Trusted Execution System and Method Based on Cloud Technology

The trusted execution system addresses data security and efficiency challenges by using dedicated communication channels and hardware accelerators for enclave computations, ensuring secure and efficient tenant computing without resource occupation.

JP2025523565AActive Publication Date: 2025-07-23HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024576848
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-01
Filing Date
2023-06-30
Publication Date
2025-07-23
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

Existing cloud technologies face challenges in ensuring data security and confidentiality while maintaining efficient computing performance, as enclaves occupy host machine resources, affecting service performance.

Method used

A trusted execution system is implemented using a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device, with dedicated communication channels for efficient and confidential calculations, utilizing hardware acceleration without occupying host machine resources.

Benefits of technology

The system enhances confidentiality and efficiency of tenant computing by offloading calculations to hardware accelerators, reducing the impact on host machine performance and resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025523565000001_ABST
    Figure 2025523565000001_ABST
Patent Text Reader

Abstract

This application provides a trusted execution system and method based on cloud technology to improve the confidentiality and efficiency of a tenant's computing requirements and reduce the impact on service performance. The system includes a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device, with a first communication channel established between the first tenant virtual instance and the first enclave virtual instance, and a second communication channel established between the first enclave virtual instance and the hardware accelerator device. The first tenant virtual instance sends a first computing request to the first enclave virtual instance via the first communication channel. The first enclave virtual instance receives the first computing request and invokes the hardware accelerator device based on the first computing request via the second communication channel to perform the computation. The first enclave virtual instance may further send the first computing result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud technology, and in particular, to a trusted execution system and method based on cloud technology.

Background Art

[0002] As the public cloud and hybrid cloud markets become increasingly mature and rapidly develop, security issues are gradually attracting the attention of enterprises. As a representative, the government and the financial industry have raised significant concerns regarding the confidentiality of data security in the gradual cloudification process of government and financial industry services. Throughout the data link, cloud service providers, operators, device providers, chip providers, and software providers may steal or tamper with relevant data. Therefore, how to ensure the maximum reliability and security of customer data has become an important point in current cloud technology development. Based on the above problems, a trusted execution environment (TEE) is provided as a concept for solving data privacy problems. The main principle of the trusted execution environment is to create a new environment for processing customer data in the existing execution environment. As long as the end-to-end reliability and verifiability of this secure environment are guaranteed, data security can be ensured. TEE is widely applied in intelligent terminal scenarios. For example, the fingerprint data of an application used for mobile payment is stored in a dedicated secure operating system for execution to prevent the theft of confidential data.

[0003] In the cloud scenario, a specific device or area used for performing calculations on the tenant's confidential data is called an enclave. The tenant cannot directly access the enclave, and by performing confidential calculations through the enclave, the data security of the tenant can be guaranteed.

[0004] However, currently, an Enclave is usually implemented by a virtual instance running on a host machine and has very limited functionality. Furthermore, the Enclave needs to occupy the processor and memory of the host machine to perform confidential computing. For example, to complete encryption and decryption functions, the enclave can only use the processor and memory of the host machine for computing. Since the tenant's virtual instance also runs on the host machine, the Enclave occupies the processor and memory that could originally be provided to the tenant's virtual instance. As a result, the services within the host machine are affected. Summary of the Invention

[0005] The present invention provides a cloud technology-based trusted execution system and method for improving the confidentiality and efficiency of a tenant's computing requirements and reducing the impact on service performance. Means for Solving the Problems

[0006] According to a first aspect, the present invention provides a trusted execution system based on cloud technology. The trusted execution system includes a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device. A first communication channel is established between the first tenant virtual instance and the first enclave virtual instance, and a second communication channel is established between the first enclave virtual instance and the hardware accelerator device. The first tenant virtual instance transmits a first calculation request to the first enclave virtual instance via the first communication channel. The first enclave virtual instance receives the first calculation request and invokes the hardware accelerator device based on the first calculation request via the second communication channel to perform calculations. The first enclave virtual instance may further transmit the first calculation result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel.

[0007] The trusted execution system may perform efficient and confidential calculations on the first calculation request transmitted by the first tenant virtual instance. The first tenant virtual instance transmits the first calculation request to the first enclave virtual instance in the process of using cloud services. To improve the calculation efficiency, the first enclave virtual instance invokes the hardware accelerator device to perform accelerated calculations on the first calculation request. To improve the calculation confidentiality, the first enclave virtual instance transmits the first calculation result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel. The first enclave virtual instance invokes the hardware accelerator device to perform accelerated calculations, so that the resources in the host machine are not additionally occupied, and the impact on the service performance of the host machine is reduced.

[0008] In a possible implementation of the first aspect, the first virtual function VF or the first physical function PF of the hardware accelerator device is directly passed through to the first enclave virtual instance according to the Peripheral Component Interconnect Express (PCIe) protocol. The second communication channel is a pass-through channel based on the PCIe protocol. The first enclave virtual instance invokes the first virtual function VF or the first physical function PF of the hardware accelerator device to perform calculations.

[0009] The first enclave virtual instance invokes the function of the hardware accelerator device for calculation in a hardware pass-through manner. As a result, the hardware acceleration function of the trusted execution system is increased, and the efficiency of the calculation request is improved.

[0010] In a possible implementation of the first aspect, the trusted execution system further includes a virtual instance manager. The virtual instance manager provides a secure module device. The secure module device acquires calculation request authentication information and provides authentication information for the first enclave virtual instance.

[0011] The secure module device set in the virtual manager within the trusted execution system acquires the relevant authentication information of the first calculation request and provides the authentication information to the first enclave virtual instance. After the authentication information is approved, the first enclave virtual instance starts to perform confidential calculations. By setting the relevant authentication information of the first calculation request, the confidentiality of performing calculations by the trusted execution system for the first calculation request sent by the first tenant virtual instance can be further improved.

[0012] Optionally, the secure module device may obtain the relevant authentication information of the first computing request from the cloud management platform. The cloud management platform is configured to manage the authentication information, and the authentication information is, for example, the tenant account information of the first tenant virtual instance and / or the key related to the account information.

[0013] In this possible implementation, the secure module device is further configured to set up a second communication channel between the first enclave virtual instance and the hardware accelerator device, and provide a software development kit (SDK) for the first enclave virtual instance. The first enclave virtual instance is further configured to call the second communication channel based on the SDK to send computation-related data from the second communication channel to the hardware accelerator device.

[0014] By installing the SDK, the first enclave virtual instance upgrades its function to call the hardware accelerator device for computation, so that the function can be extended based on the original function, and thus the operational difficulty of the function upgrade of the first enclave virtual instance can be reduced.

[0015] In a possible implementation of the first aspect, the virtual instance manager is further configured to provide an accelerator device, the accelerator device is configured to set up a second communication channel between the first enclave virtual instance and the hardware accelerator device, and the first enclave virtual instance is further configured to send computation-related data to the hardware accelerator device via the second communication channel.

[0016] The virtual instance manager in a trusted execution system provides an accelerator device. The first enclave virtual instance receives the first computing request of the first tenant virtual instance, and the accelerator device sends the relevant data of the first computing request to the hardware accelerator device. In this solution, the hardware acceleration function of the trusted execution system is added via the accelerator device, improving the efficiency of computing requests.

[0017] In a possible implementation of the first aspect, the trusted execution system further includes a second tenant virtual instance and a second enclave virtual instance. A third communication channel is set up between the second tenant virtual instance and the second enclave virtual instance, and a fourth communication channel is set up between the second enclave virtual instance and the hardware accelerator device. The second tenant virtual instance is configured to send a second computing request to the second enclave virtual instance via the third communication channel. The second enclave virtual instance receives the second computing request and, to perform the computation, calls the second virtual function VF or the second physical function PF of the hardware accelerator device based on the second computing request via the fourth communication channel. The second virtual function VF or the second physical function PF of the hardware accelerator device is directly passed through to the second enclave virtual instance according to the Peripheral Component Interconnect Express PCIe protocol, and the fourth communication channel is a pass-through channel based on the PCIe protocol.

[0018] The trusted execution system further includes a plurality of tenant virtual instances and a plurality of enclave virtual instances corresponding to the tenant virtual instances. Each enclave virtual instance receives a computing request of the tenant virtual instance and invokes a hardware accelerator device based on the computing request to perform computing. The hardware accelerator devices within the trusted execution system may be used by a single tenant or simultaneously by multiple tenants.

[0019] In a possible implementation of the first aspect, the first tenant virtual instance and the first enclave virtual instance operate on a host machine, and the hardware accelerator device is inserted into a main board slot of the host machine.

[0020] The first tenant virtual instance and the first enclave virtual instance within the trusted execution system operate on the operating system of the host machine, and the hardware accelerator device is inserted into a main board slot of the host machine. The hardware accelerator device can save the resources of the host machine and reduce the impact on the service performance of the host machine.

[0021] In this possible implementation, the hardware accelerator device is a smart card having an independent operating system, memory, and processor.

[0022] The smart card may provide a hardware acceleration function to the trusted execution system. Since the smart card has an independent operating system, memory, and processor, its usage performance is more efficient and stable.

[0023] In a possible implementation of the first aspect, the first tenant virtual instance and the first enclave virtual instance operate on the operating system of the host machine, and the host machine is connected to the hardware accelerator device via a PCIe high-speed communication bus.

[0024] In a trusted execution system, the host machine and the hardware accelerator device are connected via a PCIe high-speed communication bus. The high-speed communication bus can improve the communication efficiency between the host machine and the hardware accelerator device. The host machine can flexibly use the resources in the hardware accelerator device, resulting in cost reduction.

[0025] In a possible implementation of the first aspect, the calculation includes one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation.

[0026] The acceleration calculation performed by the hardware accelerator device in a trusted execution system includes one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation, so that different calculation requirements of the tenant virtual instance can be met.

[0027] According to a second aspect, the present invention provides a trusted execution method based on cloud technology. The method is applied to a trusted execution system, which includes a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device. A first communication channel is set between the first tenant virtual instance and the first enclave virtual instance, and a second communication channel is set between the first enclave virtual instance and the hardware accelerator device. The method includes the following steps: The first tenant virtual instance sends a first calculation request to the first enclave virtual instance via the first communication channel. The first enclave virtual instance receives the first calculation request, calls the hardware accelerator device based on the first calculation request via the second communication channel to perform calculations, and sends the first calculation result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel.

[0028] Any one of the second aspect or the implementation forms of the second aspect is a method implementation form corresponding to any one of the first aspect or the implementation forms of the first aspect. The descriptions in any one of the first aspect or the implementation forms of the first aspect are applicable to any one of the second aspect or the implementation forms of the second aspect, and will not be described in detail here.

[0029] According to a third aspect, the present invention provides a computer device. The computer device includes a processor and a memory. The memory is configured to store computer-executable instructions. The processor is configured to execute the computer-executable instructions stored in the memory so that the computer device can operate the first tenant virtual instance and the first enclave virtual instance to implement the method disclosed in any one of the second aspect and the possible implementation forms of the second aspect.

[0030] According to a fourth aspect, the present invention provides a computer storage medium containing computer-readable instructions. When the computer-readable instructions are executed, a first tenant virtual instance and a first enclave virtual instance are operated to implement the method disclosed in any one of the second aspect and the possible implementation forms of the second aspect.

[0031] According to a fifth aspect, the present invention provides a computer program product containing instructions. When the computer program product operates on a computer, the computer can operate a first tenant virtual instance and a first enclave virtual instance to perform the method disclosed in any one of the second aspect and the possible implementation forms of the second aspect.

Brief Description of the Drawings

[0032]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

DETAILED DESCRIPTION OF THE INVENTION

[0033] The following describes the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are only a part, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] First, the terms used in the embodiments of the present application are explained and described.

[0035] Definitions of Acronyms and Key Terms VM (Virtual Machine) refers to a complete software-simulated computer system that has sufficient hardware system functions and operates in a completely isolated environment. All tasks that can be completed on a server can be implemented on a virtual machine. When creating a virtual machine on a server, a part of the physical machine's hard disk and memory capacity needs to be used as the virtual machine's hard disk and memory capacity. Each virtual machine has an independent hard disk and operating system. The user of the virtual machine can operate the virtual machine by the user using the server.

[0036] Hypervisor (acting as a virtual machine manager) is an actual operating system that establishes and maintains a framework for managing virtual machines and provides many important services for other vxd programs.

[0037] VMM (Virtual Machine Monitor) is another name for a virtual machine manager.

[0038] Docker, which acts as a container, uses the namespace and cgroup technologies supported by the Linux kernel to isolate the application (APP) processes in an independent operating environment and the dependency packages of the application processes (specifically, the operating environment bins / libs, which are all the files required to run the APP).

[0039] An APP (Application) is a computer program used to complete one or more specific tasks. An APP operates in user mode, can interact with users, and has a visual user interface.

[0040] A TEE (Trusted Execution Environment) is an independent processing environment that has computing and storage functions and can provide security and integrity protection.

[0041] The CPU (Central Processing Unit) is the core of the computer system's computing and control, and is the final execution unit for information processing and program operation.

[0042] An enclave is a specific area for running customers' confidential data.

[0043] A PF (Physical Function) is used to support the PCI functions of SR-IOV and has the ability to fully configure or control PCIe device resources.

[0044] A VF (Virtual Function) is a lightweight PCIe function associated with a PF and can share one or more physical resources with the physical function and another VF associated with the same physical function.

[0045] An SDK (Software Development Kit) is a collection of development tools used by software engineers to create application software for specific software packages, software frameworks, hardware platforms, operating systems, and so on.

[0046] An SMD (Secure Module Device) is configured to provide a functional interface for completing the operation requirements of an enclave.

[0047] An AD (Accelerator Device) is a device configured to provide hardware acceleration capabilities to an enclave.

[0048] PCIe (Peripheral Component Interconnect Express) is a high-speed serial computer expansion bus standard and an interface standard for connecting high-speed components.

[0049] Embodiments of the present application provide a cloud technology-based trusted execution system and method for improving the confidentiality and efficiency of tenant computing requirements and reducing the impact on service performance. Details are described individually below.

[0050] FIG. 1 is a diagram of the architecture of a cloud data center according to an embodiment of the present application. As shown in FIG. 1, the cloud data center 1 includes a cloud management platform 10, an internal data center network 20, a client 40, and a plurality of host machines. In FIG. 1, for the sake of example, two host machines, for example, host machine 51 and host machine 52 are used. The host machine 51 and the host machine 52 complete information exchange with the internal data center network 20 and the cloud management platform 10 via network interface cards 5124 and 5224, respectively. The cloud management platform 10 completes information exchange with the client 40 via the Internet 30. The host machine 51 is used as an example for explanation. The host machine 51 includes a software layer 511 and a hardware layer 512. The tenant virtual instance 5111, the enclave virtual instance 5112, the virtual instance manager 5113, and the cloud management platform client 5114 operate on the host machine operating system 5115 in the software layer 511. The hardware layer 512 includes a memory 5121, a hardware accelerator device 5122, a processor 5123, and a network interface card 5124 connected to each other via a bus 5125.

[0051] The host machine 52 has a configuration similar to that of the host machine 51, and details are not described here.

[0052] The tenant virtual instance 5111 and the enclave virtual instance 5112 may be, for example, virtual machines (VMs). Correspondingly, the virtual instance manager 5113 is a hypervisor, which is also called a virtual machine monitor (VMM). The tenant virtual instance 5111 and the enclave virtual instance 5112 may be, for example, containers (Docker). Correspondingly, the virtual instance manager 5113 is a container manager.

[0053] Specifically, the cloud management platform 10 provides an access interface (e.g., a configuration interface for tenant-based configuration or an API for tenant-based configuration). Tenants of the cloud data center 1 may operate the client 40 to remotely access the access interface, register a cloud account and password with the cloud management platform 10, and log in to the cloud management platform 10. After successful authentication of the cloud account and password by the cloud management platform 10, the tenant may further make a payment on the cloud management platform to select and purchase virtual instances of specific specifications (processors, memory, and disks). After the purchase is successful, the cloud management platform 10 provides a remote login account and password for the purchased virtual instance. As a result, the client 40 may remotely log in to the virtual instance and install and operate the tenant's application on the virtual instance. The cloud management platform client 5114 receives control plane commands sent by the cloud management platform 10, creates virtual instances on the host machine based on the control plane control commands, and performs full life cycle management on the virtual instances. Thus, the tenant may create, manage, log in to, and operate virtual instances in the cloud data center 1 via the cloud management platform 10.

[0054] Before processing the data, an application (APP) running on a virtual instance decrypts the data in the memory 5121 of the host machine 51. Therefore, the data is more vulnerable to in - process attacks in the memory 5121. Confidential computing typically uses a hardware - based trusted execution environment (TEE) to solve this problem. The TEE is a secure area within the central processing unit (CPU). Embedded encryption keys and an embedded attestation mechanism are used to ensure the security of the TEE so that only authorized application code can access the keys. If malicious software or other unauthorized code attempts to access the keys, or if the authorized code is hacked or modified in some way, the TEE will deny access to the keys and cancel the calculation. In this way, the confidential data can remain in a protected state in the memory until the application instructs the TEE to decrypt the confidential data for processing. During the decryption process and the overall calculation process, the data cannot be accessed by any user.

[0055] Specifically, in a cloud scenario, when a tenant has confidential computing requirements and a tenant virtual instance 5111 is created in the software layer 511 of the host machine 51, an enclave virtual instance 5112 is created synchronously. An enclave is a specific area used to operate the customer's confidential data, and the enclave virtual instance 5112 is a virtual instance used to perform confidential computing for the customer.

[0056] In the following, with reference to the above - mentioned architecture of the cloud data center and the concept of confidential computing, a cloud - technology - based trusted execution system and method provided in the embodiments of the present application will be described.

[0057] Figure 2 is a diagram of a cloud technology-based trusted execution system according to an embodiment of the present application. The system may be, for example, host machine 51 or host machine 52 shown in Figure 1. Here, host machine 51 is used as an example for explanation. As shown in Figure 2, the trusted execution system includes tenant virtual instance 5111, enclave virtual instance 5112, and hardware accelerator device 5122. Communication channel 100 is set up between tenant virtual instance 5111 and enclave virtual instance 5112, and both tenant virtual instance 5111 and enclave virtual instance 5112 operate on host machine operating system 5115. Communication channel 200 is set up between enclave virtual instance 5112 and hardware accelerator device 5122. Tenant virtual instance 5111 sends a calculation request to enclave virtual instance 5112 via communication channel 100. Enclave virtual instance 5112 calls hardware accelerator device 5122 via communication channel 200 to perform the calculation, and then returns the calculation result to tenant virtual instance 5111 via communication channel 100.

[0058] Specifically, hardware accelerator device 5122 may be, for example, a smart card having an independent operating system, memory, and processor. Hardware accelerator device 5122 may be directly inserted into the main board slot of host machine 51, or hardware accelerator device 5122 may be connected to host machine 51 via a PCIe bus. In addition, the acceleration calculation performed by the hardware accelerator device in the trusted execution system includes one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation. As a result, different calculation requirements of tenant virtual instance 5111 can be satisfied.

[0059] Furthermore, the trusted execution system includes a virtual instance manager 5113. The virtual instance manager 5113 is configured to manage tenant virtual instances 5111 and enclave virtual instances 5112. The virtual instance manager 5113 further provides a secure module device 5116. The secure module device 5116 is configured to obtain authentication information required for performing confidential computing by the enclave virtual instance 5112 and provide authentication information for the enclave virtual instance 5112.

[0060] Specifically, the operating procedure of the trusted execution system shown in FIG. 2 may be described with reference to FIG. 3. FIG. 3 is a diagram of data exchange of a cloud technology-based trusted execution system according to an embodiment of the present application. In the method shown in FIG. 3, it is assumed that a tenant logs in to the cloud management platform 10 and inputs a designation of the tenant virtual instance 5111 to be created. The cloud management platform 10 notifies the cloud management platform client 5114 of the designation of the virtual instance 5111 to be created. The virtual instance manager 5113 where the cloud management platform client 5114 is arranged creates the virtual instance 5111 in the operating system of the host machine 51 and allocates the virtualized hardware resources in the host machine 51 to the virtual instance 5111. If the tenant has confidential computing requirements, the tenant may instruct the cloud management platform 10 to create an enclave virtual instance 5112 to be used in cooperation with the virtual instance 5111. The cloud management platform 10 instructs the cloud management platform client 5114 to create the enclave virtual instance 5112. The virtual instance manager 5113 where the cloud management platform client 5114 is arranged creates the enclave virtual instance 5112 in the operating system of the host machine 51 and allocates another virtualized hardware resource in the host machine 51 to the enclave virtual instance 5112. The tenant may determine the designation of the enclave virtual instance 5112 on the cloud management platform 10, and the cloud management platform 10 instructs the cloud management platform client 5114 to create the enclave virtual instance 5112 with the corresponding designation. Alternatively, the tenant does not need to specify the designation of the enclave virtual instance 5112 on the cloud management platform 10, and the enclave virtual instance 5112 may use the default designation on the cloud management platform 10 applicable to the enclave type of virtual instance.The enclave virtual instance 5112 is used in cooperation with the virtual instance 5111. A tenant may log in to the virtual instance 5111, but cannot log in to the enclave virtual instance 5112. If the tenant has confidential computing requirements for the virtual instance 5111, the virtual instance 5111 generates the confidential computing requirements and sends the requirements to the enclave virtual instance 5112 for processing.

[0061] It should be noted that except for the tenant, other tenants or cloud service providers cannot access or use the enclave virtual instance 5112. The enclave virtual instance 5112 can communicate with the virtual instance 5111 only through the communication channel 100. Also, the enclave virtual instance 5112 and the virtual instance 5111 have the same life cycle. When the tenant releases the virtual instance 5111, the enclave virtual instance 5112 is also released. Also, when the enclave virtual instance 5112 is released, the memory data corresponding to the enclave virtual instance 5112 is strictly formatted to ensure that the tenant's confidential computing information is not leaked.

[0062] Also, the enclave virtual instance 5112 pre-stores the tenant's identity authentication information.

[0063] For example, if the tenant needs to perform any one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation within the virtual instance 5111, the virtual instance 5111 generates the confidential computing requirements and sends the requirements to the enclave virtual instance 5112 for processing.

[0064] Since the tenant may log in to the virtual instance 5111, in this embodiment of the present application, the virtual instance 5111 may be referred to as the tenant virtual instance. As shown in FIG. 3, the operating procedure of the trusted execution system is as follows:

[0065] Step S301: Tenant virtual instance 5111 sends calculation request 1 to enclave virtual instance 5112 via communication channel 100.

[0066] When the tenant generates confidential computing requirements for virtual instance 5111, virtual instance manager 5113 receives the requirements and sends them to enclave virtual instance 5112 via communication channel 100. Communication channel 100 is a communication channel established by virtual instance manager 5113 between tenant virtual instance 5111 and enclave virtual instance 5112 and is used to transmit data information between tenant virtual instance 5111 and enclave virtual instance 5112.

[0067] Step S302: Secure module device 5116 obtains authentication information 1 from cloud management platform client 5114.

[0068] Note that when tenant virtual instance 5111 sends calculation request 1 to enclave virtual instance 5112 via communication channel 100, it should be noted that calculation request 1 is sent to enclave virtual instance 5112 via virtual instance manager 5113. In this case, secure module device 5116 in virtual instance manager 5113 can know that tenant virtual instance 5111 has sent calculation request 1.

[0069] Therefore, the secure module device 5116 obtains the authentication information 1 corresponding to the tenant virtual instance 5111 from the cloud management platform client 5114. Specifically, before purchasing the tenant virtual instance 5111 on the cloud management platform 10, the tenant registers some relevant personal information. The content of the personal information is, for example, the account registered by the tenant on the cloud management platform 10, the mobile phone number, the email address, and / or the login password. The personal information is stored on the cloud management platform 10. Before performing confidential computing, the secure module device 5116 obtains the tenant's personal information from the cloud management platform 10 via the cloud management platform client 5114, and the personal information is used as the authentication information 1 for tenant identity identification.

[0070] Step S303: The secure module device 5116 returns the obtained authentication information 1 to the enclave virtual instance 5112.

[0071] After the secure module device 5116 obtains the tenant's authentication information 1 from the cloud management platform 10 via the cloud management platform client 5114, the cloud management platform 10 returns the tenant's authentication information 1 to the secure module device 5116 via the cloud management platform client 5114, and then the secure module device 5116 returns the obtained authentication information 1 to the enclave virtual instance 5112.

[0072] Specifically, after being created, the enclave virtual instance 5112 reserves the tenant's authentication information 1. After receiving the tenant's confidential computing request, the enclave virtual instance 5112 needs to verify whether the tenant's identity is valid. In this case, the enclave virtual instance 5112 determines whether to perform confidential computing by comparing whether the reserved authentication information 1 of the tenant matches the authentication information 1 of the tenant obtained by the secure module device 5116 from the cloud management platform 10 via the cloud management platform client 5114. If the reserved authentication information 1 matches the obtained authentication information 1, the enclave virtual instance 5112 continues to execute the confidential computing request. If the reserved authentication information 1 does not match the obtained authentication information 1, the enclave virtual instance 5112 rejects the execution of the confidential computing request.

[0073] Step S304: The enclave virtual instance 5112 calls the virtual function VF or physical function PF of the hardware accelerator device 5122 via the communication channel 200 to perform calculations.

[0074] In this step, when it is determined through comparison that the authentication information 1 of the tenant reserved by the enclave virtual instance 5112 matches the authentication information 1 of the tenant obtained by the secure module device 5116 from the cloud management platform 10 via the cloud management platform client 5114, the enclave virtual instance 5112 calls the virtual function VF or physical function PF of the hardware accelerator device via the communication channel 200 to perform calculations. The communication channel 200 is a communication channel established by the secure module device 5116 between the enclave virtual instance 5112 and the hardware accelerator device 5122 according to the PCIe protocol and is used for the data information between the enclave virtual instance 5112 and the hardware accelerator device 5122.

[0075] The virtual function (VF) or physical function (PF) of the hardware accelerator device 5122 is directly passed through to the enclave virtual instance 5112 according to the Peripheral Component Interconnect Express (PCIe) protocol. FIG. 4 is a diagram of the structure for implementing the virtual function VF or physical function PF by the hardware accelerator device 5122 according to an embodiment of the present application. The hardware accelerator device 5122 may be divided into a plurality of functional modules that implement virtual functions VF1, VF2, ..., and VFn. The VF may be mounted to different enclave virtual instances to perform acceleration calculations for different enclave virtual instances. Similarly, the hardware accelerator device 5122 may be divided into a plurality of functional modules that implement physical functions PF1, PF2, ..., and PFn. The PF may be mounted to different enclave virtual instances to perform acceleration calculations for different enclave virtual instances.

[0076] For example, VF1 may be mounted to the enclave virtual instance 5112.

[0077] Note that each VF unit or PF unit is a computing function unit obtained from the hardware accelerator device 5122 through division according to the SRIOV protocol. The units are isolated from each other, and each unit may be mounted to a virtual instance by using a pass-through technique for direct use.

[0078] Step S305: The hardware accelerator device 5122 returns the calculation result 1 to the enclave virtual instance 5112.

[0079] After the calculation is completed, the hardware accelerator device 5122 transmits the calculation result 1 to the enclave virtual instance 5112 via the communication channel 200.

[0080] Step S306: Next, the enclave virtual instance 5112 returns the calculation result 1 to the tenant virtual instance 5111.

[0081] The enclave virtual instance 5112 transmits the calculation result 1 to the tenant virtual instance 5111 via the communication channel 100. In this way, the entire confidential calculation process is completed.

[0082] In this embodiment of the present application, the trusted execution system may perform efficient confidential calculations on the calculation requests transmitted by the tenant virtual instance. After the calculation request of the tenant virtual instance is transmitted to the enclave virtual instance, the enclave virtual instance calls the hardware accelerator device in the hardware pass-through mode for calculation and returns the result to the enclave virtual instance. Next, the enclave virtual instance returns the calculation result to the tenant virtual instance. The enclave virtual instance calls the hardware accelerator device for calculation, as a result, the resources in the host machine are not additionally occupied, and the impact on the service performance of the host machine is reduced.

[0083] FIG. 5 is another diagram of a cloud technology-based trusted execution system according to an embodiment of the present application. As shown in FIG. 5, the difference between the trusted execution system and the embodiment shown in FIG. 2 is that the secure module device 5116 provides a software development kit (SDK) for the enclave virtual instance 5112, and the enclave virtual instance 5112 calls the hardware accelerator device 5122 by using the software development kit SDK for calculation.

[0084] Currently, the secure module device 5116 provides a limited interface function mainly including DescribePCR (for viewing the specified PCR value), ExtendPCR (for PCR extension operation), LockPCRs (for locking the specified PCR), DescribeNSM (for querying the NSM device status), GetAttestationDoc (for obtaining the attestation document), and GetRandom (for obtaining random numbers). The interface function of the secure module device 5116 can be extended by using the software development kit SDK. As a result, the secure module device 5116 has a hardware-accelerated interface function.

[0085] Specifically, the operation procedure of the trusted execution system shown in FIG. 5 may be described with reference to FIG. 6. FIG. 6 is another diagram of data exchange of the cloud technology-based trusted execution system according to an embodiment of the present application. As shown in FIG. 6, the operation procedure of the trusted execution system is as follows:

[0086] Step S601: The tenant virtual instance 5111 sends a calculation request 2 to the enclave virtual instance 5112 via the communication channel 100.

[0087] Step S602: The secure module device 5116 obtains the authentication information 2 from the cloud management platform client 5114.

[0088] Step S603: The secure module device 5116 returns the obtained authentication information 2 to the enclave virtual instance 5112.

[0089] For the specific implementation forms of steps S601 to S603, please refer to the descriptions of steps S301 to S303 in FIG. 3. Details will not be described again here.

[0090] Step S604: The enclave virtual instance 5112 calls the hardware accelerator device 5122 via the communication channel 200 to perform calculations.

[0091] In this embodiment, the communication channel 200 is a communication channel established by the secure module device 5116 between the enclave virtual instance 5112 and the hardware accelerator device 5122 based on the software development kit (SDK), and is used for data information between the enclave virtual instance 5112 and the hardware accelerator device 5122. Based on the software development kit (SDK), the secure module device 5116 has the interface function of hardware acceleration. As a result, the enclave virtual instance 5112 may call the hardware accelerator device 5122 to perform calculations.

[0092] Step S605: The hardware accelerator device 5122 returns the calculation result 2 to the enclave virtual instance 5112.

[0093] Step S606: Next, the enclave virtual instance 5112 returns the calculation result 2 to the tenant virtual instance 5111.

[0094] For the specific implementation forms of steps S605 and S606, please refer to the descriptions of steps S305 and S306 in FIG. 3. Details are not described again here.

[0095] In this embodiment of the present application, the enclave virtual instance in the trusted execution system upgrades the function of calling the hardware accelerator device to perform calculations by installing the SDK. As a result, the function can be extended based on the original function of the secure module device. Therefore, the operational difficulty of the function upgrade of the enclave virtual instance can be reduced.

[0096] Figure 7 is another diagram of a cloud technology-based trusted execution system according to an embodiment of the present application. As shown in Figure 7, the difference between the trusted execution system and the embodiment shown in Figure 2 is that the virtual instance manager 5113 provides an accelerator device 5117 for the enclave virtual instance 5112, and the accelerator device 5117 sends a calculation request to the hardware accelerator device 5122 for calculation.

[0097] Specifically, the operation procedure of the trusted execution system shown in Figure 7 may be described with reference to Figure 8. Figure 8 is another diagram of data exchange of a cloud technology-based trusted execution system according to an embodiment of the present application. As shown in Figure 8, the operation procedure of the trusted execution system is as follows:

[0098] Step S801: The tenant virtual instance 5111 sends a calculation request 3 to the enclave virtual instance 5112 via the communication channel 100.

[0099] Step S802: The secure module device 5116 obtains the authentication information 3 from the cloud management platform client 5114.

[0100] Step S803: The secure module device 5116 returns the obtained authentication information 3 to the enclave virtual instance 5112.

[0101] For the specific implementation forms of steps S801 to S803, please refer to the description of steps S301 to S303 in Figure 3. The details will not be described again here.

[0102] Step S804: The enclave virtual instance 5112 calls the hardware accelerator device 5122 via the communication channel 200 for calculation.

[0103] In this embodiment, when the enclave virtual instance 5112 is created, the accelerator device 5117 is a virtualized accelerator device configured by the virtual instance manager 5113 for the enclave virtual instance 5112. The communication channel 200 is a communication channel established by the accelerator device 5117 between the enclave virtual instance 5112 and the hardware accelerator device 5122, and is used for data information between the enclave virtual instance 5112 and the hardware accelerator device 5122. When the tenant virtual instance 5111 sends a calculation request 3 to the enclave virtual instance 5112 via the communication channel 100, the calculation request 3 is sent to the enclave virtual instance 5112 via the virtual instance manager 5113. In this case, the accelerator device 5117 in the virtual instance manager 5113 can know that the tenant virtual instance 5111 has sent the calculation request 3. When the enclave virtual instance 5112 determines through comparison that the authentication information 3 of the tenant reserved by the enclave virtual instance 5112 matches the authentication information 3 of the tenant obtained by the secure module device 5116 from the cloud management platform 10 via the cloud management platform client 5114, the accelerator device 5117 sends the calculation request 3 to the hardware accelerator device 5122 for calculation in order to complete the process of the enclave virtual instance 5112 calling the hardware accelerator device 5122. Step S805: The hardware accelerator device 5122 returns the calculation result 3 to the enclave virtual instance 5112.

[0104] Step S806: Next, the enclave virtual instance 5112 returns the calculation result 3 to the tenant virtual instance 5111.

[0105] For the specific implementation forms of steps S805 and S806, please refer to the descriptions of steps S305 and S306 in FIG. 3. Details will not be described again here.

[0106] In this embodiment of the present application, the virtual instance manager in the trusted execution system configures a virtual accelerator device for the enclave virtual instance, and the accelerator device sends the computation requests of the tenant virtual instance to the hardware accelerator device for computation. As a result, the enclave virtual instance has a hardware accelerator function.

[0107] FIG. 9 is another view of a cloud technology-based trusted execution system according to an embodiment of the present application. As shown in FIG. 9, the difference between the trusted execution system and the embodiment shown in FIG. 2 is that the trusted execution system includes two tenant virtual instances 5111 and 6111, two enclave virtual instances 5112 and 6112, and a hardware accelerator device 5122. A communication channel 100 is set up between tenant virtual instance 5111 and enclave virtual instance 5112, and a communication channel 300 is set up between tenant virtual instance 6111 and enclave virtual instance 6112. The communication channel 100 (300) is a communication channel established by virtual instance manager 5113 between tenant virtual instance 5111 (6111) and enclave virtual instance 5112 (6112), and is used to transmit data information between tenant virtual instance 5111 (6111) and enclave virtual instance 5112 (6112). Tenant virtual instance 5111, tenant virtual instance 6111, enclave virtual instance 5112, and enclave virtual instance 6112 all operate on host machine operating system 5115. A communication channel 200 is set up between enclave virtual instance 5112 and hardware accelerator device 6122, and a communication channel 400 is set up between enclave virtual instance 6122 and hardware accelerator device 5122. The communication channel 200 (400) is a communication channel established by secure module device 5116 between enclave virtual instance 5112 (6112) and hardware accelerator device 5122, and is used for data information between enclave virtual instance 5112 (6112) and hardware accelerator device 5122. Tenant virtual instance 5111 sends a computation request to enclave virtual instance 5112 via communication channel 100.The enclave virtual instance 5112 calls the virtual function VF1 of the hardware accelerator device 5122 via the communication channel 200 to perform calculations, and then returns the calculation results to the tenant virtual instance 5111 via the communication channel 100. The tenant virtual instance 6111 sends a calculation request to the enclave virtual instance 6112 via the communication channel 300. The enclave virtual instance 6112 calls the virtual function VF2 of the hardware accelerator device 5122 via the communication channel 400 to perform calculations, and then returns the calculation results to the tenant virtual instance 6111 via the communication channel 200. That is, the trusted execution system can meet the requirement of performing confidential calculations simultaneously by multiple virtual tenant instances.

[0108] Optionally, the trusted execution system may alternatively be implemented by using a computer cluster including a plurality of computer devices. This is not limited in the embodiments of the present invention.

[0109] Furthermore, an embodiment of the present invention further provides a computer storage medium including computer-readable instructions. When the computer-readable instructions are executed, the method performed by the trusted execution system is implemented.

[0110] An embodiment of the present invention further provides a computer program product including instructions. When the computer program product operates on a computer, the computer is enabled to perform the method performed by the trusted execution system.

[0111] Based on the description of the foregoing embodiments, those skilled in the art can clearly understand that the present invention can surely be implemented by using software in addition to the general-purpose hardware required, or by using dedicated hardware including dedicated integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, all functions completed by a computer program can be easily implemented by using corresponding hardware, and the specific hardware structure used to implement the same function may be in various forms, such as in the form of analog circuits, digital circuits, or dedicated circuits. However, in the present invention, in many cases, the implementation of software programs is a better implementation. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, may be implemented in the form of software products. The computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, removable hard disk, ROM, RAM, magnetic disk, or optical disk, and includes several instructions for instructing a computer device (which may be a personal computer, training device, or network device, etc.) to perform the method in the embodiments of the present invention.

[0112] All or part of the above embodiments may be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of computer program products.

[0113] A computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, procedures or functions according to embodiments of the present invention are completely or partially generated. The computer may be a general-purpose computer, a dedicated computer, a computer network, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a certain website, computer, training device, or data center to another website, computer, training device, or data center by means of a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, or microwave) method. The computer-readable storage medium may be any usable medium accessible by a computer or a data storage device integrating one or more usable media, such as a training device or a data center. The usable medium may be a magnetic medium (e.g., floppy disk, hard disk, or magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)), etc.

Explanation of Signs

[0114] 1 Cloud data center 10 Cloud management platform 20 Internal network of the data center 30 Internet 40 Client 51 Host machine 511 Software layer 5111 Tenant virtual instance 5112 Enclave virtual instance 5113 Virtual instance manager 5114 Cloud management platform client 5115 Host Machine Operating System 5116 Secure Module Device 5117 Accelerator Device 512 Hardware Layer 5121 Memory 5122 Hardware Accelerator Device 5123 Processor 5124 Network Interface Card 5125 Bus 52 Host Machine 5224 Network Interface Card 6111 Tenant Virtual Instance 6112 Enclave Virtual Instance 100, 200, 300, 400 Communication Channels

Claims

1. A cloud technology-based trusted execution system comprising a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device, wherein a first communication channel is set up between the first tenant virtual instance and the first enclave virtual instance, and a second communication channel is set up between the first enclave virtual instance and the hardware accelerator device, the first tenant virtual instance is configured to send a first calculation request to the first enclave virtual instance via the first communication channel, the first enclave virtual instance is configured to receive the first calculation request, call the hardware accelerator device based on the first calculation request via the second communication channel for performing calculations, and send a first calculation result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel, a system.

2. A first virtual function VF or a first physical function PF of the hardware accelerator device is directly passed through to the first enclave virtual instance according to a Peripheral Component Interconnect Express (PCIe) protocol, the second communication channel is a pass-through channel based on the PCIe protocol, and the first enclave virtual instance is configured to call the first virtual function VF or the first physical function PF of the hardware accelerator device for performing calculations, The system according to claim 1.

3. further comprising a virtual instance manager, the virtual instance manager is configured to provide a secure module device, the secure module device is configured to obtain calculation request authentication information and provide the authentication information for the first enclave virtual instance, The system according to claim 1 or 2.

4. the secure module device is further configured to set up the second communication channel between the first enclave virtual instance and the hardware accelerator device and provide a software development kit (SDK) for the first enclave virtual instance, The first enclave virtual instance is further configured to call the second communication channel based on the SDK to transmit calculation-related data from the second communication channel to the hardware accelerator device. The system according to claim 3.

5. The virtual instance manager is further configured to provide an accelerator device. The accelerator device is configured to set up the second communication channel between the first enclave virtual instance and the hardware accelerator device. The first enclave virtual instance is further configured to transmit calculation-related data to the hardware accelerator device via the second communication channel. The system according to claim 3.

6. The system further includes a second tenant virtual instance and a second enclave virtual instance, a third communication channel is set up between the second tenant virtual instance and the second enclave virtual instance, and a fourth communication channel is set up between the second enclave virtual instance and the hardware accelerator device. The second tenant virtual instance is configured to transmit a second calculation request to the second enclave virtual instance via the third communication channel. The second enclave virtual instance receives the second calculation request, and in order to perform calculations, calls a second virtual function VF or a second physical function PF of the hardware accelerator device based on the second calculation request via the fourth communication channel, and transmits the calculation result generated by the hardware accelerator device to the second tenant virtual instance via the third communication channel. The second virtual function VF or the second physical function PF of the hardware accelerator device is directly passed through to the second enclave virtual instance according to the Peripheral Component Interconnect Express (PCIe) protocol, and the fourth communication channel is a pass-through channel based on the PCIe protocol. The system according to any one of claims 2 to 5.

7. The system according to any one of claims 1 to 6, wherein the first tenant virtual instance and the first enclave virtual instance operate on a host machine, and the hardware accelerator device is inserted into a main board slot of the host machine.

8. The system according to claim 7, wherein the hardware accelerator device is a smart card having an independent operating system, memory, and processor.

9. The system according to any one of claims 1 to 6, wherein the first tenant virtual instance and the first enclave virtual instance operate on a host machine, and the host machine is connected to the hardware accelerator device via a PCIe bus.

10. The system according to any one of claims 1 to 9, wherein the calculation includes one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation.

11. A cloud technology-based trusted execution method, the method being applied to a trusted execution system, the trusted execution system comprising a first tenant virtual instance, a first enclave virtual instance, and a hardware accelerator device, a first communication channel being set between the first tenant virtual instance and the first enclave virtual instance, a second communication channel being set between the first enclave virtual instance and the hardware accelerator device, the method comprising the following steps, namely, sending, by the first tenant virtual instance, a first calculation request to the first enclave virtual instance via the first communication channel; receiving, by the first enclave virtual instance, the first calculation request, invoking the hardware accelerator device based on the first calculation request via the second communication channel for performing a calculation, and sending a first calculation result generated by the hardware accelerator device to the first tenant virtual instance via the first communication channel and including.

12. The first virtual function VF or the first physical function PF of the hardware accelerator device is directly passed through to the first enclave virtual instance according to the Peripheral Component Interconnect Express (PCIe) protocol, the second communication channel is a pass-through channel based on the PCIe protocol, and the first enclave virtual instance calls the first virtual function VF or the first physical function PF of the hardware accelerator device to perform calculations. The method according to claim 11. **Claim 13** The system further includes a virtual instance manager configured to provide a secure module device, and the method includes: obtaining calculation request authentication information by the secure module device and providing the authentication information for the first enclave virtual instance The method according to claim 11 or 12, further including this step. **Claim 14** The method includes: configuring, by the secure module device, the second communication channel between the first enclave virtual instance and the hardware accelerator device, and providing a software development kit (SDK) for the first enclave virtual instance; and invoking, by the first enclave virtual instance, the second communication channel based on the SDK to transmit calculation-related data from the second communication channel to the hardware accelerator device The method according to claim 13, further including these steps. **Claim 15** The virtual instance manager is further configured to provide an accelerator device, and the method includes: configuring, by the accelerator device, the second communication channel between the first enclave virtual instance and the hardware accelerator device; and transmitting, by the first enclave virtual instance, calculation-related data to the hardware accelerator device via the second communication channel The method according to claim 13, further including these steps. **Claim 16** The system further comprises a second tenant virtual instance and a second enclave virtual instance, a third communication channel is set up between the second tenant virtual instance and the second enclave virtual instance, a fourth communication channel is set up between the second enclave virtual instance and the hardware accelerator device, and the method comprises: sending, by the second tenant virtual instance, a second calculation request to the second enclave virtual instance via the third communication channel; receiving, by the second enclave virtual instance, the second calculation request, and in order to perform calculations, invoking a second virtual function VF or a second physical function PF of the hardware accelerator device based on the second calculation request via the fourth communication channel, and sending the calculation result generated by the hardware accelerator device to the second tenant virtual instance via the third communication channel, wherein the second virtual function VF or the second physical function PF of the hardware accelerator device is directly passed through to the second enclave virtual instance according to the peripheral component interconnect express PCIe protocol, and the fourth communication channel is a pass-through channel based on the PCIe protocol; The method according to any one of claims 12 to 15, further comprising.

17. The method according to any one of claims 11 to 16, wherein the first tenant virtual instance and the first enclave virtual instance operate on a host machine, and the hardware accelerator device is inserted into a main board slot of the host machine.

18. The method according to claim 17, wherein the hardware accelerator device is a smart card having an independent operating system, memory, and processor.

19. The method according to any one of claims 11 to 16, wherein the first tenant virtual instance and the first enclave virtual instance operate on a host machine, and the host machine is connected to the hardware accelerator device via a PCIe bus.

20. The calculation includes one or any combination of data encryption calculation, data decryption calculation, data encoding calculation, data decoding calculation, data compression calculation, and data decompression calculation, and is the method according to any one of claims 11 to 19.

21. A computer device, comprising a processor and a memory, the memory is configured to store computer-executable instructions, the processor is configured to execute the computer-executable instructions stored in the memory to enable the computer device to operate a first tenant virtual instance and a first enclave virtual instance so as to implement the method according to any one of claims 11 to 20, Computer device.

22. A computer storage medium including computer-readable instructions, wherein when the computer-readable instructions are executed, a first tenant virtual instance and a first enclave virtual instance are caused to operate so as to implement the method according to any one of claims 11 to 20.

23. A computer program product including instructions, wherein when the computer program product operates on a computer, the computer is enabled to operate a first tenant virtual instance and a first enclave virtual instance so as to perform the method according to any one of claims 11 to 20.

Citation Information

Patent Citations

  • Configurable logic platform having multiple reconfigurable regions - Patent Application 20070122999

    JP2019530100A

  • Method, apparatus, and computer program for protecting information in a secure processor-based cloud computing environment

    JP2021500669A

  • Systems and methods for hypervisor-assisted hardware accelerator offloads in a virtualized information handling system environment

    US20180336052A1

  • Unifying hardware trusted execution environment technologies using virtual secure enclave device

    US20210133315A1