it is confirmed that the computing device has established a trusted communication connection with the confidential virtual machine; otherwise, it is confirmed that the computing device has not established a trusted communication connection with the confidential virtual machine. If at least one of the at least two computing devices has not established a trusted communication connection with the confidential virtual machine, the control terminal sends a corresponding notification message to the confidential virtual machine to prompt the confidential virtual machine to establish a trusted communication connection with the computing device that has not established a trusted communication connection.

Citation Information

Patent Citations

  • Multi-party cooperation method and related device

    CN115550070A

  • Data encryption protection method based on trusted virtualization environment

    CN117519900A