A data outbound compliance self-checking system based on a trusted execution environment and three-dimensional consistency detection
Patent Information
- Application Number
- CN202610987685.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-03
- Publication Date
- 2026-09-29
AI Technical Summary
[0010]针对现有技术存在的监管机构直接审查企业明文数据易导致企业隐私泄露、企业自行开展数据出境自查但监管机构难以确认其是否实际执行指定检测模型及合规规则、以及现有单一维度检测模型难以精准识别复杂变异违规数据等问题,本发明提出了一种基于可信执行环境与三维一致性检测的数据出境合规自查系统,为企业在数据出境前开展本地可信自查提供一种可验证的软硬件协同范式
[0020](1)本发明系统兼顾企业数据隐私保护与出境自查可信性,建立企业侧可信自查机制:针对现有数据出境审查方案中,监管机构或第三方机构直接获取企业明文数据进行检测,可能导致企业商业秘密、用户隐私等敏感信息泄露的问题,本发明在企业侧部署可信执行环境,使待出境数据仅在企业侧受硬件级隔离保护的TEE内存中进行明文检测,监管机构不获取企业原始业务数据。同时,通过远程证明机制验证企业侧实际运行的检测程序、检测模型、合规规则及工程配置是否为经授权的版本,从而在技术层面实现企业数据不出域、检测过程可验证、监管结果可可信。
Smart Images

Figure CN122845205A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security and cyberspace security technology, and relates to enterprise data export compliance self-inspection, Trusted Execution Environment (TEE) and abnormal data detection technology. Specifically, it relates to a structured data export compliance self-inspection system based on Trusted Execution Environment, remote proof and three-dimensional consistency detection. Background Technology
[0002] With the development of globalization, enterprises generate a large amount of structured data that needs to be transferred across borders during cross-border operations, cloud service collaboration, customer service, and data analysis. Enterprises need to conduct compliance self-checks on relevant data before it leaves the country to identify sensitive information, abnormal fields, and non-compliant content. However, relying solely on enterprises to conduct self-checks makes it difficult for regulatory agencies to verify whether enterprises have truly implemented the prescribed testing procedures and used the specified testing models and rule versions, resulting in a lack of credibility for the self-check results. On the other hand, if regulatory agencies directly obtain and review enterprises' plaintext data, there is a risk of leakage of sensitive information such as trade secrets and user privacy, and requiring enterprises to provide plaintext data may not meet legal compliance requirements in some scenarios.
[0003] Therefore, there is an urgent need for a technical solution that can both protect corporate data from leakage and provide regulatory agencies with a basis for trust in the testing process and results. By deploying a Trusted Execution Environment (TEE) on the enterprise side, plaintext testing of data to be exported can be performed within a locally protected execution space, ensuring that the data never leaves the enterprise's control. Simultaneously, combined with a remote verification mechanism, regulatory agencies can verify whether the testing programs, models, and rules actually running on the enterprise side are authorized versions. This allows for credible supervision and compliance assurance of the enterprise's self-inspection process for exporting data without obtaining the enterprise's original data.
[0004] Existing solutions to the conflict between cross-border data export regulation and privacy include:
[0005] (1) Plaintext-based deep packet inspection (DPI) and traffic mirroring solutions: These solutions deploy auditing devices at the gateway to directly decrypt and perform in-depth analysis of network traffic. While these solutions are highly efficient, they completely undermine the enterprise's end-to-end encryption protocols, fail to protect the enterprise's business data privacy, and are difficult to gain the enterprise's trust and cooperation.
[0006] (2) Pure cryptographic privacy-preserving computation schemes, such as fully homomorphic encryption and secure multi-party computation methods: These technical schemes aim to achieve absolute privacy protection during the computation process. For example, rule matching is performed on traffic in an encrypted state. However, their computational overhead is usually several orders of magnitude higher than that of plaintext operations, and the system throughput is extremely low, which is simply unable to support the network traffic of millions of requests per second (QPS) in real business.
[0007] Reference document 1 (Chinese Invention Patent: Deep Packet Inspection Method and System, Publication No. CN104717101A, Publication Date: 2015.06.17) and Reference document 2 (Chinese Invention Patent Application: A Method for Intelligent Analysis of Malicious HTTPS Traffic Based on Online Training Algorithm, Publication No. CN113259313A, Publication Date: 2021.08.13) focus on gateway-based deep packet inspection (DPI) or encrypted traffic feature extraction, identifying business types or malicious behavior by decrypting traffic or analyzing communication statistical characteristics. However, this approach does not address the pain point of enterprises refusing to expose core trade secrets in plaintext. Intercepting and decrypting through a gateway completely destroys the end-to-end encryption protocol, making it difficult to gain the trust of enterprises in compliance and regulatory scenarios.
[0008] Reference document 3 (Chinese Invention Patent: Blockchain Data Processing Method and Apparatus Based on Cloud Computing, Publication No. CN113438289A, Publication Date: 2021.09.24) introduces privacy computing technology, which uses TEE (Trusted Execution Environment) for blockchain data processing. It encapsulates encrypted decryption and core logic within a cloud-based TEE to ensure data is "usable but not visible." However, this solution ignores the extremely limited physical characteristics of TEE in terms of trusted memory (EPC) and computing resources. It lacks sufficient granularity in scheduling and management when dealing with high-concurrency traffic. In real-world data outbound operations, requiring all network traffic to directly enter the TEE for encryption, decryption, and deep inference can lead to severe memory paging overhead and queuing delays.
[0009] Existing technologies are mostly detection models targeting specific dimensions, failing to fully consider the complexity and dynamic changes of methods used to evade illegal cross-border data. For example, while reference document 4 (Chinese Invention Patent: A Method for Detecting Network Traffic Anomalies Based on Online Continuous Learning, Publication No. CN119299238A, Publication Date 2025.01.10) introduces prediction and detection models based on continuous learning or neural networks, it often only focuses on frequency domain / time domain features or single spatial features. Faced with advanced evasion techniques commonly used in illegal cross-border data smearing, such as structural camouflage and semantic injection, these single-dimensional detection methods often suffer from extremely high false negative rates. They lack a consistent discrimination model that integrates "syntactic structure," "physical form," and "business semantics" across dimensions, making regulatory systems vulnerable to being deceived by deliberately altered compliant data shells. Summary of the Invention
[0010] To address the problems of existing technologies, such as regulatory agencies directly reviewing plaintext data, which could lead to privacy leaks; the difficulty for regulatory agencies to verify whether companies are actually implementing designated detection models and compliance rules when conducting self-inspections of data exports; and the inability of existing single-dimensional detection models to accurately identify complex and mutated non-compliant data, this invention proposes a data export compliance self-inspection system based on a trusted execution environment and three-dimensional consistency detection. This provides a verifiable hardware and software collaborative paradigm for companies to conduct local trusted self-inspections before data exports. The system deploys a three-dimensional consistency discrimination model that considers "syntactic structure—physical form—business semantics" within the company's trusted execution environment. It performs plaintext compliance checks on the structured data to be exported and, through a remote verification mechanism, enables regulatory agencies to verify that the detection programs, models, and rules actually running on the company's side are authorized versions. This allows for trusted supervision of the company's data export self-inspection process without exposing the company's original plaintext data to regulatory agencies.
[0011] The present invention provides a data export compliance self-inspection system based on trusted execution environment and three-dimensional consistency detection, comprising: an enterprise export gateway deployed at the enterprise network boundary, a TEE self-inspection enclave deployed on a trusted physical computing node on the enterprise side, a three-dimensional consistency discrimination model deployed inside the TEE self-inspection enclave, and a regulatory agency center.
[0012] The enterprise outbound gateway is used to control and route the structured data of the encrypted session traffic to be exported before it actually leaves the country. The structured data to be exported is submitted to the TEE self-inspection enclave for compliance testing through the enterprise's internal security channel. The enterprise outbound gateway receives the compliance test results returned by the TEE self-inspection enclave and only allows the corresponding encrypted session traffic to be exported when the test result is compliant. When the test result is non-compliant, suspected non-compliant, or no valid test result is obtained, the enterprise outbound gateway will block, suspend the export of the corresponding data, or transfer it to the enterprise's internal manual review process.
[0013] The TEE self-inspection enclave runs a trusted execution environment in hardware-isolated memory, executes deployed detection programs, and calls pre-deployed three-dimensional consistency discrimination models and compliance inspection standards to perform compliance checks on the structured data of outbound traffic. After the three-dimensional consistency discrimination model completes the compliance check, the TEE self-inspection enclave returns the compliance check results to the enterprise's outbound gateway. The TEE self-inspection enclave also uploads the audit metadata of the structured data of the outbound traffic for compliance checks to the regulatory agency center.
[0014] The three-dimensional consistency discrimination model, based on compliance inspection standards, sequentially examines the structured data of outbound traffic across three dimensions: syntactic structure, physical form, and business semantics. In the syntactic structure dimension, it extracts the tree-like topology of the structured data format and compares it with the data format object set in the compliance inspection standards to identify any non-compliant structures. In the physical form dimension, it extracts the attribute features of each field in the structured data, including text length, frequency of enumerated values, and numerical value, and performs outlier detection to identify any violations. In the business semantics dimension, it performs cross-domain consistency analysis and semantic violation checks.
[0015] The regulatory agency center is used to issue signed and authorized 3D consistency discrimination models and model update packages, compliance inspection standards, testing procedures, and TEE project configurations to TEE self-inspection sites, and to manage the local versions of the 3D consistency discrimination models, compliance inspection standards, testing procedures, and project configurations. The 3D consistency discrimination model update packages and compliance inspection standards are generated based on the enterprise's registered business scope, industry compliance requirements, and data detection parameters adapted to the enterprise's outbound business. The regulatory agency center is also used to issue remote certification random challenge values to TEE self-inspection sites and verify the remote certification reports returned by the TEE self-inspection sites to confirm that the trusted execution environment on the enterprise side is actually running authorized testing procedures, 3D consistency discrimination models, and compliance inspection standards.
[0016] The regulatory agency center receives audit metadata uploaded by the TEE self-inspection enclave that does not contain original business plaintext data. The audit metadata includes one or more of the following: detection time, three-dimensional consistency discrimination model version, compliance inspection standard version, trusted execution environment measurement information, detection conclusion, risk type, and risk score.
[0017] The aforementioned TEE self-check enclave, when the three-dimensional consistency discrimination model detects circuit breaker type violations in all encrypted session traffic, directly triggers interception and generates a violation alarm; for traffic that does not detect circuit breaker type violations, the abnormal values output by each dimension are weighted and summed, and compared with the set suspected abnormal threshold to finally determine whether the traffic is in violation.
[0018] The aforementioned TEE self-inspection enclave is implemented using the Apache Teaclave trusted computing framework. The three-dimensional consistency discrimination model is written in Rust, and during the compilation phase, the three-dimensional consistency discrimination model is directly registered and compiled into a built-in function of the Teaclave framework. When encrypted session traffic routed from the enterprise's outbound gateway enters the hardware-isolated memory, it is decrypted in blocks of a set size. The decrypted plaintext data blocks are then input into the three-dimensional consistency discrimination model in real time as a stream for detection. After the three-dimensional consistency discrimination model completes its detection, it performs read-after-destruction and closed-loop reporting. Read-after-destruction means that the memory management module of the hardware-isolated memory immediately triggers a memory overwrite operation to completely erase the decryption key and all related plaintext data. Closed-loop reporting means that after destroying the plaintext, only the judgment result, which does not contain any original data, is re-encrypted using the public key of the regulatory agency center before being reported to the regulatory agency center.
[0019] The advantages and positive effects of this invention are as follows:
[0020] (1) The present invention takes into account both enterprise data privacy protection and the credibility of outbound self-inspection, and establishes a credible self-inspection mechanism on the enterprise side: In response to the problem that in the existing data outbound review scheme, regulatory agencies or third-party institutions directly obtain the plaintext data of enterprises for testing, which may lead to the leakage of sensitive information such as enterprise trade secrets and user privacy, the present invention deploys a trusted execution environment on the enterprise side, so that the data to be exported is only tested in plaintext in the TEE memory protected by hardware level isolation on the enterprise side, and the regulatory agencies do not obtain the original business data of the enterprise. At the same time, the detection program, detection model, compliance rules and engineering configuration actually running on the enterprise side are verified through a remote certification mechanism to verify whether they are authorized versions, thereby achieving, at the technical level, that enterprise data does not leave the domain, the detection process is verifiable, and the regulatory results are credible.
[0021] (2) The system of the present invention improves the credibility of the enterprise's self-inspection process through the remote certification and model version binding mechanism: After the enterprise deploys its own local testing software, the regulatory agency has difficulty in confirming whether the enterprise has actually implemented the specified testing process, whether it has used the latest testing model and compliance rules, and whether there is a problem of program replacement or configuration tampering. The present invention binds the TEE metric value, the testing program version, the three-dimensional consistency discrimination model version, the compliance inspection standard version and the engineering configuration, and generates a remote certification report. This enables the regulatory agency to verify that the trusted execution environment on the enterprise side is actually running an authorized testing program, model and rules without obtaining the enterprise's original plaintext data, thereby improving the credibility and auditability of the enterprise's data export self-inspection results.
[0022] (3) The present invention constructs a three-dimensional consistency discrimination model, which achieves accurate defense against complex variant escape under the limitation of TEE resources: In view of the shortcomings of existing detection models based on single keyword regular matching or shallow statistics, such as high false negative rate and easy escape by structural camouflage or noise filling, the present invention aims to propose a three-dimensional consistency discrimination model from shallow to deep, which performs pipeline-style cross-validation in three dimensions: syntactic structure layer (form), physical morphology layer (body) and business semantic layer (meaning), which greatly improves the recall rate and sensitivity of the model under harsh environment.
[0023] (4) The system of this invention is based on the latest Teaclave SDK Built-in mode to achieve in-depth engineering optimization: In view of the significant performance loss and context switching overhead of traditional TEE frameworks when processing intensive network traffic, the system of this invention uses the built-in mode provided by the latest Apache Teaclave SDK for system-level integration optimization. By using a memory-safe language (such as Rust), the above-mentioned three-dimensional consistency discrimination model is directly constructed as the built-in execution logic of the Teaclave framework, completely removing the extra running burden of traditional sandbox virtual machines, and realizing the native full-speed streaming processing of the detection model in protected memory (Enclave). This greatly reduces the latency of single traffic decryption and inference, ensuring the high availability and feasibility of the architecture in industrial-grade massive high-concurrency outbound scenarios. Attached Figure Description
[0024] Figure 1 This is a schematic diagram of the overall architecture of the data export compliance self-inspection system based on TEE and three-dimensional consistency detection according to the present invention;
[0025] Figure 2 This is a flowchart of the verification process for the three-dimensional consistency discrimination model of the present invention. Detailed Implementation
[0026] The present invention provides a data export compliance self-inspection system based on a trusted execution environment and three-dimensional consistency detection, which constructs a lightweight data export supervision mechanism that balances enterprise data privacy protection, extremely high gateway throughput, and multi-dimensional accurate compliance review. The invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0027] The architecture of the data export compliance self-inspection system based on a trusted execution environment and a three-dimensional consistency discrimination model in this invention is as follows: Figure 1 As shown, a four-tuple system model is adopted to clearly define the rights and responsibilities of each party and the data boundaries. To formally express the core entities and core assets of the architecture, including: (1) Enterprise outbound gateway (Enterprise Egress Gateway): Deployed at the enterprise network boundary, it is responsible for receiving the structured data of the encrypted session traffic to be exported, generating data traffic identifiers or data digests for the structured data to be exported, and submitting the structured data to be exported to the TEE self-inspection enclave for detection; the enterprise outbound gateway, based on the detection results returned by the TEE self-inspection enclave, performs actions such as allowing, blocking, or transferring the encrypted session traffic to be exported for manual review. (2) TEE self-inspection enclave (TEERegulatory Enclave): Deployed on trusted physical computing nodes, located on the enterprise side, and built on hardware-level memory isolation technologies such as SGX (Software Protection Extension) / TDX (Trusted Domain Extension). Internally, it runs a trusted execution environment based on frameworks such as Apache Teaclave. (3) Regulatory agency center (Regulatory Authority Center): Represents the national or industry data export authority, responsible for managing compliance baselines, issuing detection model parameters, and receiving final audit alerts. (4) Three-dimensional Consistency Discriminative Model M: Composed of Pre-trained and safely deployed The internal core detection algorithm engine includes three detection dimensions: syntactic structure, physical form, and business semantics.
[0028] This invention provides a system for pre-exit trusted self-inspection and outbound control of structured data awaiting export from the enterprise side. Instead of performing probability-based traffic sampling on the data awaiting export, the enterprise's outbound gateway submits the structured data within the system's management scope to the enterprise's TEE self-inspection site for testing before actual export. To ensure that the testing programs, models, and compliance standards actually running on the enterprise side are all authorized versions, this invention also establishes a trusted verification link for the enterprise's self-inspection process through a remote verification mechanism. An implementation flow for this invention's system to achieve pre-exit trusted self-inspection and outbound control of structured data awaiting export from the enterprise side is as follows, including steps 11-15.
[0029] Step 11: Model Update and Compliance Rule Deployment. Based on the type of outbound business, the enterprise extracts anonymized business sample features or statistical parameters locally, generates data detection parameters adapted to the outbound business, and transmits them to the regulatory agency center. The regulatory agency center's model and rule management module generates a corresponding 3D consistency discrimination model update package and compliance inspection standards based on the enterprise's registered business scope, industry compliance requirements, and the data detection parameters adapted to the enterprise's outbound business, and digitally signs the model update package and compliance inspection standards. The regulatory agency center issues the signed 3D consistency discrimination model and model update package, compliance inspection standards, detection programs, and TEE project configuration to the TEE self-inspection site, and manages the version of the 3D consistency discrimination model, compliance inspection standards, detection programs, and TEE project configuration locally.
[0030] The TEE self-inspection enclave performs signature verification and integrity checks on the received model update package, compliance inspection standards, and engineering configuration package. After successful verification, it loads these into the trusted execution environment for execution. The model update package contains parameter thresholds for detecting data related to the corresponding business across three dimensions: syntactic structure, physical form, and business semantics. In this embodiment, the engineering configuration package includes runtime environment configurations for configuring the trusted execution environment and predefined startup parameters; the detection program refers to the code program that uses a three-dimensional consistency discrimination model to process and detect structured data.
[0031] Step 12: Extract data traffic identifiers and data digests. This involves extracting the structured data from any outbound encrypted session traffic. Arrival at the exit gateway At this time, the gateway's packet processing module first extracts the unique identifier ID of the traffic. This unique identifier can be the five-tuple information of the network protocol (source IP, destination IP, source port, destination port, transport layer protocol) or the application layer Request ID. Secondly, the gateway's packet processing module also extracts a data digest from the structured data.
[0032] Step 13: Plaintext Inspection of TEE on the Enterprise Side. The enterprise's outbound gateway packages and submits the structured data to be exported, data traffic identifier, and data digest to the TEE self-inspection enclave through the enterprise's internal secure channel. The TEE self-inspection enclave performs plaintext inspection on the structured data to be exported in hardware-isolated memory, executes the inspection program, calls the pre-deployed three-dimensional consistency discrimination model, and performs compliance inspections on the structured data to be exported in terms of syntactic structure, physical form, and business semantics according to compliance inspection standards.
[0033] Step 14: Detection Result Binding and Outbound Control. The TEE self-inspection enclave generates a detection conclusion based on the detection results, binding it to the data traffic identifier and data digest. When the detection conclusion is compliant, the TEE self-inspection enclave returns a compliant release result to the enterprise's outbound gateway. When the detection conclusion is non-compliant or suspected non-compliant, the TEE self-inspection enclave returns a blocking result or a manual review result to the enterprise's outbound gateway. The enterprise's outbound gateway only allows the corresponding structured data to leave the country when the data digest and detection conclusion binding information are consistent and the detection conclusion is compliant. The TEE self-inspection enclave uploads the audit metadata for compliance detection to the regulatory agency center.
[0034] Step 15: Remote Verification and Audit. The TEE self-inspection enclave generates a remote verification report based on random challenge values issued by the trusted hardware root and the regulatory agency center's model and rule management model. The remote verification report includes at least the trusted execution environment metric, a summary of the testing program, a summary of the 3D conformance discrimination model version, a summary of the compliance check standard version, and a summary of the TEE engineering configuration. The regulatory agency center verifies the remote verification report to confirm that the enterprise-side TEE self-inspection enclave has not been tampered with and that the specified versions of the testing program, 3D conformance discrimination model, compliance check standard, and engineering configuration are actually running.
[0035] The structured data of the encrypted session traffic to be exported, submitted by the enterprise's outbound gateway to the TEE self-inspection enclave, will undergo plaintext detection in the enterprise's hardware-isolated memory. Subsequently, the system executes a pre-deployed detection program, invoking a pre-deployed three-dimensional consistency discrimination model. Based on compliance inspection standards, it performs a three-layer pipeline-style compliance review of the structured data to be exported, from shallow to deep, specifically including steps 21-23. The compliance inspection standards include parameter thresholds for the three-dimensional consistency discrimination model to detect syntactic structure, physical form, and business semantics. These standards are distributed to the TEE self-inspection enclave by the regulatory agency's model and rule module in the form of a rule package with version identification and digital signature.
[0036] Step 21: Perform the first layer of verification. The first layer is the syntactic structure layer, where fidelity determination based on the schema topology is primarily performed. This aims to intercept highly deterministic violations with minimal computational overhead. The first layer of verification includes:
[0037] (1) Extraction and comparison: The three-dimensional consistency discrimination model first parses the format of the structured data to be exported, such as JSON or XML, extracts its tree topology from the format, and strictly compares it with the data format object set Schema in the compliance inspection standards pre-filed by the regulatory agency.
[0038] (2) Identify non-compliant structures. Non-compliant structures include: A. Shadow field injection: Identify and intercept illegally extended or unregistered unknown fields, such as maliciously added debug_log fields. B. Missing key fields: Detect whether essential anchor fields for compliance auditing have been intentionally deleted. Essential anchor fields refer to fields that are required by compliance inspection standards to be fixed in position and have unchanged content. C. Type and hierarchy mutation: Verify whether the underlying data type of a field has been maliciously tampered with, such as String type mutation to Object, and whether it has escaped traditional regular expression detection by changing the nesting depth. D. High-entropy load detection: For fields with correct structures, calculate the Shannon entropy of their content and intercept abnormal loads filled with encrypted or obfuscated noise.
[0039] Step 22: Perform the second layer of verification. The second layer is the physical morphology layer. For data that passes the first layer of structural verification, this layer mainly performs outlier detection based on statistical distribution characteristics to capture abnormal traffic that is distorted in "magnitude" and "morphology".
[0040] The three-dimensional consistency discrimination model does not perform deep understanding of the specific text content. Instead, it extracts the physical attribute features of each field in the structured data, such as text length, enumeration value frequency, and numerical size, for violation identification. Specific violation identification types include abnormal length inflation and enumeration domain and numerical drift. Abnormal length inflation refers to monitoring whether the length of a specific text field experiences a non-linear surge to determine if a large violation payload is suspected. Enumeration domain and numerical drift refer to detecting whether the classification field exhibits abnormal values outside the historical normal baseline samples, and whether numerical indicators deviate significantly from the normal business logic range. The degree of deviation can be pre-set to define whether a deviation is considered severe.
[0041] Step 23: Perform the third layer of verification. The third layer is the business semantic layer. For suspected data that passes the first two layers of detection but shows slight fluctuations in statistical characteristics, this layer will perform deep penetration detection of business logic consistency at the semantic level, and perform cross-domain consistency analysis and semantic violation checks.
[0042] Cross-domain consistency analysis refers to the use of a three-dimensional consistency discrimination model, combined with industry domain knowledge of the exporting company, to vectorize and extract the actual semantics of text fields and determine whether the semantics belong to the same industry domain. Semantic violation checks primarily detect heterogeneous semantic injection, that is, whether sensitive data from non-declared domains is injected into compliant fields, in order to accurately identify "sensitive content under a legal guise." For example, under a fully compliant field name, such as "order description order_desc," a violating company might attempt to fill in and export extremely sensitive data from non-declared domains, such as medical patient prescriptions or advanced industrial formulas.
[0043] In this embodiment of the invention, the schema in the compliance inspection standard includes the following numerical field parameters and text field parameters, as shown in Tables 1 and 2. The regulatory agency center can adjust the parameters included in the schema in the compliance inspection standard as needed. The regulatory agency center pre-obtains traffic samples from the enterprise's outbound gateway, calculates the standard parameters of each parameter in the schema in the compliance inspection standard, and then distributes them to the TEE self-inspection enclave for the detection of this type of traffic.
[0044] In this embodiment of the invention, there are violations of both circuit breaker and non-circuit breaker types. Circuit breaker violations mainly include two types: the first is structural errors, such as missing or redundant fields, or incorrect field types; the second is significant deviations from the indicator, for example, a value of an indicator deviating directly from three standard deviations from the mean will trigger a circuit breaker.
[0045] In this embodiment of the invention, when the three-dimensional consistency discrimination model detects any type of circuit breaker violation, the TEE self-checks the enclave, triggers interception, generates a violation alarm, and uploads the compliance detection results to the enterprise's outbound gateway. If the three-dimensional consistency discrimination model does not detect a circuit breaker violation, then for each layer of detection the traffic passes through, an anomaly value is obtained. The anomaly values of each layer are weighted and summed, and compared with a set suspected anomaly threshold. If the sum exceeds the threshold, the traffic is judged to be in violation, triggering interception and generating a violation alarm; otherwise, the traffic is considered compliant and allowed to pass.
[0046] Table 1 Numeric field parameters
[0047]
[0048] Table 2 Text Field Parameters
[0049]
[0050] To efficiently run the three-dimensional consistency discrimination model on extremely limited TEE hardware memory, such as SGX EPC, and to meet the real-time requirements of outbound gateways, this invention optimizes the underlying engineering architecture based on the latest Apache Teaclave trusted computing framework, implementing a secure execution and closed-loop destruction mechanism based on Teaclave Built-in mode. Built-in mode means Teaclave runs on real SGX hardware. The steps and data flow mechanism for implementing the secure execution and closed-loop destruction mechanism based on Teaclave Built-in mode in this invention include the following steps 31-33.
[0051] Step 31: Implement native compilation and deployment based on Rust and Built-in mode.
[0052] The system of this invention uses Rust, a language with extremely strong memory safety features, to write the three-dimensional consistency discrimination model. During the compilation phase, it skips the traditional WASM sandbox packaging process and directly registers and compiles the three-dimensional consistency discrimination model as a built-in function of the Teaclave framework.
[0053] The system of this invention compiles the three-dimensional consistency discrimination model code and the core executor of Teaclave into the same Enclave, thereby achieving full-speed native operation at the underlying level without sandbox loss.
[0054] Step 32: Implement streaming decryption and detection within the enclave.
[0055] When structured data routed from the enterprise's outbound gateway enters the TEE, the system does not perform a full load. Instead, it divides the data into chunks of fixed-size memory. The plaintext data chunks are then fed into the pipeline of the three-dimensional consistency discrimination model in real time as a stream for rolling detection.
[0056] Step 33: Implement a closed loop for hardware-level self-destructing messages, audit reporting, and remote verification.
[0057] After the three-dimensional consistency discrimination model completes the detection of the current structured data to be exported, regardless of whether the detection result is compliant, non-compliant or suspected non-compliant, the TEE self-inspection enclave will execute the "read and burn" function and audit reporting.
[0058] The term "read-and-burn" refers to the TEE's self-checking enclave's internal memory management module triggering a memory overwrite operation to erase plaintext data, temporary keys, and intermediate calculation results generated during the detection process.
[0059] The aforementioned audit reporting refers to the process whereby, after destroying the plaintext, the TEE self-inspection enclave only encrypts the audit metadata (which does not contain the original business content) using the public key of the regulatory agency center, and reports it to the regulatory model and rule management center through a secure channel. The audit metadata includes the version of the three-dimensional consistency discrimination model, the version of the compliance inspection standard, the detection conclusion, the risk type, the risk score, trusted execution environment measurement information, and the detection time.
[0060] The aforementioned remote verification closed loop refers to the TEE self-inspection enclave generating a remote verification report based on the random challenge value issued by the regulatory model and rule management center. The regulatory model and rule management center verifies the remote verification report to confirm that the detection program, three-dimensional consistency discrimination model, compliance inspection standards, and engineering configuration actually running in the enterprise-side TEE self-inspection enclave are all authorized versions.
[0061] Except for the technical features described in the specification, all other technologies are known to those skilled in the art. Descriptions of well-known components and technologies are omitted in this invention to avoid redundancy and unnecessary limitation. The embodiments described above do not represent all embodiments consistent with this application. Various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of this invention are still within the protection scope of this invention.
[0062] In general, the various exemplary embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, firmware, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software executed by a controller, microprocessor, or other computing device. When aspects of embodiments of this disclosure are illustrated or described as block diagrams, flowcharts, or using some other graphical representation, it will be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as non-limiting examples in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
Claims
1. A data export compliance self-inspection system based on a trusted execution environment and three-dimensional consistency detection, characterized in that, include: The enterprise outbound gateway, deployed at the enterprise network boundary, receives structured data of encrypted session traffic awaiting outbound traffic, submits it to the TEE self-inspection enclave for compliance testing through the enterprise's internal security channel, receives the compliance test results returned by the TEE self-inspection enclave, and only allows the corresponding outbound traffic to leave the country when the test result is compliant. When the test result returned by the TEE self-inspection enclave is a violation, suspected violation, or no valid test result is obtained, the corresponding outbound traffic is blocked, suspended from leaving the country, or transferred to the enterprise's internal manual review process. Where TEE stands for Trusted Execution Environment; The TEE self-inspection enclave, deployed on a trusted physical computing node on the enterprise side, runs a trusted execution environment in hardware-isolated memory, executes the deployed detection program, calls the three-dimensional consistency discrimination model and compliance inspection standards, performs compliance inspection on the structured data of outbound traffic, and returns the compliance inspection results to the enterprise outbound gateway. TEE self-inspection enclaves will upload audit metadata of structured data on outbound traffic for compliance testing to the regulatory agency center; The three-dimensional consistency discrimination model deployed in the TEE self-inspection enclave, based on compliance inspection standards, sequentially detects the structured data in three dimensions: syntactic structure, physical form, and business semantics. In the syntactic structure dimension, it extracts the tree-like topology of the data format and compares it with the data format object set in the compliance inspection standards to identify any non-compliant structures. In the physical form dimension, it extracts the attribute features of each field of the structured data, including text length, enumeration value frequency, and numerical value, and performs outlier detection to identify any violations. In the business semantics dimension, it performs cross-domain consistency analysis and semantic violation checks. And the regulatory agency center; the regulatory agency center issues signed and authorized three-dimensional consistency discrimination model and model update package, compliance inspection standards, testing procedures and TEE engineering configuration to the TEE self-inspection enclave. The three-dimensional consistency discrimination model update package and compliance inspection standards are generated according to the enterprise's filing business scope, industry compliance requirements and data testing parameters adapted to the enterprise's outbound business; the regulatory agency center manages the version of the three-dimensional consistency discrimination model, compliance inspection standards, testing procedures and TEE engineering configuration locally; the regulatory agency center also issues random challenge values for remote certification to the TEE self-inspection enclave and verifies the remote certification report returned by the TEE self-inspection enclave to confirm that the trusted execution environment on the enterprise side is actually running authorized testing procedures, three-dimensional consistency discrimination model and compliance inspection standards.
2. The system according to claim 1, characterized in that, The enterprise outbound gateway extracts traffic identifiers and data summaries from the structured data to be exported, and then submits them together with the structured data to the TEE self-inspection enclave through the enterprise's internal security channel. The TEE self-inspection enclave binds the compliance test results with the data traffic identifier and data summary of the corresponding structured data and returns them to the enterprise's outbound gateway.
3. The system according to claim 1, characterized in that, The regulatory agency center obtains data detection parameters adapted to outbound business from the enterprise's outbound gateway in advance. These data detection parameters are generated by the enterprise by extracting de-identified business sample features or statistical parameters locally according to the type of outbound business.
4. The system according to claim 1 or 3, characterized in that, The aforementioned TEE self-inspection enclave generates a remote verification report based on the trusted hardware root and the random challenge value. The remote verification report includes a trusted execution environment metric, a detection program summary, a three-dimensional consistency discrimination model version summary, a compliance inspection standard version summary, and a TEE project configuration summary.
5. The system according to claim 1, characterized in that, The aforementioned three-dimensional consistency discrimination model identifies illegal structures in the syntactic structure dimension, including: Shadow field injection: Identifies and intercepts illegally extended and unregistered unknown fields; Missing critical fields: Check if any required fields used for compliance checks have been removed; Type and hierarchical mutation: Validate whether the data type of the field has been maliciously tampered with, and whether there is any evasion of regular expression detection by changing the nesting depth; High-entropy load detection: For fields with correct structure, calculate the Shannon entropy of the field content to perform abnormal load detection.
6. The system according to claim 1, characterized in that, The aforementioned three-dimensional consistency discrimination model includes violation detection in the physical morphology dimension, including: Abnormal length inflation: Detects whether the length of a specific text field experiences a non-linear surge; Enumeration domain and numerical drift: Detect whether the classification field has abnormal values and whether the numerical index deviates significantly from the normal range.
7. The system according to claim 1, characterized in that, The aforementioned three-dimensional consistency discrimination model includes violation detection in the business semantic dimension, including: Cross-domain consistency analysis: Combining the industry domain knowledge of the outbound enterprise, the actual semantics of the text fields are vectorized and extracted to determine whether the industry domain to which the semantics belong is consistent; Semantic violation check: Check for the injection of sensitive data from non-declared areas under compliant fields.
8. The system according to claim 1, characterized in that, The aforementioned TEE self-inspection enclave is implemented using the Apache Teaclave trusted computing framework. The three-dimensional consistency discrimination model is written in Rust. During the compilation phase, the three-dimensional consistency discrimination model is directly registered and compiled into a built-in function of the Teaclave framework. When structured data routed from the enterprise's outbound gateway enters the hardware-isolated memory, it is divided into blocks of a set size. The data blocks are then input into the three-dimensional consistency discrimination model in real time as a stream for detection. After the three-dimensional consistency discrimination model completes its detection, hardware-level self-destruction and audit reporting are executed. The self-destruction refers to the memory management module inside the TEE self-inspection enclave triggering a memory overwrite operation to erase the plaintext data, temporary keys, and intermediate calculation results generated during the detection process. The audit reporting refers to the fact that after destroying the plaintext, the TEE self-inspection enclave only encrypts the audit metadata that does not contain the original business content using the public key of the regulatory agency center and reports it to the regulatory agency center through a secure channel.
9. The system according to claim 1 or 8, characterized in that, The audit metadata uploaded by the aforementioned TEE self-inspection enclave includes the detection time, the version of the three-dimensional consistency discrimination model, the version of the compliance inspection standard, trusted execution environment measurement information, detection conclusions, risk types, and risk scores.
10. The system according to claim 1, characterized in that, The aforementioned TEE self-inspection enclave, when the three-dimensional consistency discrimination model detects a circuit breaker type violation in the structured data of outbound traffic, directly triggers interception and generates a violation alarm; for structured data where no circuit breaker type violation is detected, the outlier values detected in each dimension are weighted and summed, and compared with the set suspected anomaly threshold to finally determine whether the traffic is in violation.
Citation Information
Patent Citations
Deep packet inspection method and system
CN104717101A
Malicious HTTPS traffic intelligent analysis method based on online training algorithm
CN113259313A
Block chain data processing method and device based on cloud computing
CN113438289A
Network traffic anomaly detection method based on online continuous learning
CN119299238A