Data processing method, apparatus, device and storage medium
A trusted execution environment-based data processing method addresses the challenge of secure data management in third-party cloud environments by encrypting virtual mirroring files and using decryption keys, ensuring secure data management and transmission.
Patent Information
- Application Number
- JP2025508667
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-06-09
- Filing Date
- 2024-06-06
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2044-06-06
AI Technical Summary
The challenge of achieving secure and reliable data management in third-party cloud environments, where data leakage risks are high due to the untrustworthiness of cloud environments provided by third-party companies.
Implementing a data processing method based on a trusted execution environment, where a host device determines a metric value describing a target virtual machine and transmits it to a client device, receiving a decryption key to decrypt a virtual mirroring file and launch the virtual machine, ensuring secure data management through encrypted virtual mirroring files.
This approach enhances data processing security by utilizing a trusted execution environment, providing secure data management and transmission, ensuring data protection at every stage of its lifecycle, including storage, transmission, and processing.
Smart Images

Figure 0007813412000001 
Figure 0007813412000002 
Figure 0007813412000003
Abstract
Description
[Technical Field]
[0001] This application claims priority to a Chinese patent application for invention entitled "Data Processing Method, Apparatus, Device and Storage Medium" filed on June 9, 2023, with filing date 202310687091X, the entire contents of which are incorporated herein by reference.
[0002] FIELD OF THE DISCLOSURE Exemplary embodiments of the present disclosure relate generally to the field of computers, and more particularly to a data processing method, apparatus, device, and computer-readable storage medium based on a trusted execution environment. [Background technology]
[0003] With the development of cloud technology, more and more individuals, companies, and organizations tend to upload and manage their data in the cloud. However, building a secure and reliable cloud environment requires specialized technical personnel and significant software and hardware costs. Therefore, these individuals, companies, and organizations typically manage their data through cloud environments provided by third-party companies. However, cloud environments provided by third-party companies are unreliable. In this case, how to achieve secure and reliable data management in a third-party cloud environment is an urgent technical issue that needs to be resolved. Summary of the Invention
[0004] In a first aspect of the present disclosure, a data processing method based on a trusted execution environment is provided, comprising: determining, at a host device, a first metric value describing a target virtual machine hosted on the host device based on a first parameter set; transmitting the first metric value to a client device via a trusted execution environment component of the host device; receiving from the client device via the trusted execution environment component a decryption key for decrypting a first virtual mirroring file of the target virtual machine; and executing the first virtual mirroring file based on the decryption key to launch the target virtual machine.
[0005] In a second aspect of the present disclosure, a data processing method based on a trusted execution environment is provided, comprising: receiving, at a client device, from a trusted execution environment component of a host device, a first metric value describing a target virtual machine hosted on the host device; determining a second metric value describing a desired virtual machine of the client device based on a second parameter set; and, in response to the second metric value matching the first metric value, sending a decryption key to the trusted execution environment component of the host device for decrypting a first virtual mirroring file of the target virtual machine.
[0006] In a third aspect of the present disclosure, a data processing device based on a trusted execution environment is provided, comprising: a first metric value generation module configured to determine a first metric value describing a target virtual machine hosted on a host device based on a first parameter set; a first metric value transmission module configured to transmit the first metric value to a client device via a trusted execution environment component of the host device; a decryption key receiving module configured to receive a decryption key for decrypting a first virtual mirroring file of the target virtual machine from the client device via the trusted execution environment component; and a first virtual mirroring file execution module configured to execute the first virtual mirroring file based on the decryption key to launch the target virtual machine.
[0007] In a fourth aspect of the present disclosure, a data processing device based on a trusted execution environment is provided, comprising: a first metric value receiving module configured to receive, from a trusted execution environment component of a host device, a first metric value describing a target virtual machine hosted on the host device; a second metric value generating module configured to determine, based on a second metric value set, a second metric value describing a desired virtual machine of the client device; and a decryption key sending module that, in response to the second metric value matching the first metric value, sends a decryption key to the trusted execution environment component of the host device for decrypting a first virtual mirroring file of the target virtual machine.
[0008] In a fifth aspect of the present disclosure, there is provided an electronic device comprising at least one processing unit and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the electronic device to perform a method according to the first or second aspect.
[0009] In a sixth aspect of the present disclosure, there is provided a computer-readable storage medium having stored thereon a computer program that is executed by a processor to implement the method according to the first or second aspect.
[0010] It should be understood that the contents of this Summary are not intended to define key features or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will be readily apparent from the following description. [Brief explanation of the drawings]
[0011] These and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent from the following detailed description taken in conjunction with the drawings, in which like or similar reference numerals indicate like or similar elements.
[0012] [Figure 1A] FIG. 1 is a schematic diagram illustrating an example environment in which embodiments of the present disclosure can be implemented. [Figure 1B] FIG. 1 is a schematic diagram illustrating an example environment in which embodiments of the present disclosure can be implemented. [Figure 2] FIG. 2 is a signaling interaction diagram of a data processing method according to some embodiments of the present disclosure. [Figure 3A] FIG. 1 is a block diagram illustrating a data processing method according to some embodiments of the present disclosure. [Figure 3B] FIG. 1 is a block diagram illustrating a data processing method according to some embodiments of the present disclosure. [Figure 4] 10 is a flowchart illustrating data processing steps performed by a host device according to some embodiments of the present disclosure. [Figure 5] 10 is a flowchart illustrating data processing steps performed by a client device according to some embodiments of the present disclosure. [Figure 6]1 is a schematic structural block diagram illustrating a data processing apparatus according to some embodiments of the present disclosure. [Figure 7] FIG. 1 is a schematic structural block diagram illustrating another data processing apparatus according to some embodiments of the present disclosure. [Figure 8] FIG. 1 is a block diagram illustrating an electronic device in which one or more embodiments of the present disclosure can be implemented. DETAILED DESCRIPTION OF THE INVENTION
[0013]
[0023] The embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the drawings show several embodiments of the present disclosure, it should be understood that the present disclosure can be realized in various forms and should not be construed as being limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of the present disclosure.
[0014] In describing embodiments of the present disclosure, the term "comprises" and similar expressions should be understood as open-ended, meaning "including, but not limited to." The term "based on" should be understood as "based at least in part on." The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment." The term "some embodiments" should be understood as "at least some embodiments." Other explicit and implicit definitions are included below.
[0015] In this specification, unless explicitly stated otherwise, performing a step "in response to A" does not mean performing the step immediately after "A", but may include one or more intermediate steps.
[0016] As can be understood, the data related to this technical solution (including but not limited to the data itself, the acquisition or use of the data) must comply with the requirements of relevant laws and regulations.
[0017] As can be understood, before using the technical solutions disclosed in each embodiment of the present disclosure, the types, scope of use, and use scenarios of personal information related to the present disclosure should be notified to users in an appropriate manner in accordance with relevant laws and regulations, and their permission should be obtained.
[0018] For example, in response to receiving an active request from a user, prompt information is sent to the user to clearly remind the user that the operation to be performed requires the acquisition and use of the user's personal information, so that the user can independently choose whether to provide personal information to software or hardware, such as an electronic device, application, server, or storage medium, that performs the operation of the technical solution of the present disclosure, based on the prompt information.
[0019] As an optional, non-limiting example, in response to a user's active request, the user may be sent a form of prompt information, such as a pop-up window, that is displayed in text form in the pop-up window, and the pop-up window may also display a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0020] As can be appreciated, the above notification and user authentication processes are merely exemplary and are not intended to limit the scope of the present invention, and other methods that comply with relevant regulations may also be applied to the scope of the present invention.
[0021] As explained above, with the development of cloud technology, more and more individuals, companies, and organizations tend to upload and manage their data in the cloud. However, because building a secure and reliable cloud environment requires specialized technical personnel and significant software and hardware costs, these individuals, companies, and organizations typically manage their data through cloud environments provided by third-party companies. However, because the cloud environments provided by third-party companies are not completely trustworthy, there is a risk of data leakage when using cloud environments provided by third-party companies to manage data.
[0022] In light of this, how to achieve safe and reliable data management in a third-party cloud environment is an urgent technical challenge that needs to be resolved now.
[0023] An embodiment of the present disclosure proposes a data processing scheme based on a trusted execution environment, in which a host device determines a first metric value describing a target virtual machine hosted on the host device based on a first parameter set, the host device transmits the first metric value to a client device via a trusted execution environment component, and the host device receives a decryption key for decrypting the first virtual mirroring file of the target virtual machine from the client device via the trusted execution environment component, and executes the first virtual mirroring file to launch the target virtual machine based on the decryption key.
[0024] This improves the security of the data processing environment by utilizing a trusted execution environment and encrypted virtual mirroring files.
[0025] Example Environment 1A is a schematic diagram illustrating an example environment 100A in which an embodiment of the present disclosure can be implemented. As shown in FIG. 1A, the example environment 100A includes a host device 110 and a client device 120 of a user 140.
[0026] 1A , host device 110 has a trusted execution environment 115 deployed therein. A virtual machine 112, which may be referred to as a target virtual machine 112 or a launched virtual machine 112, executes in trusted execution environment 115. Using the virtual machine executing in trusted execution environment 115, client device 120 can perform data management, i.e., manage and maintain data 114. Embodiments of the present disclosure are not limited in this respect.
[0027] In some embodiments, client device 120 communicates with host device 110 to facilitate data management. Client device 120 may be any type of mobile, fixed, or portable device, including a mobile phone, desktop computer, laptop computer, notebook computer, netbook computer, tablet computer, media computer, multimedia tablet, personal communication system (PCS) device, personal navigation device, personal digital assistant (PDA), audio / video player, digital camera / camcorder, pointing device, television receiver, radio receiver, e-book device, gaming device, or any combination thereof, and accessories and peripheral devices for these devices, or any combination thereof. In some embodiments, client device 120 may also support any type of user prompting interface (e.g., "wearable" circuitry).
[0028] The host device 110 may be an independent physical server, a server cluster or distributed system consisting of multiple physical servers, or a service cloud server that can provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence. The host device 110 may comprise a computing system / server, such as a main block, an edge computing node, or a computing device in a cloud environment. As an example, the host device 110 is a cloud vendor's host machine.
[0029] A communication connection is established between the host device 110 and the client device 120. The communication connection may be established via wired or wireless means. The communication connection may include a Bluetooth connection, a mobile network connection, a Universal Serial Bus connection, a Wireless Fidelity connection, etc., although embodiments of the present disclosure are not limited in this respect. In embodiments of the present disclosure, the host device 110 and the client device 120 may implement signaling interaction via the communication connection between them.
[0030] To achieve secure data management, corresponding software and hardware configurations are deployed on the host device 110 and the client devices. Figure 1B is a schematic diagram illustrating another example environment 100B in which embodiments of the present disclosure can be implemented. For ease of discussion, the environment 100B will be described with reference to the environment 100A of Figure 1A.
[0031] 1B, host device 110 includes a virtual machine monitor for managing virtual machines running on host device 110. Additionally, host device 110 and client device 120 each include a first virtual mirroring file and a second virtual mirroring file. The virtual mirroring files may also be referred to as virtual machine mirrors or virtual machine mirroring programs.
[0032] In some embodiments, the first and second virtual mirroring files may include database components. Further, in some embodiments, the database components are selected depending on the requirements and usage scenario of the user 140, for example, the database components may be an analytics-focused database type or a data management-focused database type.
[0033] In some examples, the database component includes a database engine, which may be an existing database engine, a later-developed database engine, a user-customized database engine, or a general-purpose database engine, although the present disclosure is not limited in this respect.
[0034] In some embodiments, the first and second virtual mirroring files may further include an authentication component for providing remote authentication services, including, but not limited to, verifying the authenticity of the trusted execution environment and negotiating session keys.
[0035] In some embodiments, the first and second virtual mirroring files may further include an encryption / decryption component that, for example, encrypts processing results and messages generated by the virtual machine 112 and decrypts messages received from the client device 120.
[0036] In some embodiments, the first and second virtual mirroring files may also optionally include a key configuration component that allows user 140 to configure various types of keys used in communications between host device 110 and client device 120 and change keys used to encrypt virtual machine 112, including symmetric and asymmetric keys.
[0037] Also, although not shown, the signature public and private key pair sk s , pk s and the encryption public and private key pair sk e , pk e The system may further include other components, such as a storage component that stores keys such as:
[0038] 1B, host device 110 includes a trusted execution environment component 118. In some embodiments, trusted execution environment component 118 may implement a virtual machine-level trusted execution environment.
[0039] It should be understood that the structure and function of each element in environments 100A and 100B are described for illustrative purposes only and do not imply any limitation on the scope of the present disclosure. In other words, the structure, function, quantity, and linkage relationship of elements in environments 100A and 100B can be changed according to actual needs. The present disclosure is not limited in this respect.
[0040] Exemplary Process 2 is a signaling interaction diagram of a data processing method according to some embodiments of the present disclosure. For ease of discussion, the process 200 will be described with reference to the environment 100A of FIG. 1A and the environment 100B of FIG. 1B, e.g., with reference to the host device 110 and the client device 120.
[0041] According to some embodiments of the present disclosure, a secure data processing environment can be deployed to improve the security of data transmission and use, thereby improving the security of data management, and a fully encrypted database system can be implemented to ensure the security of data at each stage of transmission, use, and storage.
[0042] Next, a detailed description will be given of how to deploy a secure data processing environment and how to utilize the deployed data processing environment to achieve secure data storage, transmission and processing.
[0043] During operation, the host device 110 generates a first metric value (245) based on the first parameter set and transmits the first metric value (250) describing the target virtual machine 112 hosted on the host device 110 to the client device 120 via the trusted execution environment component 118.
[0044] For client device 120, upon receiving the first metric value, client device 120 determines a second metric value (255) that describes the desired virtual machine of client device 120 based on the second set of parameters.
[0045] Next, if the second metric value determined by the client device 120 matches the received first metric value, the trusted execution environment component 118 of the host device 110 sends a decryption key (260) for decrypting the first virtual mirroring file of the target virtual machine 112. Correspondingly, the trusted execution environment component 118 of the host device 110 performs the first virtual mirroring and starts the target virtual machine 112 based on the decryption key.
[0046] In this way, the virtual machine 112 running on the host device 110 is doubly protected by the decryption key established by the user 140 and the trusted execution environment component 118 deployed on the host device 110, thereby improving the security of the data processing environment.
[0047] Furthermore, the first parameter set may include multiple parameters that are strongly related to the target virtual machine 112 so that the first metric value can better describe the target virtual machine 112 hosted on the host device 110. One example of a parameter is a first parameter related to the host device 110. Another example of a parameter is a second parameter related to the first virtual mirroring file. Yet another example of a parameter is a third parameter related to user information of the client device 120.
[0048] It should be understood that the above example parameters are for illustrative purposes only, and that in other embodiments, other example parameters may be used, and the disclosure is not limited in this respect.
[0049] As should be understood, client device 120 generates a second parameter set of second metric values corresponding to the first parameter set. In other words, the parameters included in the first and second parameter sets correspond to each other, and the included parameters must be known in advance by host device 110 and client device 120. Thus, the second parameter set includes multiple parameters that correspond to the first parameter set and are highly related to the desired virtual machine of client device 120. In some embodiments, the second parameter set accordingly includes at least one of a first parameter related to host device 110, a second parameter related to the first virtual mirroring file, and a third parameter related to user information of client device 120.
[0050] In some embodiments, the first virtual mirroring file includes at least one component configured to run automatically upon startup of the target virtual machine 112, example components including, but not limited to, a database component, an authentication component, an encryption / decryption component, and a key setting component.
[0051] In some embodiments, for security reasons, once virtual machine 112 is started, user 140 is prohibited from manipulating virtual machine 112 in any way other than through the virtual mirroring file.
[0052] Generally, different trusted execution environments have different hardware (cores, processors, etc.) requirements. In light of this, in some embodiments, the host device 110 needs to be configured with a hardware configuration that supports the trusted execution environment 118, such as a corresponding kernel version.
[0053] Different deployment methods may be adopted depending on the user 140's different trust levels in the host device 110. In some usage scenarios, when the user 140 has a low trust level in the host device 110, the first virtual mirroring file executed on the host device 110 may be generated by the user 140 himself / herself. Specifically, the client device 120 generates the first virtual mirroring file and encrypts it using, for example, Linux®-based hard disk encryption technology or full disk encryption technology. Then, the client device 120 may send the encrypted first virtual mirroring file (220) to the host device 110.
[0054] Alternatively, in some usage scenarios, the user 140 may at least partially trust the host device 110. In this case, the user 140 may generate a first virtual mirroring file (225) using components pre-deployed by the host device 110, or may generate a first virtual mirroring file using a virtual mirroring file template pre-deployed by the host device 110. In this case, the client device 120 first generates a configuration file (205) indicating software and hardware configuration information required for the first virtual mirroring file or a corresponding virtual mirroring file template, and sends the configuration file to the host device 110. The host device 110 may generate the first virtual mirroring file based on the configuration file. Furthermore, after generating the first virtual mirroring file, the host device 110 may send information (210) about the generated first virtual mirroring file to the client device 120 so that the client device 120 is aware of the execution status of the configuration file.
[0055] Additionally, in some embodiments, to ensure the security of the transmission of the decryption key, the client device 120 and the host device 110 may pre-negotiate a session key (235) before transmitting the decryption key. Specifically, the host device 110 negotiates a first session key with the client device 120 via the trusted execution environment component 118. Then, when transmitting the decryption key, the host device 110 encrypts the decryption key using the first session key. In this way, the security of the transmission of the decryption key is improved.
[0056] Additionally, during the initial interaction phase, the host device 110 may send first authentication information (215) to the client device 120 that authenticates the host device 110. One example of the first authentication information may be a certificate chain, where the root certificate of the certificate chain may be the device's hardware manufacturer and the terminal certificate of the certificate chain may be a pre-generated certificate representing the host device 110. Furthermore, in some embodiments, the first authentication information includes the public key of the host device 110 to be used when communicating with the host device 110.
[0057] In some embodiments, the first authentication information may include the public key of the host device 110 that negotiates the first session key with the client device 120. In other words, the authentication process of the host device 110 is bound to the transmission of the public key of the host device 110. In this case, the client device 120 can obtain the public key of the host device 110 after completing authentication with the host device 110, thereby improving the security and reliability of the transmission of the public key of the host device 110.
[0058] According to some embodiments of the present disclosure, to further improve the security of the launched and running virtual machine 112, the host device 110 may encrypt (230) the first virtual mirroring file in memory via the trusted execution environment component 118.
[0059] To better understand the process of deploying a data processing environment, the process of deploying a data processing environment will be further explained in conjunction with FIGS. 3A and 3B.
[0060] 3A and 3B are block diagrams 300A and 300B illustrating data processing methods according to some embodiments of the present disclosure. For ease of discussion, FIG. 3A and FIG. 3B will be described with reference to the environment 100A of FIG. 1A and the environment 100B of FIG. 1B, for example, by utilizing the host device 100 and the client device 120.
[0061] 3A, the client device 120 obtains first authentication information, such as a certificate chain, from a cloud vendor that authenticates the host device 110. The client device 120 verifies the validity of the first authentication information. If the client device 120 verifies that the first authentication information is correct, the encrypted first virtual mirroring file, which needs to be decrypted by a decryption key, is sent to the host device 110.
[0062] In some embodiments, the client device 120 may perform key negotiation with the trusted execution environment component 118 to negotiate a first session key sk and initiate a request to launch the virtual machine 112. Additionally, the first session key sk may be negotiated based on a Diffie-Hellman key exchange mechanism.
[0063] In some embodiments, the host device 110 deploys the encrypted first virtual mirroring file and encrypts the first virtual mirroring file in memory via the trusted execution environment component 118 .
[0064] Additionally, the trusted execution environment component 118 of the host device 110 generates and transmits a first metric value mr1 to the host device 110, which may also be referred to as a boot metric value.
[0065] In some embodiments, generation of the first metric value mr1 is related to the deployed trusted execution environment 115 / trusted execution environment component 118, i.e., the first metric value mr1 generated by different trusted execution environments 115 / trusted execution environment components 118 is different. In some embodiments, the first metric value mr1 is related to a first parameter related to the host device 110 (e.g., platform configuration information), a second parameter related to the first virtual mirroring file (e.g., first virtual mirroring information), and a third parameter related to user information of the client device 120. As should be understood, the first metric value mr1 may be determined based on any suitable parameters or rules, and the disclosure is not limited in this respect.
[0066] The client device 120 locally obtains the corresponding parameters to obtain the second metric value mr2, also referred to as the desired startup metric value mr2, and examples of parameters for generating the second metric value mr2 include a first parameter related to the host device 110 (such as platform configuration information), a second parameter related to the first virtual mirroring file (information about the first virtual mirroring), and a third parameter related to user information of the client device 120.
[0067] The client device 120 compares the second metric value mr2 with the metric value mr1 sent by the host device 110. If there is a match, it sends the decryption key secret to the host device 110.
[0068] In some embodiments, host device 110 and client device 120 may negotiate a first session key sk. In some embodiments, host device 110 encrypts a decryption key secret with the first session key sk, i.e., Enc(sk, secret), and sends the encrypted decryption key to host device 110.
[0069] The host device 110 receives the encrypted decryption key and decrypts it using the first session key sk to obtain the decryption key secret. The host device 110 may then decrypt the received first virtual mirroring file based on the decryption key secret. Furthermore, the trusted execution environment component 118 of the host device 110 may launch the first virtual mirroring file in encrypted memory. Because the first virtual mirroring file includes at least one component that enables self-launching, after the virtual machine 112 is launched, the client device 120 may use each component deployed in the virtual machine 112, such as a database component, an authentication component, an encryption / decryption component, and a key setting component.
[0070] Further, refer to FIG. 3B. In the example of FIG. 3B, the client device 120 selects a configuration file associated with the virtual mirroring file provided by the provider of the host device 110, such as a kernel version, a database engine, and an encryption / decryption algorithm. The host device 110 generates a corresponding full-disk encrypted mirroring file, i.e., an encrypted first virtual mirroring file, according to the configuration file of the client device 120. In some examples, the full-disk encrypted mirroring key (i.e., the decryption key of the first virtual mirroring file) of the first virtual mirroring file is randomly generated by the corresponding cloud vendor of the host device 110. In some examples, the first virtual mirroring file generated by the host device 110 includes a key configuration component that facilitates the user 140 to subsequently change the decryption key for decrypting the first virtual mirroring file.
[0071] Next, the client device 120 obtains the certificate chain first authentication information from the host device 110. In addition, together with the first authentication information, the host device 110 also provides the client device 120 with information related to the generated first virtual mirroring file.
[0072] The client device 120 verifies the validity of the first authentication information. In some embodiments, if the first authentication information is verified as valid by the client device 120, the client device 120 may perform key negotiation with the trusted execution environment component 118 to negotiate a first session key sk and initiate a request to launch the virtual machine 112. Additionally, the first session key sk may be negotiated based on a Diffie-Hellman key exchange mechanism.
[0073] In some embodiments, the host device 110 deploys the encrypted first virtual mirroring file and encrypts the first virtual mirroring file in memory via the trusted execution environment component 118 .
[0074] Additionally, the trusted execution environment component 118 of the host device 110 generates and transmits a first metric value mr1 to the host device 110. In some embodiments, the generation of the first metric value mr1 is related to the deployed trusted execution environment 115 / trusted execution environment component 118, i.e., the first metric value mr1 generated by different trusted execution environments 115 / trusted execution environment components 118 is different. In some embodiments, the first metric value mr1 is related to a first parameter related to the host device 110 (e.g., platform configuration information), a second parameter related to the first virtual mirroring file (e.g., first virtual mirroring information), and a third parameter related to user information of the client device 120. As should be understood, the first metric value mr1 may be determined based on any suitable parameter or rule, and the disclosure is not limited in this respect. As should be understood, the first metric value mr1 may be determined based on any suitable parameter or rule, and the disclosure is not limited in this respect.
[0075] The client device 120 locally obtains the corresponding parameters to obtain the second metric value mr2, also referred to as the desired startup metric value mr2, and examples of parameters for generating the second metric value mr2 include a first parameter related to the host device 110 (such as platform configuration information), a second parameter related to the first virtual mirroring file (information about the first virtual mirroring), and a third parameter related to user information of the client device 120.
[0076] The client device 120 compares the second metric value mr2 with the metric value mr1 sent by the host device 110. If there is a match, it sends the decryption key secret to the host device.
[0077] In some embodiments, host device 110 and client device 120 may negotiate a first session key sk. In some embodiments, host device 110 encrypts a decryption key secret with the first session key sk, i.e., Enc(sk, secret), and sends the encrypted decryption key to host device 110.
[0078] The host device 110 receives the encrypted decryption key and decrypts it using the first session key sk to obtain the decryption key secret. The host device 110 may then decrypt the received first virtual mirroring file based on the decryption key secret. Furthermore, the trusted execution environment component 118 of the host device 110 may launch the first virtual mirroring file in encrypted memory. Because the first virtual mirroring file includes at least one component that enables self-launching, after the virtual machine 112 is launched, the client device 120 may use each component deployed in the virtual machine 112, such as a database component, an authentication component, an encryption / decryption component, and a key setting component.
[0079] In some embodiments, the first virtual mirroring file includes at least one component that enables self-activation, so the client device 120 first modifies the private key of the full disk of the virtual machine 112 through the key configuration service of the virtual machine 112, and then creates a signature public and private key pair sk s , pk s , encryption public and private key pair sk e , pk e may be set.
[0080] Through the above steps, the trusted execution environment component 118 of the host device 110 starts (265) the virtual machine 112, and a more secure data processing environment can be deployed on the host device 110. Then, the user 140 can realize data management in a more secure manner.
[0081] 2, the trusted execution environment component 118 of the host device 110 may send second authentication information (275) to the client device, the second authentication information including at least one key pair for decrypting the database operation instructions of the client device 120, authenticating the trusted execution environment. Based on the received at least one key pair, the client device 120 may send the encrypted database operation instructions to the host device 110.
[0082] For ease of understanding, how to execute a database manipulation command will be explained in conjunction with the following example operations.
[0083] In some embodiments, the user 140 completes identity authentication through a user management system of the client device 120. Additionally, the user 140 verifies, via an authentication component of the client device 120, whether the virtual machine 112 environment running the database component in the cloud environment is trustworthy.
[0084] In a specific implementation, user 140 sends a single random number, nonce, to virtual machine 112. An authentication component within virtual machine 112 generates second authentication information, also referred to as trusted environment verification data. Along with the second authentication information, the encryption public key pk e、 Signature public key pk s and the signing private key sk s A random number signed by s , nonce) to the client device 120.
[0085] In some embodiments, the second authentication information includes a signature public key pk s、 Encryption public key pk e In this way, it can be ensured that the public key value in the returned information is bound to the trusted execution environment. That is, once the trusted execution environment is verified, the public key information sent along with it is also considered to be trustworthy. In some embodiments, the signature public key pk s , encryption public key pk e as a report data field in the second authentication information.
[0086] The client device 120 verifies whether the second authentication information is correct and sends Sig(sk s If the verification passes, the user 140 may safely use the virtual machine 112.
[0087] In some embodiments, a user 140 sends a database operation instruction via a client device 120. As a specific embodiment, an authorization control module of the client device 120 first determines whether the user has permission to operate on corresponding data, such as a table, a library, etc. If there is no permission, the instruction is directly discarded; otherwise, the client device 120 encrypts the database operation instruction and sends it to the virtual machine 112 via the trusted environment execution component 118.
[0088] In some embodiments, database manipulation instructions are transmitted using double encryption, i.e., Enc(pk e , ssk), Enc(ssk, database operation command), where ssk is a randomly selected session key, and pk e is the encryption public key.
[0089] When the host device 110 receives the request, it first decrypts the database operation command and then sends it to the database component of the virtual machine 112 to perform the database operation. The virtual machine 112 executes the database operation command and sends the operation result (result) to the user.
[0090] Accordingly, to ensure data security, the operation result (Enc(ssk, result)) is also encrypted and sent to the client device 120, where ssk is a randomly selected session key. The client device 120 decrypts it using the session key (ssk) to obtain the data processing result (result).
[0091] As can be seen from the above process, the user 140's decryption key is required to obtain the data contained in the virtual mirroring file. In other words, before the first virtual mirroring file is loaded into memory, all data, including applications, is protected by the user device's mirroring encryption key. After the first virtual mirroring file is loaded into memory, all data operations are performed via the trusted execution environment component. The data is encrypted during transmission, and the key pair for decryption is transmitted along with the trusted execution environment's authentication information. This ensures that there are corresponding security measures in place to protect the data, regardless of whether the data is on disk or in memory, during transmission, or during processing. In other words, data security is guaranteed at every stage of its lifecycle.
[0092] Through the above process, the present disclosure realizes the deployment of a safe and reliable data processing environment in a cloud environment using the virtual machine-level trusted execution environment component 118, which improves data processing performance and system security compared to software implementations. Furthermore, in this environment, users do not need to install a trusted execution environment component or modify existing database components, thereby reducing the deployment cost of the data processing system. Example Method
[0093] 4 is a flowchart illustrating a data processing process 400 according to some embodiments of the present disclosure. For ease of discussion, the discussion will be made with reference to the environments 100A and 100B of FIGS. 1A and 1B. The data processing process 400 is implemented in the host device 110.
[0094] At block 410, the host device determines a first metric value describing a target virtual machine hosted on the host device based on the first parameter set.
[0095] At block 420, the host device transmits the first metric value to the client device via the trusted execution environment component.
[0096] At block 430, the host device receives a decryption key from the client device via the trusted execution environment component to decrypt the first virtual mirroring file of the target virtual machine.
[0097] At block 440, the host device executes the first virtual mirroring file to start the target virtual machine based on the decryption key.
[0098] In some embodiments, the first parameter set includes at least one of a first parameter associated with the host device, a second parameter associated with the first virtual mirroring file, and a third parameter associated with user information of the client device.
[0099] In some embodiments, the host device negotiates with the client device, via the trusted execution environment component, a first session key in which the decryption key is encrypted.
[0100] In some embodiments, the host device transmits first authentication information to the client device that includes a public key of the host device for use in communicating with the host device, the first authentication information authenticating the host device.
[0101] In some embodiments, the host device sends to the client device first authentication information that includes a public key of the host device to negotiate a first session key with the client device, the first authentication information authenticating the host device.
[0102] In some embodiments, the host device encrypts the first virtual mirroring file in memory via a trusted execution environment component.
[0103] In some embodiments, the host device generates a configuration file for generating the first virtual mirroring file from the client device, and generates the first virtual mirroring file based on the configuration file.
[0104] In some embodiments, the host device receives an encrypted first virtual mirroring file from the client device.
[0105] In some embodiments, the first virtual mirroring file includes at least one component including a database component, an authentication component, an encryption / decryption component, and a key setting component, and at least one component configured to be automatically executed upon startup of the target virtual machine.
[0106] In some embodiments, after the target virtual machine is launched, the host device sends second authentication information to the client device via the trusted execution environment component, the second authentication information including at least one key pair for encrypting and decrypting database operation instructions of the client device, the second authentication information authenticating the trusted execution environment.
[0107] 5 is a flowchart illustrating a data processing process 500 according to an embodiment of the present disclosure. For ease of discussion, the discussion will be made with reference to the environments 100A and 100B of FIGS. 1A and 1B. The data processing process 500 is implemented in the client device 120.
[0108] At block 510, the client device receives, from a trusted execution environment component of the host device, a first metric value describing a target virtual machine hosted on the host device.
[0109] At block 520, the client device determines a second metric value describing a desired virtual machine for the client device based on the second parameter set.
[0110] In block 530, the client device sends a decryption key to the trusted execution environment component of the host device to decrypt the first virtual mirroring file of the target virtual machine in response to the second metric value matching the first metric value.
[0111] In some embodiments, the client device receives from the host device first authentication information that includes a public key of the host device for use in communicating with the host device, the first authentication information authenticating the host device.
[0112] In some embodiments, the client device receives from the host device first authentication information that includes a public key of the host device for negotiating a first session key with the host device, the first authentication information authenticating the host device.
[0113] In some embodiments, the second parameter set includes at least one of a first parameter associated with the host device, a second parameter associated with the first virtual mirroring file, and a third parameter associated with user information of the client device.
[0114] In some embodiments, the client device negotiates with a trusted execution environment component of the host device a first session key upon which the decryption key is encrypted.
[0115] In some embodiments, the client device transmits a configuration file to the host device that generates the first virtual mirroring file, and the client device generates the first virtual mirroring file corresponding to the configuration file.
[0116] In some embodiments, the client device transmits an encrypted virtual mirroring file to the host device.
[0117] In some embodiments, after the target virtual machine launches, the client device receives second authentication information from a trusted execution environment component of the host device, the second authentication information including at least one key pair for encrypting and decrypting database operation instructions of the client device, the second authentication information authenticating the trusted execution environment.
[0118] Exemplary Apparatus and Devices 6 is a schematic structural block diagram illustrating a data processing apparatus 600 according to some embodiments of the present disclosure. The apparatus 600 may be implemented as or included in the host device 110. Each block / component in the apparatus 600 may be implemented by hardware, software, firmware, or any combination thereof.
[0119] As shown in FIG. 6, the apparatus 600 includes a first metric value generation module 610 configured to determine a first metric value describing a target virtual machine hosted on the host device based on a first parameter set; a first metric value transmission module 620 configured to transmit the first metric value to a client device via a trusted execution environment component of the host device; a decryption key reception module 630 configured to receive a decryption key for decrypting a first virtual mirroring file of the target virtual machine from the client device via the trusted execution environment component; and a first virtual mirroring file execution module 640 configured to execute the first virtual mirroring file based on the decryption key to launch the target virtual machine.
[0120] In some embodiments, the first parameter set includes at least one of a first parameter associated with the host device, a second parameter associated with the first virtual mirroring file, and a third parameter associated with user information of the client device.
[0121] In some embodiments, the apparatus 600 further comprises a first key negotiation module configured to negotiate, via the trusted execution environment component, with the client device a first session key upon which the decryption key is encrypted.
[0122] In some embodiments, the apparatus 600 further comprises a first authentication information transmission module configured to transmit to the client device first authentication information that includes a public key of the host device for use in communicating with the host device, the first authentication information authenticating the host device.
[0123] Alternatively, in some embodiments, apparatus 600 further comprises a first authentication information transmission module configured to transmit to the client device first authentication information including a public key of a host device that negotiates a first session key with the client device, the first authentication information authenticating the host device.
[0124] In some embodiments, the apparatus 600 further comprises a memory encryption component configured to encrypt the first virtual mirroring file in memory via the trusted execution environment component.
[0125] In some embodiments, the apparatus 600 further comprises a configuration file receiving module configured to receive a configuration file for generating a first virtual mirroring file from a client device and generate the first virtual mirroring file based on the configuration file.
[0126] In some embodiments, the apparatus 600 further comprises a mirroring file receiving module configured to receive the encrypted first virtual mirroring file from the client device.
[0127] In some embodiments, the first virtual mirroring file includes at least one component including a database component, an authentication component, an encryption / decryption component, and a key setting component, and at least one component configured to be automatically executed upon startup of the target virtual machine.
[0128] In some embodiments, the apparatus 600 further comprises a second authentication information transmission module configured to transmit, after the target virtual machine launches, via a trusted execution environment component of the host device to the client device, second authentication information including at least one key pair for encrypting and decrypting database operation instructions of the client device, the second authentication information authenticating the trusted execution environment.
[0129] 7 is a schematic structural block diagram illustrating another data processing apparatus 700 for interface information according to some embodiments of the present disclosure. The apparatus 700 may be implemented as or included in the client device 120. Each block / component in the apparatus 700 may be implemented by hardware, software, firmware, or any combination thereof.
[0130] As shown in FIG. 7, the apparatus 700 includes a first metric value receiving module 710 configured to receive, from a trusted execution environment component of the host device, a first metric value describing a target virtual machine hosted on the host device; a second metric value generating module 720 configured to determine, based on a second metric value set, a second metric value describing a desired virtual machine of the client device; and a decryption key sending module 730 that, in response to the second metric value matching the first metric value, sends a decryption key for decrypting the first virtual mirroring file of the target virtual machine to the trusted execution environment component of the host device.
[0131] In some embodiments, the second parameter set includes at least one of a first parameter associated with the host device, a second parameter associated with the first virtual mirroring file, and a third parameter associated with user information of the client device.
[0132] In some embodiments, the apparatus 700 further comprises a second session key negotiation module configured to negotiate with a trusted execution environment component of the host device a first session key upon which the decryption key is encrypted.
[0133] In some embodiments, the apparatus 700 further comprises a first authentication information receiving module configured to receive, from the host device, first authentication information that includes a public key of the host device for use in communicating with the host device, the first authentication information authenticating the host device.
[0134] Alternatively, in some embodiments, the apparatus 700 further comprises a first authentication information receiving module configured to receive from the host device first authentication information including a public key of the host device for negotiating a first session key with the host device, the first authentication information authenticating the host device.
[0135] In some embodiments, the apparatus 700 further comprises a configuration file transmission module configured to transmit a configuration file to the host device that generates a first virtual mirroring file, and to generate a first virtual mirroring file corresponding to the configuration file at the client device.
[0136] In some embodiments, the apparatus 700 further comprises a mirroring file transmission module configured to transmit the encrypted virtual mirroring file to the host device.
[0137] In some embodiments, the apparatus 700 further comprises a second authentication information receiving module configured to receive, after the target virtual machine is launched, from a trusted execution environment component of the host device, second authentication information including at least one key pair for decrypting database operation instructions of the client device, the second authentication information authenticating the trusted execution environment.
[0138] 8 is a block diagram illustrating an electronic device 800 capable of implementing one or more embodiments of the present disclosure. It should be understood that the electronic device 800 illustrated in FIG. 8 is merely exemplary and does not limit the functionality and scope of the embodiments described herein. The electronic device 800 illustrated in FIG. 8 may be used to implement the client device 120 of FIG. 1A.
[0139] 8, electronic device 800 is a typical form of electronic or computing device. Components of electronic device 800 include, but are not limited to, one or more processors or processing units 810, memory 820, storage device 830, one or more communication units 840, one or more input devices 880, and one or more output devices 860. Processing unit 810 may be a real or virtual processor and can perform various processes according to programs stored in memory 820. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to enhance the parallel processing capabilities of electronic device 800.
[0140] The electronic device 800 typically includes a plurality of computer storage media, which may be any available media accessible to the electronic device 800, including, but not limited to, volatile and nonvolatile media, removable and non-removable media. The memory 820 may be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM)), flash memory, or a combination thereof. The storage device 830 may include, for example, The media may be removable or non-removable and may include machine-readable media such as a flash drive, magnetic disk, or any other medium capable of storing information and / or data (such as training data) and accessible within electronic device 800.
[0141] The electronic device 800 may further include other removable / non-removable media, volatile / non-volatile memory storage media. Although not shown in FIG. 8, a disk drive for reading from or writing to a removable, non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading from or writing to a removable, non-volatile optical disk may also be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data media interfaces. The memory 820 includes a computer program product 825 having one or more program modules configured to perform various methods or operations of each embodiment of the present disclosure.
[0142] The communication unit 840 facilitates communication with other electronic devices over a communication medium. Additionally, the functionality of the components of the electronic device 800 may be implemented as a single computing cluster or as multiple computing machines that can communicate over a communication connection. Thus, the electronic device 800 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or other network nodes.
[0143] The input device(s) 850 may be one or more input devices, such as, for example, a mouse, a keyboard, a trackball, etc. The output device(s) 860 may be one or more output devices, such as, for example, a display, a speaker, a printer, etc. Furthermore, the electronic device 800 may communicate with one or more external devices (not shown) via the communication unit 840 as needed, such as a storage device, a display device, etc., that communicate with one or more devices that allow a user to interact with the electronic device 800, or any device (e.g., a network card, a modem, etc.) that allows the electronic device 800 to communicate with one or more electronic devices. Such communication may be performed by an input / output (I / O) interface (not shown).
[0144] In accordance with an exemplary implementation of the present disclosure, a computer-readable storage medium having stored thereon computer-executable instructions that, when executed by a processor, implement the methods described above is provided. Additionally, in accordance with an exemplary implementation of the present disclosure, a computer program product is provided that includes computer-executable instructions tangibly stored on a non-transitory computer-readable medium and that, when executed by a processor, implements the methods described above.
[0145] Aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatus, devices, and computer program products implemented according to the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, are implemented by computer-readable program instructions.
[0146] These computer-readable program instructions are provided to a processing unit of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus such that, when executed by the processing unit of the computer or other programmable data processing apparatus, a device is created that implements the functions / acts specified in one or more blocks in the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium, and the instructions cause the computer, programmable data processing apparatus, and / or other device to operate in a particular manner, such that the computer-readable medium on which the instructions are stored includes an article of manufacture containing instructions for implementing the functions / acts specified in one or more blocks in the flowcharts and / or block diagrams.
[0147] The computer-readable program instructions are loaded into a computer, other programmable data processing apparatus, or other device to cause the computer, other programmable data processing apparatus, or other device to perform a series of operational steps to produce computer-implemented processes, whereby the instructions executing on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0148] The flowcharts and block diagrams in the accompanying drawings illustrate possible architectures, functions, and operations of systems, methods, and computer program products according to various aspects of the present disclosure. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or part of instructions, including one or more executable instructions capable of implementing a given logical function. In some alternative embodiments, the functions depicted in the blocks may be executed in a different order than that depicted in the figures. For example, two consecutive blocks may actually be executed essentially in parallel, or may be executed in the reverse order depending on the functionality involved. It should be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a system using dedicated hardware that performs a given function or operation, or by a combination of dedicated hardware and computer instructions.
[0149] Although various embodiments of the present disclosure have been described above, the above descriptions are illustrative and not exhaustive, and are not limited to the various embodiments disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the various embodiments described. The terms used in this specification are selected to best explain the principles, practical applications, or improvements to commercially available technologies of the various embodiments, or to enable other skilled in the art to understand the various embodiments disclosed herein.
Claims
1. A data processing method based on a trusted execution environment, comprising: determining, via a trusted execution environment component of the host device, a first metric value for a target virtual machine managed by the host device based on a first set of parameters; transmitting the first metric value to a client device via a trusted execution environment component of the host device; receiving, via the trusted execution environment component, from the client device, a decryption key for decrypting the first virtual mirroring file of the target virtual machine; executing the first virtual mirroring file based on the decryption key to start the target virtual machine; the decryption key was transmitted by the client device to the trusted execution environment component of the host device in response to a second metric value matching the first metric value; the client device determines the second metric value for the virtual machine desired by the client device based on a second set of parameters; the first parameter set corresponds to the second parameter set; Data processing methods.
2. The first parameter set includes: a first parameter associated with the host device; second parameters associated with the first virtual mirroring file; and a third parameter related to user information of the client device; The method of claim 1 , comprising at least one of:
3. 10. The method of claim 1, further comprising negotiating a first session key with the client device via the trusted execution environment component, wherein the decryption key is encrypted with the first session key.
4. 4. The method of claim 3, further comprising: sending to the client device first authentication information including a public key of the host device for negotiating the first session key with the client device, the first authentication information for authenticating the host device.
5. The method of claim 1 , further comprising encrypting the first virtual mirroring file in memory via the trusted execution environment component.
6. receiving a configuration file from the client device for generating the first virtual mirroring file; generating the first virtual mirroring file based on the configuration file; The method of claim 1 further comprising:
7. 2. The method of claim 1, wherein the first virtual mirroring file includes at least one component configured to be automatically executed upon startup of the target virtual machine, and the at least one component includes at least one of a database component, an authentication component, an encryption / decryption component, and a key setting component.
8. After the target virtual machine is launched, the method further includes sending, via the trusted execution environment component, second authentication information to the client device for authenticating the trusted execution environment; The method of claim 1 , wherein the second authentication information includes at least one key pair for encrypting and decrypting database manipulation instructions of the client device.
9. A data processing method based on a trusted execution environment, comprising: receiving, at a client device, from a trusted execution environment component of a host device, a first metric value for a target virtual machine managed by the host device, the first metric value being determined based on a first parameter set via the trusted execution environment component of the host device; determining a second metric value for a virtual machine desired by the client device based on a second set of parameters; and in response to the second metric value matching the first metric value, sending to the trusted execution environment component of the host device a decryption key for decrypting the first virtual mirroring file of the target virtual machine; The first parameter set corresponds to the second parameter set. Data processing methods.
10. 10. The method of claim 9, wherein the second parameter set includes at least one of a first parameter associated with the host device, a second parameter associated with the first virtual mirroring file, and a third parameter associated with user information of the client device.
11. 11. The method of claim 10, further comprising, after the target virtual machine has launched, receiving second authentication information from the trusted execution environment component of the host device for authenticating the trusted execution environment, the second authentication information including at least one key pair for encrypting and decrypting database operation instructions of the client device.
12. A data processing device based on a trusted execution environment, comprising: a first metric value generation module configured to determine, via a trusted execution environment component of a host device, a first metric value for a target virtual machine managed by the host device based on a first parameter set; a first metric value transmission module configured to transmit the first metric value to a client device via a trusted execution environment component of the host device; a decryption key receiving module configured to receive a decryption key for decrypting the first virtual mirroring file of the target virtual machine from the client device via the trusted execution environment component; a first virtual mirroring execution module configured to execute the first virtual mirroring file based on the decryption key to start the target virtual machine; the decryption key was transmitted by the client device to the trusted execution environment component of the host device in response to a second metric value matching the first metric value; the client device determines the second metric value for the virtual machine desired by the client device based on a second set of parameters; The first parameter set corresponds to the second parameter set. Data processing device.
13. A data processing device based on a trusted execution environment, comprising: a first metric value receiving module configured to receive a first metric value for a target virtual machine managed by a host device from a trusted execution environment component of the host device, the first metric value being determined based on a first parameter set via the trusted execution environment component of the host device; a second metric value generation module configured to determine a second metric value for the virtual machine desired by the client device based on the second parameter set; a decryption key transmission module that transmits a decryption key for decrypting a first virtual mirroring file of the target virtual machine to the trusted execution environment component of the host device in response to the second metric value matching the first metric value; The first parameter set corresponds to the second parameter set. Data processing device.
14. at least one processing unit; at least one memory coupled to the at least one processing unit, the memory storing instructions executed by the at least one processing unit; The instructions, when executed by the at least one processing unit, cause the electronic device to perform the method of any one of claims 1 to 11. Electronic devices.
15. A computer-readable storage medium storing a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
AMD SEV-based trusted execution environment architecture and trusted execution system
CN114647487A
Hosting security services in virtual security environment
CN115795511A
Method, system and computer program for generating computation so as to be executed in target trusted execution environment (TEE) (provisioning secure / encrypted virtual machines in cloud infrastructure)
JP2022099293A