Database management system and method based on trusted execution environment and authentication encryption
By introducing a trusted execution environment and authentication encryption technology into the SQLite database management system, the problems of data privacy leakage and tampering are solved, and secure data transmission and integrity verification are achieved, improving the system's confidentiality and operational efficiency. It is suitable for financial terminals and IoT devices.
Patent Information
- Application Number
- CN202511053629.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-07-29
AI Technical Summary
Existing SQLite database management systems pose risks of privacy leaks and tampering during data processing, lack a unified security mechanism, have insecure key management, and insufficient data integrity verification.
A database management system based on a trusted execution environment and authentication encryption is adopted. The application host and SQLite database extension module are set in a trusted environment, while the database host is in an untrusted environment. The system uses the AES-128GCM authentication encryption algorithm and Intel SGX technology to achieve secure data transmission and integrity verification. Secure data storage and access control are achieved through hash trees and key mapping tables.
It effectively prevents data privacy leaks and tampering, enhances data confidentiality and integrity, reduces storage overhead, improves computing efficiency, supports secure sharing among multiple applications, is compatible with standard SQL syntax, and meets the security needs of financial terminals and IoT devices.
Smart Images

Figure CN121030751A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of database security, and particularly relates to a database management system and method based on a trusted execution environment and authentication encryption. BACKGROUND
[0002] SQLite is a lightweight, open-source relational database management system. Unlike most other SQL databases, SQLite does not have a separate server process. It provides high storage efficiency, fast query operation, acid transaction, and small memory requirement. A complete SQLite database is stored in a cross-platform disk file.
[0003] A database file is composed of one or more pages. All pages in the same database are of the same size. All data related to the database is stored in the page, including table records, indexes, and even available space in the database file (free list pages). Each page can be indexed by page number.
[0004] A trusted execution environment is an isolated environment running in parallel with the operating system, providing security for a resource-rich environment. It can guarantee that the loaded code and data are protected in terms of confidentiality and integrity. Tee provides security functions such as isolated execution, integrity of trusted applications, and confidentiality of its assets as an isolated execution environment. Various embedded hardware technologies aim to support TEE implementation, including AMD secure execution environment, ARM Trustzone, Intel Software Guard Extensions, and so on.
[0005] The existing SQLite security scheme has many defects. First, SQLite stores data in plaintext in local files, and any attacker who obtains file access rights can easily read or tamper with the data. Second, existing encryption extensions such as SQLCipher (SQLCipher is an open-source extension library developed based on SQLite, which enhances the security of SQLite through encryption functions. Although static data encryption is provided, the data still needs to be decrypted into memory when processing, which faces the risk of memory leakage. In addition, key management is highly dependent on the application, and there is a lack of unified security mechanism. Once the key is leaked, the data security is destroyed. At the same time, most schemes do not provide data integrity verification, and cannot prevent data tampering. SUMMARY
[0006] The present application provides a database management system and method based on a trusted execution environment and authentication encryption, aiming to solve the technical problem that the SQLite database management system in the prior art has a high risk of privacy leakage and tampering during data processing.
[0007] The application provides a database management system based on a trusted execution environment and authentication encryption, comprising: an application program host, an SQLite database extension module, and a database host, the application program host and the SQLite database extension module being arranged in a trusted environment, and the database host being arranged in a non-trusted environment; the application program host is configured to establish a secure channel with the SQLite database extension module based on any one target application program of the application program host, and to generate an encrypted file and send the encrypted file to the SQLite database extension module; the SQLite database extension module is configured to decrypt the encrypted file to obtain decrypted information and execute a page query result based on the decrypted information; the SQLite database extension module is further configured to parse the page query result to obtain a first page hash value, a label, and a first encrypted page corresponding to the page query result; the database host is in communication connection with the SQLite database extension module and is configured to read the first encrypted page based on the first page hash value; the SQLite database extension module is further configured to decrypt the first encrypted page to obtain a first page; the SQLite database extension module is further configured to execute a query statement on the first page based on the decrypted information to obtain a second page; the SQLite database extension module is further configured to judge whether the second page and the first page are the same; if the second page and the first page are not the same, the database is sent update information, and the database host is configured to update the first encrypted page to a second encrypted page based on the update information and return the second encrypted page to the SQLite database extension module as an encrypted query result; the SQLite database extension module is further configured to return the encrypted query result to the application program host after encryption; the application program host is further configured to decrypt the encrypted query result and verify the decrypted encrypted query result, and if the decrypted encrypted query result meets a preset condition, the decrypted encrypted query result is accepted.
[0008] Preferably, the application program host is configured to obtain a data key preset by a target application program, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on a remote authentication protocol; if the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
[0009] Preferably, the application host is also used to encrypt the symmetric key and the unique identifier to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module, which is used to complete the identity binding with the application host based on the encrypted identifier; The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module. Preferably, the SQLite database extension module is used to look up the symmetric key in the key mapping based on the unique identifier provided by the application host, and decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
[0010] Preferably, the database host is used to construct a hash tree, wherein each leaf node of the hash tree stores the leaf hash value of the page tag, and the hash tree calculates the root hash level by level through the child node hashes, and sends the root hash to the SQLite database extension module for storage; When the database host reads the first encrypted page based on the hash value of the first page, the database host provides the SQLite database extension module with the encrypted data, tags, leaf hash values and verification path corresponding to the first encrypted page; The SQLite database extension module calculates the function value of the first encrypted page based on encrypted data, tags, leaf hash values, verification paths, and the chain hash calculation principle, and determines whether the function value is consistent with the root hash. If they are consistent, the tag corresponding to the first encrypted page is valid.
[0011] Preferably, the application host and the SQLite database extension module use the AES-128GCM mode authentication encryption algorithm; When the SQLite database extension module stops running, it encrypts and stores its own data based on SGX sealing technology, and decrypts and loads it upon restart.
[0012] This application also provides a database management method based on a trusted execution environment and authentication encryption, including: The application host establishes a secure channel with the SQLite database extension module based on any of its target applications, generates an encrypted file, and sends the encrypted file to the SQLite database extension module. The application host and the SQLite database extension module are set in a trusted environment. The SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes page query results based on the decryption information; The SQLite database extension module parses the page query results to obtain the first page hash value, tag, and first encrypted page corresponding to the page query results; The database host is communicatively connected to the SQLite database extension module and is used to read the first encrypted page based on the hash value of the first page, wherein the database host is set in an untrusted environment; The SQLite database extension module decrypts the first encrypted page to obtain the first page, executes a query statement on the first page based on the decrypted information to obtain the second page, and determines whether the second page is the same as the first page. If the second page is not the same as the first page, update information is sent to the database. The database host updates the first encrypted page to the second encrypted page based on the update information, and returns the second encrypted page as the encrypted query result to the SQLite database extension module; The SQLite database extension module returns the encrypted query results to the application host; The application host decrypts the encrypted query result and verifies it. If the decrypted encrypted query result meets the preset conditions, it accepts the decrypted encrypted query result.
[0013] Preferably, the step of establishing a secure channel between the application host and the SQLite database extension module includes: The application host is used to obtain the data key preset by the target application, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on the remote authentication protocol; If the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
[0014] Preferably, after the step of establishing a secure channel between the application host and the SQLite database extension module based on any one of its target applications, the method further includes: The application host is also used to encrypt the symmetric key and the unique identifier to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module (SQLite engine). The SQLite database extension module is used to complete the identity binding with the application host based on the encrypted identifier. The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module.
[0015] Preferably, the SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes the page query results based on the decryption information, including: The SQLite database extension module is used to find the symmetric key in the key mapping based on the unique identifier of the application host, and to decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
[0016] The beneficial effects of this application are as follows: In terms of privacy protection, this invention utilizes the Intel SGX Trusted Execution Environment and AES-GCM authentication encryption mechanism. Data processing runs entirely in plaintext within the protected SQLite database extension module (SQLiteEnclave), effectively preventing malicious access and data tampering, significantly improving data confidentiality and integrity compared to traditional solutions. In terms of computational efficiency, the execution phase separation strategy ensures that the initialization and destruction phases only require one operation, reducing the actual query time. Simultaneously, the efficient hash tree verification mechanism has a verification path length of O(log(n)), making computational complexity controllable and suitable for large-scale data processing, thus improving overall system efficiency. In terms of multi-application sharing, an independent key is assigned to each target application through a key mapping table, achieving access isolation and permission control, supporting secure sharing of the database engine across multiple applications—something traditional single-application SQLite designs cannot match. In terms of storage optimization, a hash tree-based page tag authentication protocol is adopted, storing the authentication tag hash value in an untrusted environment and retaining only the root hash in the trusted area, reducing storage overhead. Furthermore, SGX sealing technology is used for key persistence, ensuring the security of key storage.
[0017] Furthermore, this invention is deployed on the mainstream SGX hardware platform and is highly compatible with standard SQL syntax. While ensuring system security, it also ensures good operating performance, which can better meet the stringent data security and performance requirements of scenarios such as financial terminals, smart devices, and IoT gateways. It has broad application prospects and extremely high engineering practical value. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the system structure according to an embodiment of this application.
[0019] Figure 2 This is a schematic diagram of a method flow according to an embodiment of this application.
[0020] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0021] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.
[0022] like Figure 1 , Figure 2 As shown, this application provides a database management system based on a trusted execution environment and authentication encryption, including: The application host, the SQLite database extension module, and the database host are located in a trusted environment, while the database host is located in an untrusted environment. The application host is used to establish a secure channel with the SQLite database extension module based on any of its own target applications, generate an encrypted file, and send the encrypted file to the SQLite database extension module; The SQLite database extension module is used to decrypt the encrypted file, obtain decryption information, and execute page query results based on the decryption information; The SQLite database extension module is also used to parse the page query results to obtain the first page hash value, tag, and first encrypted page corresponding to the page query results; The database host is communicatively connected to the SQLite database extension module and is used to read the first encrypted page based on the hash value of the first page. The SQLite database extension module is also used to decrypt the first encrypted page to obtain the first page; It is also used to execute a query statement on the first page based on the decrypted information to obtain the second page; It is also used to determine whether the second page and the first page are the same; If the second page is different from the first page, an update message is sent to the database. The database host is used to update the first encrypted page to the second encrypted page based on the update message, and return the second encrypted page as an encrypted query result to the SQLite database extension module. The SQLite database extension module is also used to encrypt the encrypted query results and return them to the application host; The application host is also used to decrypt the encrypted query result and verify the decrypted encrypted query result. If the decrypted encrypted query result meets the preset conditions, the host accepts the decrypted encrypted query result.
[0023] As described above, the database management system architecture based on trusted execution environment and authentication encryption in this application consists of three core parts: an application host, an SQLite database extension module, and a database host. The application host and the SQLite database extension module are housed in a trusted environment, such as physically isolating the application host or using another Intel SGX enclave. (SGX is a hardware-based security technology introduced by Intel, designed to provide a secure execution environment for applications to protect sensitive data and code from potential attacks, ensuring security even if the operating system or other software layers are compromised. An Enclave (secure area) is a protected memory area within SGX that creates an isolated execution environment inside the processor. Applications can place sensitive code and data within this enclave; only code within the enclave can access this sensitive information. External software, including the operating system and malware, cannot directly access the data and execution process within the enclave, thus achieving strong isolation and protection of critical information and operations.)
[0024] The application host is primarily responsible for keys, encrypting SQL query requests, and decrypting query results. The SQLite Enclave is an extension of the SQLite database that leverages hardware-level security features to protect database operations. This means that even if the operating system or malware attempts to access this data, they cannot easily read or modify the data stored in the SQLite Enclave. This is extremely useful for scenarios where sensitive data needs to be stored in untrusted environments, such as cloud services or IoT devices.
[0025] The database host is located in an untrusted environment. Internally, the database host contains an SQLite Store, which stores encrypted database files (Ciphertext) and hash structures (Merkle trees). It also contains an SQLite Agent, which acts as a proxy between applications and the database environment's operating system. This agent handles untrusted operations (such as system calls) and interacts with the SQLite database extension module (SQLite Enclave) via OCALL (Out-of-Enclave Call) / ECALL (Enclave Call) mechanisms.
[0026] This application is deployed on the mainstream SGX hardware platform and is highly compatible with standard SQL syntax. It can avoid privacy leaks and tampering during data processing. While ensuring system security, it also ensures good operating performance. It can better meet the stringent data security and performance requirements of scenarios such as financial terminals, smart devices, and IoT gateways. It has broad application prospects and extremely high engineering practical value.
[0027] In one embodiment, the application host is used to obtain the data key pre-set by the target application, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on the remote authentication protocol; If the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
[0028] As mentioned above, this application assigns an independent key to each target application through a key mapping table, thereby achieving access isolation and permission control, and supporting a secure shared database engine for multiple applications, which is unmatched by the traditional single-application design of SQLite.
[0029] In one embodiment, the application host is further configured to encrypt the symmetric key ki and the unique identifier IDi to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module (SQLite engine), the SQLite database extension module being configured to complete the identity binding with the application host based on the encrypted identifier; The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module.
[0030] In one embodiment, the SQLite database extension module is used to find the symmetric key in the key mapping based on the unique identifier of the application host, and decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
[0031] In one embodiment, the database host is used to construct a hash tree, wherein each leaf node of the hash tree stores the leaf hash value of the page tag, and the hash tree calculates the root hash level by level through the child node hashes, and sends the root hash to the SQLite database extension module for storage. When the database host reads the first encrypted page based on the hash value of the first page, the database host provides the SQLite database extension module with the encrypted data, tags, leaf hash values and verification path corresponding to the first encrypted page; The SQLite database extension module calculates the function value of the first encrypted page based on encrypted data, tags, leaf hash values, verification paths, and the chain hash calculation principle, and determines whether the function value is consistent with the root hash. If they are consistent, the tag corresponding to the first encrypted page is valid.
[0032] As described above, this application employs a hash tree-based page tag authentication protocol, storing the authentication tag hash value in an untrusted environment and retaining only the root hash in the trusted region, thus reducing storage overhead. Simultaneously, SGX sealing technology is used for key persistence, ensuring the security of key storage. The execution phase separation strategy ensures that the overhead of the initialization and destruction phases only occurs once, reducing the actual query time. Furthermore, the efficient hash tree verification mechanism has a verification path length of O(log(n)), making its computational complexity controllable and suitable for large-scale data processing, thereby improving the overall system operating efficiency.
[0033] In one embodiment, the application host and the SQLite database extension module employ an authentication encryption algorithm in AES-128GCM mode; When the SQLite database extension module stops running, it encrypts and stores its own data based on SGX sealing technology, and decrypts and loads it upon restart.
[0034] As described above, this application utilizes the Intel SGX Trusted Execution Environment and AES-GCM authentication encryption mechanism to ensure that the entire data processing is carried out in plaintext within the protected SQLite database extension module (SQLite Enclave), effectively preventing malicious access and data tampering. Compared with traditional solutions, this greatly improves the confidentiality and integrity of the data.
[0035] To facilitate a better understanding of this system, the following example illustrates the overall process: The system includes a database host, an SQLite database extension module (SQLite Enclave), and an application host. The database host contains an SQLite storage module, the SQLite extension module (SQLite Enclave) contains an SQLite engine, and the application host has any number of applications i installed. The default information for application i is a data key, and its SQL statement (target query statement) is Sj. The default information for the SQLite database extension module is a password mapping table, represented as follows: And the application's i-tag mapping table, represented as ; 1. Initialization Phase Suppose that application i wants to use this system. It first generates a symmetric key ki based on the data key, verifies the integrity of the SQLite Enclave through the SGX remote authentication protocol, and establishes a secure channel to share the symmetric key ki. Application i encrypts ki and the unique identifier IDi and sends them to the SQLite engine. The SQLite engine stores them in a key map (in computer science, this typically refers to a mapping relationship that associates keyboard keys with specific functions, commands, or operations. For example, in some software, users can customize key mappings, setting a key to perform a specific task, such as mapping "Ctrl + S" to the save file operation). This completes the binding of the key to the identity of application i.
[0036] 2. Execution Phase SQL request encryption and transmission: Application i encrypts the Sj to be executed and the generated random number Nj into an encrypted file using ki. Additional authentication tags Tsj and IDi, in the form of: Send to SQLite Enclave; SQLite Enclave Decryption and Execution: Page read: The SQLite Enclave looks up ki in the key map based on IDi and then reads the encrypted file. Decryption is performed to obtain decrypted information (Sj and Nj). After decryption, a query is performed based on Sj in the decrypted information to obtain the query result of page p. At this time, page p is in an encrypted state, represented as Eki(p). Page p is parsed to obtain the first page hash value NOp, the tag Tp, and the first encrypted page Eki(p). The SQLite storage module reads Eki(p) through NOp, the SQLite Enclave obtains Eki(p), and verifies the integrity of tag Tp by combining the hash tree, and decrypts it into page p. Page update: Execute Sj on page p to obtain the second page (query result Rj, page p', Tp'); if page p' is not equal to page p, update NOp→Tp to NOp'→Tp' in the tag mapping, and re-encrypt, update Eki(p) to Eki(p'), update the hash tree and synchronize the root hash value.
[0037] 3. Results returned The SQLite Enclave encrypts the query results Rj and Nj from the second page and returns them to application i. Application i verifies the consistency of Nj to defend against replay attacks. Specifically, it sends a... Application i Decrypt to obtain Rj and Nj. If Nj remains unchanged, accept Rj.
[0038] When the system executes the above process, it also includes: 4. Page Tag Authentication Protocol Hash tree construction: Each leaf node stores the hash value of the page tag Φp = hash(<NOp,Tp> The internal nodes are calculated level by level through the hashes of their child nodes, and the final root hash Φ(R) is stored in the SQLite Enclave.
[0039] Dynamic verification process: When reading the page, the untrusted environment provides encrypted data Eki(p), tag Tp, leaf hash Φp, and verification path μp. SQLite Enclave calculates the function value λ(Φp,μp) using chained hashing. If the result of the function value λ(Φp,μp) matches Φ(R), the tag is valid.
[0040] 5. Encryption and Key Management Authentication encryption algorithm: AES-128 GCM mode is adopted. During encryption, ciphertext Cp and tag Tp are generated. During decryption, the tag is verified to ensure that the data has not been tampered with.
[0041] Key persistence: When SQLite Enclave exits, it encrypts and stores the Key Map and root hash using SGX sealing technology, and unseales and loads them upon restart.
[0042] This system separates the execution phase: the overhead of the initialization and destruction phases only needs to be done once, and the actual query time accounts for 24% of the total time, compared to 79% for traditional encrypted SQLite. This system uses a hash tree for efficient verification: the verification path length is O(log(n)), the computational complexity is controllable, and it is suitable for large-scale data.
[0043] This application utilizes the Intel SGX Trusted Execution Environment to ensure that the data processing always runs in plaintext within a protected enclave. Combined with the AES-GCM authentication and encryption mechanism, it provides dual security guarantees for the blockchain system in terms of confidentiality and integrity, preventing malicious access and data tampering.
[0044] This application adopts a page tag authentication protocol based on a hash (Merkle) tree, which stores the authentication tag hash value in an untrusted environment and retains only the root hash in the trusted area. When reading data, the tag is dynamically verified by verifying the path, which significantly reduces storage overhead and improves the efficiency of integrity verification.
[0045] This application implements a multi-application shared database engine, which assigns an independent key to each application through a key mapping table to achieve access isolation and permission control, is compatible with standard SQL syntax, and is deployed on a mainstream SGX hardware platform, taking into account both system security and operating performance.
[0046] This application also provides a database management method based on a trusted execution environment and authentication encryption, including: S1. The application host establishes a secure channel with the SQLite database extension module based on any of its target applications, generates an encrypted file, and sends the encrypted file to the SQLite database extension module. The application host and the SQLite database extension module are set in a trusted environment. S2. The SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes the page query results based on the decryption information; S3. The SQLite database extension module parses the page query result to obtain the first page hash value, tag, and first encrypted page corresponding to the page query result; S4. The database host is communicatively connected to the SQLite database extension module for reading the first encrypted page based on the hash value of the first page, wherein the database host is set up in an untrusted environment; S5. The SQLite database extension module decrypts the first encrypted page to obtain the first page. On the first page, a query statement is executed based on the decrypted information to obtain the query result and the second page. It is determined whether the second page and the first page are the same. If the second page and the first page are not the same, update information is sent to the database. S6. The database host updates the first encrypted page to the second encrypted page based on the update information, and returns the second encrypted page as the encrypted query result to the SQLite database extension module; S7. The SQLite database extension module returns the encrypted query results to the application host. S8. The application host decrypts the encrypted query result and verifies the decrypted encrypted query result. If the decrypted encrypted query result meets the preset conditions, the decrypted encrypted query result is accepted.
[0047] In one embodiment, the step of establishing a secure channel between the application host and the SQLite database extension module includes: The application host is used to obtain the data key preset by the target application, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on the remote authentication protocol; If the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
[0048] In one embodiment, after the step of the application host establishing a secure channel with the SQLite database extension module based on any one of its target applications, the method further includes: The application host is also used to encrypt the symmetric key and the unique identifier to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module. The SQLite database extension module is used to complete the identity binding with the application host based on the encrypted identifier. The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module.
[0049] In one embodiment, the SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes the page query results based on the decryption information, including: The SQLite database extension module is used to find the symmetric key in the key mapping based on the unique identifier of the application host, and to decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
[0050] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0051] The above description is only a preferred embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural changes made based on the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A database management system based on a trusted execution environment and authentication encryption, characterized in that, include: The application host, the SQLite database extension module, and the database host are located in a trusted environment, while the database host is located in an untrusted environment. The application host is used to establish a secure channel with the SQLite database extension module based on any of its target applications, generate an encrypted file, and send the encrypted file to the SQLite database extension module; The SQLite database extension module is used to decrypt the encrypted file, obtain decryption information, and execute page query results based on the decryption information; The SQLite database extension module is also used to parse the page query results to obtain the first page hash value, tag, and first encrypted page corresponding to the page query results; The database host is communicatively connected to the SQLite database extension module and is used to read the first encrypted page based on the hash value of the first page; The SQLite database extension module is also used to decrypt the first encrypted page to obtain the first page; It is also used to execute a query statement on the first page based on the decrypted information to obtain the second page; It is also used to determine whether the second page and the first page are the same; If the second page is different from the first page, an update message is sent to the database. The database host is used to update the first encrypted page to the second encrypted page based on the update message, and return the second encrypted page as an encrypted query result to the SQLite database extension module. The SQLite database extension module is also used to encrypt the encrypted query results and return them to the application host; The application host is also used to decrypt the encrypted query result and verify the decrypted encrypted query result. If the decrypted encrypted query result meets the preset conditions, the host accepts the decrypted encrypted query result.
2. The database management system based on trusted execution environment and authentication encryption according to claim 1, characterized in that, The application host is used to obtain the data key preset by the target application, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on the remote authentication protocol; If the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
3. The database management system based on trusted execution environment and authentication encryption according to claim 2, characterized in that, The application host is also used to encrypt the symmetric key and the unique identifier to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module. The SQLite database extension module is used to complete the identity binding with the application host based on the encrypted identifier. The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module.
4. The database management system based on trusted execution environment and authentication encryption according to claim 1, characterized in that, The SQLite database extension module is used to find the symmetric key in the key mapping based on the unique identifier of the application host, and to decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
5. The database management system based on trusted execution environment and authentication encryption according to claim 1, characterized in that, The database host is used to construct a hash tree, wherein each leaf node of the hash tree stores the leaf hash value of the page tag, and the hash tree calculates the root hash level by level through the child node hashes, and sends the root hash to the SQLite database extension module for storage; When the database host reads the first encrypted page based on the hash value of the first page, the database host provides the SQLite database extension module with the encrypted data, tags, leaf hash values and verification path corresponding to the first encrypted page; The SQLite database extension module calculates the function value of the first encrypted page based on encrypted data, tags, leaf hash values, verification paths, and the chain hash calculation principle, and determines whether the function value is consistent with the root hash. If they are consistent, the tag corresponding to the first encrypted page is valid.
6. The database management system based on trusted execution environment and authentication encryption according to claim 1, characterized in that, The application host and the SQLite database extension module use the AES-128 GCM mode authentication encryption algorithm; When the SQLite database extension module stops running, it encrypts and stores its own data based on SGX sealing technology, and unencrypts and loads it upon restart.
7. A database management method based on a trusted execution environment and authentication encryption, characterized in that, include: The application host establishes a secure channel with the SQLite database extension module based on any of its target applications, generates an encrypted file, and sends the encrypted file to the SQLite database extension module. The application host and the SQLite database extension module are set in a trusted environment. The SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes page query results based on the decryption information; The SQLite database extension module parses the page query results to obtain the first page hash value, tag, and first encrypted page corresponding to the page query results; The database host is communicatively connected to the SQLite database extension module and is used to read the first encrypted page based on the hash value of the first page, wherein the database host is set in an untrusted environment; The SQLite database extension module decrypts the first encrypted page to obtain the first page, executes a query statement on the first page based on the decrypted information to obtain the second page, and determines whether the second page is the same as the first page. If the second page is not the same as the first page, it sends update information to the database. The database host updates the first encrypted page to the second encrypted page based on the update information, and returns the second encrypted page as the encrypted query result to the SQLite database extension module; The SQLite database extension module returns the encrypted query results to the application host; The application host decrypts the encrypted query result and verifies it. If the decrypted encrypted query result meets the preset conditions, it accepts the decrypted encrypted query result.
8. A database management method based on a trusted execution environment and authentication encryption according to claim 7, characterized in that, The steps for establishing a secure channel between the application host and the SQLite database extension module include: The application host is used to obtain the data key preset by the target application, generate a symmetric key based on the data key, and verify the integrity of the SQLite database extension module based on the remote authentication protocol; If the SQLite database extension module is complete, a secure channel is established with the SQLite database extension module to share the symmetric key.
9. The database management method based on trusted execution environment and authentication encryption according to claim 8, characterized in that, After the step of establishing a secure channel between the application host and the SQLite database extension module based on any one of its target applications, the method further includes: The application host is also used to encrypt the symmetric key and the unique identifier to obtain an encrypted identifier, and send the encrypted identifier to the SQLite database extension module. The SQLite database extension module is used to complete the identity binding with the application host based on the encrypted identifier. The application host is also used to obtain the target query statement, random number and authentication tag, and encrypt the target query statement, random number and authentication tag based on the symmetric key to obtain an encrypted file; The application host is also used to send the encrypted file to the SQLite database extension module.
10. The database management method based on trusted execution environment and authentication encryption according to claim 7, characterized in that, The SQLite database extension module decrypts the encrypted file to obtain decryption information, and executes the page query results based on the decryption information, including: The SQLite database extension module is used to find the symmetric key in the key mapping based on the unique identifier of the application host, and to decrypt the encrypted file based on the symmetric key to obtain decryption information, wherein the decryption information includes the target query statement and a random number; The SQLite database extension module is also used to execute page query results based on the target query statement.
Citation Information
Patent Citations
Non-interactive public verifiable symmetric searchable encryption method with forward and backward security
CN118761085A
RFID bidirectional authentication method based on asymmetric key and HASH function
WO2014201585A1