Data labeling method and system combined with zero terminal and TEE, storage medium and product
The data annotation system, which combines zero terminals with TEE trusted computing nodes, solves the problems of terminal leakage and cloud theft during the data annotation process, and achieves data security, efficiency improvement and traceability, while ensuring the security of privacy-sensitive information.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
- Filing Date
- 2026-01-16
- Publication Date
- 2026-05-01
AI Technical Summary
Existing data labeling methods pose risks of data leakage from terminal devices and data theft from the cloud, and cannot effectively protect the security of privacy-sensitive information.
The data annotation system adopts a combination of zero-terminal and TEE trusted computing nodes. A trusted connection is established through two-way verification. Data annotation is carried out within the TEE trusted computing node to ensure that data is operated and transmitted in a hardware-level isolated environment. The data management platform in the TEE trusted computing node is used for encrypted storage and decryption, and operation logs are recorded for anomaly monitoring.
It enables data leakage to be avoided from the source during the data annotation process, reduces hardware costs, improves work efficiency, ensures data security and traceability, and prevents data theft and tampering.
Smart Images

Figure CN121547288B_ABST
Abstract
Description
Data labeling methods, systems, storage media, and products combining zero terminals and TEE Technical Field
[0001] This application relates to the field of data security technology, and in particular to a data annotation method, system, storage medium and product that combines zero terminal and TEE. Background Technology
[0002] With the rapid development of artificial intelligence technology, high-quality labeled data has become the core foundation for AI model training, especially in fields such as medical image diagnosis and intelligent financial risk control, where labeled data contains a large amount of privacy-sensitive information. Current data labeling mainly employs the following two methods:
[0003] 1. Local Terminal Annotation Mode: Data annotators obtain the data to be annotated through local terminals such as personal computers and mobile devices. After the data is stored on the local device, the annotation operation is carried out, and the results are sent back to the data management platform. In this mode, the data to be annotated needs to be downloaded and stored on the local terminal. However, the terminal device is vulnerable to malicious software intrusion, physical theft, or unauthorized copying, which may lead to the leakage of private data.
[0004] 2. Cloud Terminal Annotation Mode: The annotation environment is provided by a cloud server. Data annotators access the cloud server via remote desktop or other means to perform annotations, and the data to be annotated is stored on the cloud server. Although this mode can centrally manage the data to be annotated using the cloud server, there are risks of unauthorized access by cloud administrators and data theft through external network attacks; moreover, when data annotators access the cloud terminal through a regular network, the data is easily intercepted during transmission.
[0005] Therefore, existing technologies still need to be improved and enhanced. Summary of the Invention
[0006] The technical problem to be solved by this application is to provide a data annotation method, system, storage medium and product that combines zero terminal and TEE, in order to address the shortcomings of the existing technology.
[0007] To address the aforementioned technical problems, the first aspect of this application provides a data annotation system combining zero terminals and TEE, wherein the data annotation system combining zero terminals and TEE includes a zero terminal and a TEE trusted computing node, and the zero terminal and the TEE trusted computing node establish a trusted connection and perform encrypted communication through bidirectional verification;
[0008] The zero terminal is used to display the data annotation interface provided by the TEE trusted computing node and send data annotation instructions to the TEE trusted computing node;
[0009] The TEE trusted computing node is used to schedule trusted applications deployed on the TEE trusted computing node itself for the zero terminal, and to operate on the data to be labeled through the trusted applications according to the data labeling instructions. The data to be labeled is decrypted by the data management platform in the TEE trusted computing node and transmitted to the trusted application.
[0010] The data annotation system combining zero terminal and TEE, wherein the TEE trusted computing node includes a data management platform and a trusted application, and the trusted application is communicatively connected to the data management platform;
[0011] The data management platform is used to store encrypted data blocks obtained by encrypting the original data provided by the data provider, and to transmit the original data to the trusted application based on data annotation instructions. The encrypted data blocks are associated with authorization information, which is used to constrain the data annotation party of the original data.
[0012] The trusted application is used to operate on the raw data based on the data annotation instructions.
[0013] The data annotation system combining zero terminal and TEE, wherein the TEE trusted computing node further includes several virtual machines, each of which is connected to the trusted application;
[0014] The virtual machine is used to build a communication bridge between the zero terminal and the trusted application, so as to enable the zero terminal to transmit data annotation instructions to the trusted application, and the trusted application to synchronize the data annotation interface to the zero terminal. When multiple zero terminals communicate with the TEE trusted computing node, each zero terminal corresponds to one virtual machine.
[0015] The data annotation system combining zero terminal and TEE, wherein the data management platform includes an environment verification module, a data management module, and a task management module;
[0016] The environment verification module is used to perform hardware root of trust verification on the zero terminal based on the first identity credential provided by the zero terminal, and to initiate remote verification to the zero terminal so that the zero terminal can remotely verify the TEE trusted computing node; and to perform hardware root of trust verification on the data provider based on the second identity credential provided by the data provider, and to initiate remote verification to the data provider so that the data provider can remotely verify the TEE trusted computing node.
[0017] The data management module is used to encrypt the original data provided by the data provider and associate authorization information with the encrypted data blocks obtained after encryption.
[0018] The task management module is used to decrypt the encrypted data block and transmit the decrypted raw data to the trusted application.
[0019] The data annotation system combining zero terminal and TEE, wherein the data management platform further includes a log auditing module;
[0020] The log auditing module is used to record the operation log of the entire operation process of the data annotation instruction, and to perform anomaly monitoring on the entire operation process of the data annotation instruction based on the operation log.
[0021] The data annotation system combining zero terminal and TEE, wherein the trusted application is also used to send the result data formed in response to the data annotation instruction back to the data management platform in the trusted computing node of the TEE;
[0022] The data management platform is also used to encrypt the result data to obtain an encrypted result data packet, perform dual verification on the encrypted result data packet, and associate and store the encrypted result data packet with its corresponding encrypted data block after the dual verification passes. The dual verification includes integrity verification based on the operation integrity check code of the encrypted result data packet and legality verification based on the authorization information of the zero terminal and the authorization information of the encrypted result data.
[0023] The data annotation system combining zero terminal and TEE, wherein the zero terminal is not configured with a local storage unit and a local computing unit.
[0024] A second aspect of this application provides a data annotation method combining zero-terminal and TEE, applying the data annotation system combining zero-terminal and TEE as described above, the method comprising:
[0025] After bidirectional verification, the TEE trusted computing node and the zero terminal establish a trusted connection and display the data annotation interface provided by the TEE trusted computing node.
[0026] The TEE trusted computing node schedules the trusted applications configured for the zero terminal;
[0027] The TEE trusted computing node obtains raw data from the data management platform in the TEE trusted computing node through the trusted application. The raw data is obtained by the data management platform decrypting the encrypted data block corresponding to the data annotation instruction.
[0028] The TEE trusted computing node receives data annotation instructions sent by the zero terminal and operates on the original data block according to the data annotation instructions through the trusted application in response to the data annotation instructions.
[0029] A third aspect of this application provides a storage medium, which is a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the data annotation method combining zero terminal and TEE as described above.
[0030] The fourth aspect of this application provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the data annotation method combining zero terminal and TEE as described above.
[0031] Beneficial effects:
[0032] 1. This application combines zero-terminal access with TEE trusted computing nodes. Data annotators access the TEE trusted computing nodes through zero-terminal access for data annotation. The data to be annotated is not stored on the terminal side, thus preventing data leakage caused by data annotators from the source. At the same time, the quick access to the TEE trusted computing nodes by data annotators using zero-terminal access reduces the hardware cost of the annotation equipment used by data annotators and shortens the time from access to starting data processing, thereby improving overall work efficiency.
[0033] 2. This application achieves hardware-level isolation through TEE trusted computing nodes, ensuring that data remains within the TEE trusted environment provided by the TEE trusted computing node throughout the entire process of transmission, computation and operation, effectively preventing data from being stolen or tampered with, and ensuring data security.
[0034] 3. This application utilizes the data management platform within the TEE trusted computing node to complete two-way verification and establish a trusted connection with both the zero terminal and the data provider. This process verifies the identity and hardware trustworthiness of both the zero terminal and the data labeler, while also ensuring the integrity and trustworthiness of the TEE trusted computing node, effectively mitigating the risk of forging a TEE environment and thus further enhancing data security.
[0035] 4. This application records the entire process operation log of the data annotation instruction through the data management platform in the TEE trusted computing node, so as to carry out anomaly monitoring based on the operation log and ensure the traceability and access controllability of the data annotation. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 is a schematic diagram of the data annotation system combining zero terminal and TEE provided in the embodiment of this application.
[0038] Figure 2 is an exemplary principle block diagram of a data annotation system combining zero terminal and TEE provided in an embodiment of this application.
[0039] Figure 3 is a block diagram of the zero-terminal principle.
[0040] Figure 4 is a block diagram of the TEE trusted computing node.
[0041] Figure 5 is a schematic diagram of the workflow of the data annotation system combining zero terminal and TEE provided in the embodiment of this application.
[0042] Figure 6 is a flowchart of the data annotation method combining zero terminal and TEE provided in the embodiments of this application. Detailed Implementation
[0043] This application provides a data annotation method, system, storage medium, and product combining zero terminal and TEE. To make the objectives, technical solutions, and effects of this application clearer, the following will provide a more detailed description of this application in conjunction with the accompanying drawings and examples. It should be noted that the specific embodiments described herein are only for explaining this application and are not intended to limit it.
[0044] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further clarified that the term “comprising” as used in this specification indicates the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or combinations thereof. It should be understood that when an element is referred to as being “connected” or “coupled” to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, the term “connected” or “coupled” as used herein encompasses wireless connection and wireless coupling. The term “and / or” as used herein includes all, any, and all combinations of one or more of the associated listed items.
[0045] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to be consistent with their meaning in the prior art context and should not be interpreted in an idealized or overly formal sense unless specifically defined herein.
[0046] It should be understood that the sequence number and size of each step in this embodiment do not represent the order of execution. The execution order of each process is determined by its function and internal logic, and should not constitute any limitation on the implementation process of this application embodiment.
[0047] Research has revealed that with the rapid development of artificial intelligence technology, high-quality labeled data has become a core foundation for AI model training, especially in fields such as medical image diagnosis and intelligent financial risk control, where labeled data contains a large amount of privacy-sensitive information. Current data labeling primarily employs the following two methods:
[0048] 1. Local Terminal Annotation Mode: Data annotators obtain the data to be annotated through local terminals such as personal computers and mobile devices, download and store the data on their local devices, perform annotation operations, and then send the results back to the data management platform. In this mode, the data to be annotated must be stored on the local terminal, which is vulnerable to malware intrusion, physical theft, or unauthorized copying, potentially leading to the risk of privacy data leakage.
[0049] 2. Cloud Terminal Annotation Mode: The annotation environment is provided by a cloud server. Data annotators access the cloud server via remote desktop or other means to perform annotations, and the data to be annotated is stored on the cloud server. Although this mode can achieve centralized management of the data to be annotated by leveraging the cloud server, there are risks of unauthorized access by cloud administrators and data theft through external network attacks; moreover, when data annotators access the cloud terminal through a regular network, the data is easily intercepted during transmission.
[0050] Based on this, this application provides a data annotation system combining a zero-terminal and a TEE (Trusted Execution Environment). The system includes a zero-terminal and a TEE trusted computing node. The zero-terminal and the TEE trusted computing node establish a trusted connection through bidirectional authentication and perform encrypted communication. The zero-terminal displays the data annotation interface provided by the TEE trusted computing node and sends data annotation instructions to it. Based on the data annotation instructions, the TEE trusted computing node schedules trusted applications deployed on the node for the zero-terminal and annotates data through these applications. The original data is decrypted by the data management platform within the TEE trusted computing node and then transmitted to the trusted application.
[0051] This application combines zero-terminal access with TEE trusted computing nodes. Data annotators connect to the TEE trusted computing nodes through zero-terminal access to conduct data annotation, ensuring that the data to be annotated is not stored on the terminal side, thus avoiding the risk of data leakage caused by terminal devices from the source. At the same time, data annotators can quickly access the TEE trusted computing nodes with the help of zero-terminal access, which not only reduces the hardware cost of the annotation equipment used by data annotators, but also shortens the time from access to starting data processing, effectively improving overall work efficiency.
[0052] The application content will be further explained below with reference to the accompanying drawings and through the description of the embodiments.
[0053] This embodiment provides a data annotation system combining zero-terminal and TEE, as shown in Figures 1 and 2. The system includes a zero-terminal 100 and a TEE trusted computing node 200. The zero-terminal 100 can connect to the TEE trusted computing node 200 after bidirectional authentication. The zero-terminal 100 is an electronic device without local storage or its own computing unit, such as a thin client or network computer. During data annotation, the zero-terminal 100 does not have the ability to store or process data; all data storage and computing tasks are handled by the TEE trusted computing node 200. The TEE trusted computing node 200 provides a hardware-isolated trusted execution environment; for example, it may be built based on Intel SGX, ARM TrustZone, or SPU. The TEE trusted computing node 200 is the core processing unit of the zero-terminal and TEE combined data annotation system, responsible for storing and processing data during the annotation process.
[0054] It is understandable that, since the zero terminal 100 lacks local storage and computing units, it needs to remotely connect to the TEE trusted computing node during the data annotation process. After connecting to the TEE trusted computing node, the zero terminal 100 sends remote commands to the TEE trusted computing node 200, causing the TEE trusted computing node 200 to execute the corresponding operation. Therefore, in the data annotation system combining the zero terminal and TEE, the zero terminal 100 is used to send data annotation commands to the TEE trusted computing node 200, causing the TEE trusted computing node 200 to execute the corresponding operation. Furthermore, since the data to be annotated cannot be stored on the zero terminal 100, but the data annotator needs to operate on the data through the zero terminal 100, after the zero terminal 100 connects to the TEE trusted computing node 200, the TEE trusted computing node 200 will send the data annotation interface to the zero terminal 100 via remote desktop. The zero terminal 100 will display this data annotation interface, and the data annotator will then execute data annotation through this interface, thereby generating data annotation commands. For this purpose, the zero terminal 100 is also used to display the data annotation interface provided by the TEE trusted computing node 200.
[0055] In one embodiment, as shown in Figure 3, the zero terminal 100 includes a remote display module, an authentication module, an operation instruction module, and a communication module. The authentication module is used for bidirectional authentication with the TEE trusted computing node. For example, when the zero terminal device connects to the TEE trusted computing node, it sends an operation access request to the TEE trusted computing node in encrypted form through the communication module. This operation access request includes a first identity credential, which may include a hardware trusted identifier (such as the zero terminal's device identifier), the operator's identity information, and operation permission information. Simultaneously, the authentication module also initiates remote authentication of the TEE trusted computing node based on the remote proof sent by the TEE trusted computing node (such as remote authentication with a remote authentication server using the remote proof), to verify the integrity and trusted status of the TEE trusted computing node.
[0056] The remote display module is used to display the data annotation interface provided by the TEE trusted computing node. For example, the zero terminal can synchronize the annotation tool interface (such as LabelImg, Medical Imaging Labeler, etc.) within the trusted application in the TEE trusted computing node in real time through the remote display module. The interface data of the data annotation interface is compressed and encrypted before transmission, which ensures smooth display and improves the security of interface data transmission.
[0057] The operation instruction module is used to send data annotation instructions to the TEE trusted computing node. These data annotation instructions are sent to the TEE trusted computing node in encrypted form via the communication module. Furthermore, the operation instruction module is also used to receive data annotation instructions, which can be generated by the operator using a peripheral device connected via a zero-terminal connection, or sent by an external device, etc.
[0058] The communication module is used to communicate with the TEE trusted computing node. It transmits data annotation instructions to the TEE trusted computing node and receives the data annotation interface provided by the TEE trusted computing node.
[0059] Furthermore, to facilitate data annotation tasks performed by data annotators via the zero-terminal, the zero-terminal can also connect to peripheral devices such as keyboards, mice, and monitors. Operators can remotely manipulate the data stored in the TEE trusted computing node using these peripheral devices. Specifically, operators can use external input devices such as keyboards, mice, and touchpads to annotate the raw data displayed in the data annotation interface. Data annotation includes, but is not limited to, bounding box selection, classification, and semantic segmentation operations. The zero-terminal will respond instantly to the data annotator's interactive behavior and automatically generate corresponding data annotation instructions, thereby achieving effective annotation of the raw data. For example, if the zero-terminal receives a bounding box selection operation from the data annotator via a peripheral device, the zero-terminal will generate a bounding box selection instruction based on this operation, and then send the bounding box selection instruction in encrypted form to the TEE trusted computing node through the communication module. The TEE trusted computing node will then respond to the bounding box selection instruction by annotating the data to be annotated with a detection bounding box.
[0060] It should be noted that the zero terminal is not equipped with a local storage unit or a local computing unit. Thus, the zero terminal displays the original data by decrypting it through data annotation, but it does not store any original data, result data, or interface cache data, or any other data used or generated during the data annotation process. This achieves zero data storage for the zero terminal, thus preventing data leakage caused by the zero terminal from the source.
[0061] Furthermore, the zero terminal sends a data annotation instruction to the TEE trusted computing node, prompting the TEE trusted computing node to execute the data annotation instruction on the data to be annotated. For example, if the data annotation instruction is to annotate data A, and this data annotation instruction contains annotation information B for data A, then after receiving the data annotation instruction, the TEE trusted computing node will annotate the data A with the annotation information B contained in the data annotation instruction. To this end, the TEE trusted computing node receives the data annotation instruction sent by the zero terminal and operates on the data to be annotated based on the data annotation instruction. This data to be annotated is stored in the data management platform within the TEE trusted computing node.
[0062] Furthermore, to further enhance data security, this application implements hardware-level data isolation within the TEE trusted computing node, separating data storage from data annotation. Specifically, the TEE trusted computing node deploys a data management platform and trusted applications. The data management platform stores data, while the trusted applications perform data annotation. The data management platform communicates with the trusted applications and provides them with data to be annotated when they respond to data annotation requests. In other words, when a zero-terminal accesses the TEE trusted computing node, the node assigns a trusted application and provides it with data to be annotated. The trusted application then receives and responds to data annotation instructions sent by the zero-terminal to perform data annotation. Therefore, in the data annotation system combining zero-terminals and TEE, the TEE trusted computing node schedules its own deployed trusted applications for the zero-terminal and operates on the data to be annotated through these applications. The encrypted data stored in the data management platform within the TEE trusted computing node is decrypted and transmitted to the trusted application.
[0063] It should be noted that, in order to further improve data security, the zero terminal and the TEE trusted computing node establish an encrypted communication channel. For example, the zero terminal and the TEE trusted computing node negotiate session keys based on the TLS protocol to build an end-to-end encrypted communication channel, ensuring the confidentiality and tamper resistance of the transmission link.
[0064] This embodiment of the application utilizes a zero-terminal and a TEE trusted computing node in conjunction. The trusted application allocated to the zero-terminal within the TEE trusted computing node provides the decrypted data to be labeled. This data is encrypted and stored by the data management platform. The zero-terminal then receives data labeling instructions from the operator and sends these instructions to the TEE trusted computing node. Finally, the trusted application responds to the data labeling instructions to perform data labeling on the data to be labeled. This not only prevents data from being stored locally on the zero-terminal side, thus avoiding data leakage caused by the zero-terminal, but also provides hardware-level isolation at the TEE level through the data management platform, ensuring data security throughout the entire operation process and preventing data theft or tampering, thereby maximizing data security.
[0065] In one embodiment, as shown in Figures 2 and 4, the TEE trusted computing node 200 includes a data management platform and a trusted application, with the trusted application communicatively connected to the data management platform. The trusted application is an application program or operating platform used to perform data annotation. The trusted application is used to operate on the raw data based on the data annotation instructions. That is, the trusted application receives data annotation instructions sent by the zero terminal, then obtains the data to be annotated (the raw data in an unencrypted state) corresponding to the data annotation instruction from the data management platform, executes the data annotation instruction on the data to be annotated to obtain result data, and transmits the result data to the data management platform. For example, in a data annotation scenario, the trusted application determines the annotation tool to execute the annotation operation corresponding to the data annotation instruction (such as bounding box operation, classification operation, semantic segmentation operation, etc.) based on the data annotation instruction, and forms annotation result data. This ensures that the annotation trajectory, intermediate results, and final annotation results formed during the annotation process all flow within the TEE trusted computing node.
[0066] Furthermore, to prevent data leakage due to data annotation by trusted applications, the trusted applications within the TEE trusted computing node have independent resource isolation and access control mechanisms. Each trusted application prohibits other trusted applications or processes from accessing its internal data and runtime status. Simultaneously, to ensure the independence of operations between zero terminals, as shown in Figure 2, the TEE trusted computing node can also deploy several virtual machines, each connected to a trusted application. These virtual machines serve as communication bridges between the zero terminals and the trusted applications, enabling the zero terminals to transmit data annotation instructions to the trusted applications and the trusted applications to synchronize the data annotation interface with the zero terminals. Moreover, when multiple zero terminals communicate with the TEE trusted computing node, each zero terminal corresponds to one virtual machine, ensuring that data interaction and operations between different zero terminals and the TEE trusted computing node do not interfere with each other. This guarantees the independence and security of each zero terminal's operation; even if multiple zero terminals communicate with the TEE trusted computing node simultaneously, there will be no data confusion or mutual interference. Furthermore, since each virtual machine is connected to a trusted application, it can perform preliminary screening and verification of data annotation instructions on zero terminals, filtering out potentially risky or invalid instructions, thus further enhancing the security and stability of the entire system. In addition, when a zero terminal experiences an anomaly, it only affects the corresponding virtual machine and does not interfere with the normal operation of other zero terminals or the entire TEE trusted computing node, ensuring high availability and reliability of the system.
[0067] It should be noted that after the zero terminal operates on the data to be labeled through the trusted application, corresponding result data is generated, and the trusted application sends this result data back to the data management platform. Therefore, the trusted application is also used to send the result data generated in response to the data labeling instruction back to the data management platform in the TEE trusted computing node. Of course, the trusted application does not store the data to be labeled, the corresponding result data, or any intermediate data generated by operating on the data to be labeled.
[0068] The data management platform stores encrypted data blocks, which are obtained by encrypting the original data provided by the data provider. The platform also associates authorization information with this encrypted database, which constrains the data labelers of the original data. Simultaneously, the platform provides labeled data to trusted applications. This labeled data is obtained by decrypting the stored encrypted data blocks, meaning it is the unencrypted original data. Therefore, data is stored in encrypted form within the data management platform. When data needs to be manipulated, the platform decrypts the encrypted data blocks and transmits them to the trusted application. The trusted application then operates on this original data (the labeled data corresponding to the data labeling instructions) within a TEE hardware isolation environment. This ensures that both the encryption / decryption process and the labeling process are completed within the TEE hardware isolation environment, guaranteeing that the original data is not leaked outside the TEE.
[0069] In one embodiment, the data management platform includes an environment verification module, a data management module, and a task management module.
[0070] The environment verification module works in conjunction with the zero terminal to perform hardware root of trust verification on the zero terminal based on the first identity credential provided by the zero terminal, and initiates remote authentication to enable the zero terminal to remotely verify the TEE trusted computing node. Simultaneously, the environment verification module also works in conjunction with the data provider to perform hardware root of trust verification on the data provider based on the second identity credential provided by the data provider, and initiates remote authentication to enable the data provider to remotely verify the TEE trusted computing node.
[0071] It is understandable that the environment verification module works in conjunction with the zero terminal to achieve bidirectional verification between the TEE trusted computing node and the zero terminal, and also works with the data provider to achieve bidirectional verification between the TEE trusted computing node and the data provider.
[0072] As shown in Figure 5, the verification process for bidirectional verification between the TEE trusted computing node and the zero terminal is as follows:
[0073] First, the zero terminal initiates a data labeling access request to the TEE trusted computing node. The data labeling access request includes a first identity credential automatically generated by the zero terminal. This first identity credential may include the zero terminal's device identifier, the operator's identity information, and operation permission information, etc.
[0074] Secondly, the zero terminal initiates remote verification to the TEE trusted computing node. The TEE trusted computing node provides remote proof to the zero terminal through the environment verification module, so that the zero terminal can verify the TEE trusted computing node through the remote verification server based on the remote proof.
[0075] Furthermore, the TEE trusted computing node uses the environment verification module to authenticate the zero terminal based on the first identity credential, for example, to determine the legitimacy of the operator's identity, the legitimacy of the zero terminal's device, and the data access permissions that the operator has.
[0076] Finally, when both authentication and remote authentication pass, the TEE trusted computing node authorizes the zero terminal to access the TEE trusted computing node and establishes a stable and trusted connection with the zero terminal through encrypted communication. If authentication and / or remote authentication fail, the TEE trusted computing node rejects the data labeling access request and records an abnormal access log, which may include the device identifier, timestamp, and reason for failure.
[0077] As shown in Figure 5, the verification process for two-way verification between the TEE trusted computing node and the data provider is as follows:
[0078] First, the data provider initiates a data upload request, which includes a second identity credential, which may include the data provider's organizational identifier, digital certificate, and hardware root of trust information, etc.
[0079] Secondly, the data provider initiates remote verification to the TEE trusted computing node. The TEE trusted computing node provides remote proof to the zero terminal through the environment verification module, so that the zero terminal can verify the TEE trusted computing node through the remote verification server based on the remote proof.
[0080] Secondly, the TEE trusted computing node verifies the identity of the data provider based on the second identity credential to verify the legitimacy of the data provider;
[0081] Finally, when both authentication and remote authentication are successful, the data provider of the TEE trusted computing node initiates a data upload request and negotiates a session key based on the TLS protocol, establishing an end-to-end encrypted communication channel between the data provider and the TEE trusted computing node to ensure the confidentiality and tamper resistance of the transmission link.
[0082] The data management module manages the raw data provided by the data provider. Specifically, after the data provider uploads the raw data, the data management module encrypts the raw data to obtain encrypted data blocks. Simultaneously, after obtaining the encrypted data blocks, it associates authorization information with the encrypted database to constrain the objects that operate on the raw data. In other words, the data management module encrypts the raw data provided by the data provider and associates authorization information with the resulting encrypted data blocks.
[0083] It is understandable that data providers upload raw data (such as medical images, financial data, etc.) to the data management platform through an established encrypted communication channel. The data management module then encrypts this raw data (e.g., using the SM4 algorithm for hardware-level encryption) to generate encrypted data blocks, which are stored in a pre-configured encrypted database located within a TEE trusted environment. Furthermore, data providers can authorize the raw data through the data management module. This authorization information can include operator identification, scope of operation (e.g., read-only operation, specific type of operation), permission validity period, task priority, etc. The data management module associates this authorization information with the encrypted data blocks. For example, when generating encrypted data blocks, a unique identifier is configured for the encrypted database, and then the authorization information is associated with this unique identifier to form a granular access control system.
[0084] It should be noted that, since the encrypted data block is associated with authorization information, after receiving a data annotation instruction, the trusted application will verify the instruction based on the authorization information associated with the encrypted data block. This verifies whether the zero-terminal associated with the instruction has the necessary permissions to operate on the original data corresponding to the encrypted data block. For example, it checks whether the identity information of the operator associated with the zero-terminal is included in the authorization information, whether the scope of the data annotation instruction is within the scope of the original data, and / or whether the original data's permissions have expired. This further ensures the legality and security of data annotation, preventing unauthorized operations from damaging or leaking the data. Only when the verification passes will the trusted application retrieve the corresponding data to be annotated from the data management platform and execute the operation; if the verification fails, the trusted application will refuse to execute the data annotation instruction and record an abnormal operation log, which may include the zero-terminal identifier, the content of the operation instruction, a timestamp, and the reason for the failed verification.
[0085] The task management module manages the operation tasks corresponding to the data annotation instructions sent by the zero terminal. Specifically, the task management module decrypts the encrypted data block and transmits the decrypted raw data to the trusted application. The task management module can use a preset shared key (stored in a TEE secure area in pair with the data encryption key) to decrypt the encrypted data block corresponding to the data annotation instruction to obtain the raw data. This raw data is then transmitted to the trusted application as the data to be annotated corresponding to the data annotation instruction, enabling the data annotation corresponding to the data to be annotated to be performed on the data to be annotated.
[0086] Furthermore, since the encrypted data blocks carry authorization information, and the zero terminal, after connecting to the TEE trusted computing node, sends capability information to the TEE trusted computing node, this capability information may include the identity information of the data labeler accessing the zero terminal device, and one or more of the data labeler's authorization scope. Therefore, the task management module is also used to allocate zero terminals to the original data corresponding to the encrypted data blocks based on the authorization information and capability information. Specifically, the task management module will filter out encrypted data blocks that meet the authorization scope of the data labeler from the original data to be operated on, and assign the operation tasks corresponding to the filtered encrypted data blocks to the zero terminal, so that the operation tasks can operate on the original data of the filtered encrypted data blocks through the zero terminal. For example, when the authorization scope of the accessed zero terminal is only border labeling, the task management module will search for encrypted data blocks with the authorization scope of only border labeling in the authorization information of the encrypted data blocks to be labeled, then decrypt the found encrypted data blocks to obtain the data to be labeled, and provide the data to be labeled to the trusted application, so that the zero terminal can perform border labeling operations on the data to be labeled through the trusted application.
[0087] In addition, the task management module provides data to be labeled to the zero terminal according to task priority. Specifically, the task management module will sequentially select encrypted data blocks that meet the authorized scope from the raw data to be operated on, decrypt them, and transmit the decrypted raw data as data to be labeled to the trusted application, so that the zero terminal can operate on the data to be labeled through the trusted application. For example, when there is an urgent data labeling task (i.e., a data labeling task with high priority), the task management module will prioritize decrypting the encrypted data blocks corresponding to the urgent data labeling task and transmit the decrypted raw data as data to be labeled to the trusted application. The trusted application displays the data to be labeled on the zero terminal through the labeling tool interface, and the data labeler can label the raw data corresponding to the urgent data labeling task through the zero terminal.
[0088] Furthermore, in addition to managing the raw data provided by the data provider, the data management platform also manages the result data formed based on data annotation instructions. That is, the data management platform is also used to encrypt the result data to obtain encrypted result data packets, perform double verification on the encrypted result data packets, and associate and store the encrypted result data packets with their corresponding encrypted data blocks after the double verification passes. The double verification includes integrity verification based on the operation integrity check code of the encrypted result data packets and legality verification based on the authorization information of the zero terminal and the authorization information of the encrypted result data.
[0089] Specifically, the data management module is used to encrypt the result data to obtain an encrypted result data packet. Specifically, the data management module receives the result data returned by the trusted application and encrypts the result data (e.g., using the SM2 algorithm) to generate an encrypted result data packet. The result data may include a unique identifier for the encrypted data block corresponding to the data to be labeled, the operation content, operator information, operation timestamp, operation integrity check code, etc.
[0090] The task management module performs dual verification on the encrypted result data packet and, after successful dual verification, associates and stores the encrypted result data packet with its corresponding encrypted data block. Specifically, the task management module performs integrity verification based on the operation integrity check code of the encrypted result data packet, as well as verification of the legality of the authorization information of the zero terminal and the authorization information of the encrypted result data. After both the integrity verification and hardware root of trust verification pass, the encrypted result data packet is stored in a preset result database, and associated with its corresponding encrypted data block. Furthermore, if the integrity verification and / or hardware root of trust verification fail, a retransmission mechanism can be triggered to send a retransmission request to the trusted application, and an exception will be recorded and an alarm will be issued after multiple failures.
[0091] Furthermore, in practical applications, to monitor the entire data annotation process, the data management platform may also include a log auditing module. This module records the entire operation log of the data annotation instructions and performs anomaly monitoring based on these logs. The operation logs are stored in encrypted form and may include data provider upload logs, two-way verification logs, encrypted data storage logs, data annotation provider access logs, task distribution logs, data decryption scheduling logs, annotation operation logs, and result feedback verification logs. Each operation log includes key fields such as timestamp, device identifier, user account, operation content, and data identifier ID.
[0092] Furthermore, after recording the entire operation log of the data annotation instructions, anomaly monitoring can be performed based on the recorded operation log. This includes monitoring for events such as unauthorized access, operation timeouts, abnormal data transmission rates, breaches of the TEE environment integrity, and abnormal disconnections of zero-terminal connections. Upon detecting an anomaly, emergency responses can be executed, such as terminating the current data annotation, disconnecting the zero-terminal from the TEE trusted computing node, and freezing relevant data annotation tasks and data access permissions to prevent further deterioration. Multi-level alarms can also be triggered (e.g., system pop-ups, email notifications, administrator SMS alerts), while simultaneously retaining anomaly logs for subsequent source tracing and analysis. This ensures that relevant personnel are promptly informed of anomalies for timely handling and provides crucial data support for in-depth analysis, helping to identify the root cause of the anomaly and implement targeted improvements, thereby continuously enhancing the security and reliability of the data management platform.
[0093] This application embodiment deploys a log auditing module in the data management platform. This module records the entire operation log of the data annotation instructions, providing traceable evidence for the entire data annotation process. Whether it's data uploading, verification, encrypted storage, or task distribution, each step is clearly presented in the logs, facilitating subsequent auditing and analysis. Furthermore, this application embodiment can also monitor for anomalies in the entire data annotation instruction operation process based on the operation logs. For example, unauthorized access may lead to data leakage, operation timeouts may affect system efficiency, abnormal data transmission rates may indicate network failures or malicious attacks, compromised TEE environment integrity may jeopardize the security of the entire system, and abnormal disconnection of zero-terminal connections may cause data annotation interruptions. This application embodiment can promptly detect and handle these anomalies through anomaly monitoring, effectively avoiding data loss and system failures, and ensuring the normal operation of the data management platform.
[0094] In summary, the data annotation system combining zero terminals and TEE provided in this embodiment has the following advantages compared with the prior art:
[0095] 1. This application embodiment uses a zero terminal as the operator's terminal, leveraging the fact that the zero terminal has no local storage or computing capabilities to prevent data from being stored on the zero terminal side, thus avoiding the risk of terminal leakage at the source. Then, the zero terminal is combined with a TEE trusted computing node, which provides TEE hardware-level isolation, ensuring that the data annotation process is not stolen or tampered with, reducing the data exposure surface.
[0096] 2. In this embodiment, operators can access the system using zero terminals without needing to configure high-performance local terminals, thus reducing the hardware cost of the operator's terminal. Simultaneously, multiple zero terminals can access the TEE trusted computing node. The TEE trusted computing node can independently manage each zero terminal and assign appropriate operational tasks based on its capabilities, achieving fine-grained task allocation and solving the problem of inconvenient access to TEE technology in distributed operation scenarios.
[0097] 3. This application embodiment achieves full traceability and compliance assurance by recording the entire operation log of the data annotation instructions. In particular, for data annotation scenarios, it enables full traceability of annotation operations, meets the compliance requirements for privacy data processing, and solves the problems of loose access control and difficulty in defining responsibilities in cloud annotation.
[0098] 4. This application's embodiments improve data transmission security by establishing end-to-end TLS encrypted transmission channels between the zero terminal and the TEE trusted computing node, and between the data provider and the TEE trusted computing node. Simultaneously, the efficient transmission of TLS and the efficient computing capabilities of the TEE trusted computing node reduce data annotation latency, avoiding the efficiency degradation caused by simple encryption.
[0099] Based on the data annotation system combining zero terminal and TEE provided in the above embodiments, this application embodiment provides a data annotation method combining zero terminal and TEE, as shown in Figure 6. The method includes:
[0100] S10, the TEE trusted computing node and the zero terminal establish a trusted connection after bidirectional verification, and display the data annotation interface provided by the TEE trusted computing node;
[0101] S20 and TEE trusted computing nodes are used by the zero terminal to schedule the trusted applications configured thereon.
[0102] S30. The TEE trusted computing node obtains raw data from the data management platform in the TEE trusted computing node through the trusted application. The raw data is obtained by the data management platform decrypting the encrypted data block corresponding to the data annotation instruction.
[0103] S40, the TEE trusted computing node receives data annotation instructions sent by the zero terminal, and operates on the original data block according to the data annotation instructions through the trusted application in response to the data annotation instructions.
[0104] Based on the above-described data annotation method combining zero terminal and TEE, this embodiment provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon. The computer-readable program instructions are used to execute the data annotation method combining zero terminal and TEE in the above embodiment.
[0105] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, and portable compact disk read-only memory (CD-ROM). ROM: CD Read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (Radio Frequency), etc., or any suitable combination thereof.
[0106] The aforementioned computer-readable storage medium may be included in an electronic device or may exist independently without being assembled into an electronic device.
[0107] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by an electronic device, a trusted connection is established with the zero terminal after bidirectional verification, and a data annotation interface provided by the TEE trusted computing node is displayed. The program schedules a trusted application configured for the zero terminal and obtains raw data from the data management platform in the TEE trusted computing node through the trusted application. It receives data annotation instructions sent by the zero terminal and operates on the raw data block according to the data annotation instructions through the trusted application in response to the data annotation instructions. The raw data is obtained by the data management platform decrypting the encrypted data block corresponding to the data annotation instructions.
[0108] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0109] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0110] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0111] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the data annotation method combining zero terminal and TEE described above, which can solve the technical problem of poor application performance. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the data annotation method combining zero terminal and TEE provided in the above embodiments, and will not be repeated here.
[0112] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the data annotation method combining zero terminal and TEE as described above.
[0113] The computer program product provided in this application can solve the technical problem of poor application performance. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the data annotation method combining zero terminal and TEE provided in the above embodiments, and will not be repeated here.
[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A data annotation system combining zero terminal and TEE, characterized in that, The data annotation system combining zero terminal and TEE includes a zero terminal and a TEE trusted computing node. The zero terminal remotely accesses the TEE trusted computing node and establishes a trusted connection with the TEE trusted computing node through two-way verification and performs encrypted communication. The zero terminal is used to display the data annotation interface provided by the TEE trusted computing node and send data annotation instructions to the TEE trusted computing node; The TEE trusted computing node is used to schedule trusted applications deployed on the TEE trusted computing node itself for the zero terminal, and to operate on the data to be labeled through the trusted applications according to the data labeling instructions. The data to be labeled is decrypted by the data management platform in the TEE trusted computing node and transmitted to the trusted application.
2. The data annotation system combining zero terminal and TEE according to claim 1, characterized in that, The TEE trusted computing node includes a data management platform and a trusted application. The trusted application is communicatively connected to the data management platform. The data management platform is used to store encrypted data blocks obtained by encrypting the original data provided by the data provider, and to transmit the original data to the trusted application based on data annotation instructions. The encrypted data blocks are associated with authorization information, which is used to constrain the data annotation party of the original data. The trusted application is used to operate on the original data based on the data annotation instructions.
3. The data annotation system combining zero terminal and TEE according to claim 1 or 2, characterized in that, The TEE trusted computing node also includes several virtual machines, each of which is connected to the trusted application. The virtual machines are used to build a communication bridge between the zero terminal and the trusted application, so as to enable the zero terminal to transmit data annotation instructions to the trusted application and the trusted application to synchronize the data annotation interface to the zero terminal. When multiple zero terminals communicate with the TEE trusted computing node, each zero terminal corresponds to one virtual machine.
4. The data annotation system combining zero terminal and TEE according to claim 2, characterized in that, The data management platform includes an environment verification module, a data management module, and a task management module. The environment verification module is used to perform hardware root of trust verification on the zero terminal based on the first identity credential provided by the zero terminal, and to initiate remote authentication to the zero terminal so that the zero terminal can remotely verify the TEE trusted computing node. It also performs hardware root of trust verification on the data provider based on the second identity credential provided by the data provider, and to initiate remote authentication to the data provider so that the data provider can remotely verify the TEE trusted computing node. The data management module is used to encrypt the original data provided by the data provider and associate authorization information with the encrypted data blocks obtained after encryption. The task management module is used to decrypt the encrypted data block and transmit the decrypted raw data to the trusted application.
5. The data annotation system combining zero terminal and TEE according to claim 4, characterized in that, The data management platform also includes a log auditing module; the log auditing module is used to record the operation log of the entire operation process of the data annotation instruction, and to monitor the anomalies of the entire operation process of the data annotation instruction based on the operation log.
6. The data annotation system combining zero terminal and TEE according to claim 1, characterized in that, The trusted application is also used to send the result data formed in response to the data annotation instruction back to the data management platform in the TEE trusted computing node; the data management platform is also used to encrypt the result data to obtain an encrypted result data packet, perform dual verification on the encrypted result data packet, and after the dual verification is passed, associate and store the encrypted result data packet with its corresponding encrypted data block, wherein the dual verification includes integrity verification based on the operation integrity check code of the encrypted result data packet and legality verification based on the authorization information of the zero terminal and the authorization information of the encrypted result data.
7. The data annotation system combining zero terminal and TEE according to claim 1, characterized in that, The zero terminal is not equipped with a local storage unit or a local computing unit.
8. A data annotation method combining zero-terminal and TEE, characterized in that, The data annotation system combining zero terminal and TEE as described in any one of claims 1-7, the method comprising: establishing a trusted connection between the TEE trusted computing node and the zero terminal after bidirectional verification, and displaying a data annotation interface provided by the TEE trusted computing node; the TEE trusted computing node scheduling a trusted application configured for the zero terminal; the TEE trusted computing node obtaining raw data from the data management platform in the TEE trusted computing node through the trusted application, wherein the raw data is obtained by the data management platform decrypting the encrypted data block corresponding to the data annotation instruction; the TEE trusted computing node responding to the data annotation instruction by receiving the data annotation instruction sent by the zero terminal and operating the raw data block according to the data annotation instruction through the trusted application.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the data annotation method combining zero terminal and TEE as described in claim 8.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the data annotation method combining zero terminal and TEE as described in claim 8.
Citation Information
Patent Citations
Communication terminal and communication terminal marking method
CN120769265A