Confidential computing environment creation method, cryptographic operation method, cryptographic operation system, electronic device, and storage medium
By using the password module manager and the confidential environment manager in electronic devices, the hardware resources are dynamically configured to match the operating needs of the password module, and the problems of insufficient password computing performance and waste of resources under the limitations of the fixed hardware architecture are solved, achieving more efficient and secure password computing performance.
Patent Information
- Application Number
- PCT/CN2024/096235
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-29
- Filing Date
- 2024-05-30
- Publication Date
- 2025-06-05
AI Technical Summary
In modern computer architecture, the cryptographic computing performance is limited by the processor hardware architecture, especially the fixed number of secure processors cannot be flexibly configured, resulting in insufficient processing capabilities of the cryptographic module and wasted hardware resources, affecting the overall performance.
The password module manager obtains the mirror information of the password module, determines the hardware resources required for its operation, generates a confidential computing environment creation request, and enables the confidential environment manager to create a confidential computing environment that matches the operation requirements of the password module, thereby meeting the performance needs of the password module and avoiding wasting hardware resources.
It realizes dynamic configuration of hardware resources according to the performance requirements of the cryptographic module, improves the overall performance of electronic devices, and ensures the security and efficiency of cryptographic operations.
Smart Images

Figure CN2024096235_05062025_PF_FP_ABST
Abstract
Description
Confidential computing environment creation method, cryptographic operation method, cryptographic operation system, electronic device and storage medium
[0001] This application claims priority to Chinese Patent Application No. 202311617297.1 filed on November 29, 2023, and the contents of the above-mentioned Chinese patent application disclosure are hereby incorporated by reference in their entirety as a part of this application. Technical Field
[0002] The embodiments of the present disclosure relate to a method for creating a confidential computing environment, a cryptographic operation method, a cryptographic operation system, an electronic device, and a storage medium. Background Art
[0003] Cryptography is a technology used to maintain information confidentiality and is widely used in computers. Its primary application involves cryptographic operations, such as encrypting and decrypting data to prevent malicious theft and digitally signing data to ensure its authenticity and security. In modern computer architectures, cryptographic operations can be implemented using specialized cryptographic modules (CMs), which are configured in electronic devices. Against this backdrop, providing technical solutions to improve the overall performance of electronic devices has become a pressing challenge for those skilled in the art.
[0004] Summary of the Invention
[0005] In view of this, the embodiments of the present disclosure provide a method for creating a confidential computing environment, a cryptographic operation method, a cryptographic operation system, an electronic device and a storage medium to improve the overall performance of the electronic device.
[0006] In a first aspect, an embodiment of the present disclosure provides a method for creating a confidential computing environment, which is applied to a cryptographic module manager, comprising:
[0007] Get the image information of the cryptographic module;
[0008] Determining hardware resources required to run the cryptographic module based on the image information of the cryptographic module;
[0009] generating a confidential computing environment creation request based on hardware resources required to run the cryptographic module;
[0010] The confidential computing environment creation request is sent so that the confidential environment manager creates a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request, and the cryptographic module operation requirements are adapted to the hardware resources required to run the cryptographic module.
[0011] Optionally, the determining, based on the image information of the cryptographic module, hardware resources required to run the cryptographic module includes:
[0012] Determining a performance profile of the cryptographic module based on the image information of the cryptographic module;
[0013] Based on the performance profile, the number of processor cores and memory resources required to run the cryptographic module are determined.
[0014] Optionally, the generating a confidential computing environment creation request based on the hardware resources required to run the cryptographic module is specifically: generating a confidential computing environment creation request based on the number of processor cores and memory resources required to run the cryptographic module.
[0015] Optionally, after sending the confidential computing environment creation request, the method further includes:
[0016] The image information of the cryptographic module is sent so that the confidential environment manager loads the image information of the cryptographic module into the created confidential computing environment, so that the cryptographic module runs in the confidential computing environment.
[0017] In a second aspect, an embodiment of the present disclosure provides a method for creating a confidential computing environment, which is applied to a confidential environment manager, comprising:
[0018] Obtaining a confidential computing environment creation request sent by a cryptographic module manager; wherein the confidential computing environment creation request is generated by the cryptographic module manager based on hardware resources required to run the cryptographic module, and the hardware resources required to run the cryptographic module are determined by the cryptographic module manager based on the obtained image information of the cryptographic module;
[0019] Based on the confidential computing environment creation request, a confidential computing environment is created that matches the cryptographic module operation requirements, and the cryptographic module operation requirements are adapted to the hardware resources required to run the cryptographic module.
[0020] Optionally, the confidential computing environment creation request includes the number of processor cores and memory resources required to run the cryptographic module.
[0021] Optionally, creating a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request includes:
[0022] Based on the number of processor cores, allocating a corresponding number of processor cores to the confidential computing environment;
[0023] Based on the memory resources, the corresponding memory addresses are configured to the confidential computing environment.
[0024] Optionally, after creating a confidential computing environment that matches the operating requirements of the cryptographic module, the process further includes:
[0025] Obtain the image information of the cryptographic module sent by the cryptographic module manager, and load the image information of the cryptographic module into the confidential computing environment to run the cryptographic module in the confidential computing environment.
[0026] In a third aspect, an embodiment of the present disclosure provides a cryptographic operation method, which is applied to a confidential computing environment created by the confidential computing environment creation method described in the first aspect and / or the second aspect. The method includes:
[0027] The cryptographic module obtains the key file and obtains a key for cryptographic operations based on the key file;
[0028] The cryptographic application sends a verification request to the cryptographic module to verify the integrity of the cryptographic module;
[0029] If the cryptographic module is complete, the cryptographic application calls the cryptographic module to perform cryptographic operations.
[0030] Optionally, the cryptographic module includes a sealing key;
[0031] The cryptographic module obtains the cryptographic operation key based on the key file specifically as follows: the cryptographic module decrypts the cryptographic file using the sealing key to obtain the cryptographic operation key.
[0032] Optionally, the cryptographic module utilizes a cryptographic operation module to assist in performing cryptographic operations;
[0033] The cryptographic application calls the cryptographic module to perform cryptographic operations, specifically: the cryptographic application calls the cryptographic module; and the cryptographic module uses the cryptographic operation module to perform cryptographic operations.
[0034] In a fourth aspect, an embodiment of the present disclosure provides a cryptographic computing system, comprising at least a cryptographic application, a cryptographic module, a cryptographic module manager, and a confidential environment manager, wherein the cryptographic module manager and the confidential environment manager are configured to create a confidential computing environment that matches the operating requirements of the cryptographic module;
[0035] The cryptographic module is used to obtain a key file in the confidential computing environment and obtain a key for cryptographic operations based on the key file;
[0036] The cryptographic application is used to send a verification request to the cryptographic module in the confidential computing environment to verify the integrity of the cryptographic module; wherein, if the cryptographic module is intact, the cryptographic application calls the cryptographic module to perform cryptographic operations.
[0037] Optionally, the password module manager includes:
[0038] An information acquisition unit, used to acquire image information of the cryptographic module;
[0039] a resource determination unit, configured to determine hardware resources required to run the cryptographic module based on the image information of the cryptographic module;
[0040] a request generating unit, configured to generate a confidential computing environment creation request based on hardware resources required to run the cryptographic module;
[0041] A request sending unit is used to send the confidential computing environment creation request so that the confidential environment manager creates a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request, and the operating requirements of the cryptographic module are adapted to the hardware resources required to run the cryptographic module.
[0042] Optionally, the confidential environment manager includes:
[0043] a request obtaining unit, configured to obtain a confidential computing environment creation request sent by a cryptographic module manager;
[0044] An environment creation unit is used to create a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request.
[0045] Optionally, it also includes: a cryptographic operation module, which is used to assist the cryptographic module in performing cryptographic operations in the confidential computing environment.
[0046] In a fifth aspect, an embodiment of the present disclosure provides an electronic device comprising at least one memory and at least one processor, wherein the memory stores one or more computer-executable instructions, and the processor calls the one or more computer-executable instructions to execute the confidential computing environment creation method as described in the first aspect and / or the second aspect, and / or the cryptographic operation method as described in the third aspect.
[0047] In a sixth aspect, an embodiment of the present disclosure provides a storage medium storing one or more computer-executable instructions. When the one or more computer-executable instructions are executed, the method for creating a confidential computing environment as described in the first aspect and / or the second aspect, and / or the cryptographic operation method as described in the third aspect are implemented.
[0048] The confidential computing environment creation method provided in the embodiment of the present disclosure is applied to a cryptographic module manager, which obtains the image information of the cryptographic module and then determines the hardware resources required to run the cryptographic module based on the image information of the cryptographic module; generates a confidential computing environment creation request based on the hardware resources required to run the cryptographic module; and sends the confidential computing environment creation request so that the confidential environment manager creates a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request, and the operating requirements of the cryptographic module are adapted to the hardware resources required to run the cryptographic module.
[0049] As can be seen, in the disclosed embodiments, the cryptographic module manager determines the hardware resources required to run the cryptographic module based on the cryptographic module's image information and generates a confidential computing environment creation request, which enables the confidential environment manager to create a confidential computing environment that matches the cryptographic module's operating requirements. As a result, the confidential computing environment created by the confidential environment manager can meet the performance requirements of the cryptographic module. Furthermore, the cryptographic module's operating requirements matched by the confidential computing environment are compatible with the hardware resources required to run the cryptographic module, thereby preventing waste of hardware resources and improving the overall performance of the electronic device. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are merely embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0051] FIG1 is a schematic diagram of an optional structure of a processor in an electronic device;
[0052] FIG2 is a schematic diagram of an optional architecture of a cryptographic operation system provided by an embodiment of the present disclosure;
[0053] FIG3 is a schematic diagram of the internal structure of a cryptographic module provided in an embodiment of the present disclosure;
[0054] FIG4 is an optional flow chart of a method for creating a confidential computing environment provided by an embodiment of the present disclosure;
[0055] FIG5 is an optional schematic diagram of step S31 provided in an embodiment of the present disclosure;
[0056] FIG6 is an optional schematic diagram of step S35 provided in an embodiment of the present disclosure;
[0057] FIG7 is an optional flow chart of a cryptographic operation method provided in an embodiment of the present disclosure;
[0058] FIG8 is a schematic diagram of another optional architecture of the cryptographic operation system provided by an embodiment of the present disclosure;
[0059] FIG9 is a schematic diagram of an optional structure of a password module manager provided in an embodiment of the present disclosure;
[0060] FIG10 is a schematic diagram of an optional structure of a confidential environment manager provided in an embodiment of the present disclosure;
[0061] FIG11 is a schematic diagram of another optional architecture of a cryptographic operation system provided by an embodiment of the present disclosure; and
[0062] FIG12 is an optional block diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0063] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present disclosure.
[0064] As described in the background art, in modern computer architecture, cryptographic operations can be implemented based on a dedicated cryptographic module (CM). By configuring a corresponding cryptographic module in an electronic device, the cryptographic module is called to perform cryptographic operations.
[0065] As an optional implementation, the cryptographic module can be configured based on high-security hardware in the electronic device to ensure the operational security of the cryptographic module while performing cryptographic operations. FIG1 exemplarily illustrates an optional structural diagram of a processor (Central Processing Unit, CPU) in an electronic device. As shown in FIG1 , the processor may include a processor core 110 and a security processor 120.
[0066] It is understood that the security processor 120 is a hardware device independent of and isolated from the processor core 110. Furthermore, the processor core 110 cannot access the hardware resources of the security processor 120, such as the internal storage of the security processor 120. Because the security processor has independent executable resources, it can form a closed executable environment. Therefore, except for data actively shared by the security processor, no external data on the security processor itself can be accessed. Therefore, when performing cryptographic operations on data, the cryptographic module can perform cryptographic operations based on the closed executable environment provided by the security processor, ensuring the security of the cryptographic operations.
[0067] In a specific example, a cryptographic module can be provided based on the security processor 120. The cryptographic module 121 is provided within the security processor 120. The security processor 120 provides a command interface for the cryptographic module 121, so that the cryptographic module 121 can implement information exchange with the processor core 110 based on the command interface for use by an application on the processor core 110. In one example, a program that uses the cryptographic module can be referred to as a cryptographic application.
[0068] However, the inventors discovered that due to the limitations of the processor hardware architecture, the number of security processors integrated in the processor is fixed. Therefore, when faced with the ever-changing cryptographic operation requirements in the system, the method of setting up cryptographic modules based on security processors cannot achieve flexible configuration of cryptographic modules, affecting the performance of cryptographic operations. For example, when more encryption and data protection tasks need to be processed, the fixed number of security processors may result in insufficient processing power of the cryptographic modules for different types of cryptographic operations; for another example, the cryptographic operation requirements of cryptographic applications on the processor decrease, and the provision of a fixed number of security processors with cryptographic modules may result in a waste of processor hardware resources. In addition, since the security processor is a processor dedicated to security functions and focuses on performing security-related operations, compared to the processor, the security processor does not need to handle high-performance computing tasks, which also makes the security processor generally have lower performance in terms of data processing frequency, cache, etc., thereby limiting the performance of the cryptographic module and reducing the overall performance of the electronic device.
[0069] Furthermore, it's important to note that integrating a security processor within a processor requires a technical prerequisite: the processor must provide hardware support for the security processor, such as an encryption / decryption engine and cache. However, most processor chips lack this support, further limiting the versatility of integrating a cryptographic module into a security processor, which then provides a secure execution environment for cryptographic operations.
[0070] It can be seen that it is particularly necessary to provide a solution for improving the overall performance of electronic devices.
[0071] In light of this, the disclosed embodiments propose an improved technical solution. A cryptographic module manager, based on the cryptographic module's image information, determines the hardware resources required to run the cryptographic module and generates a confidential computing environment creation request. This allows the confidential computing environment manager to create a confidential computing environment that matches the cryptographic module's operating requirements. This ensures that the confidential computing environment created by the confidential computing environment meets the performance requirements of the cryptographic module. Furthermore, the cryptographic module's operating requirements matched by the confidential computing environment are consistent with the hardware resources required to run the cryptographic module, thereby avoiding waste of hardware resources and improving the overall performance of the electronic device.
[0072] Figure 2 exemplarily illustrates an optional architecture diagram of a cryptographic computing system provided by an embodiment of the present disclosure. As shown in Figure 2 , the cryptographic computing system includes at least: a cryptographic module (CM) 20, a cryptographic module manager (also known as a "CM manager") 21, and a confidential environment manager (also known as a "CCE manager") 22.
[0073] Among them, the cryptographic module 20 is a module with cryptographic operation functions, which performs cryptographic operations based on the call of the cryptographic application. As shown in the internal structure diagram of the cryptographic module in Figure 3, the cryptographic module 20 may include a key management unit 201 and a cryptographic operation unit 202. The key management unit 201 is used to implement the full life cycle management of the key, including key generation, storage, use, update, destruction, etc. Usually, the plaintext of the key can only appear within the cryptographic module. If the key leaves the cryptographic module, it needs to be encrypted for protection. The cryptographic operation unit 202 is used to implement various standard cryptographic algorithms, including encryption, decryption, signing, signature verification, MAC message authentication code calculation (shown as Hash in the figure), key generation, key agreement, etc. Among them, the MAC message authentication code calculation can be calculated using a hash function, for example. The original message and the key are input into the hash function to calculate the verification code. The verification code can be a fixed-length value used to verify the integrity and authenticity of the message.
[0074] The cryptographic module manager 21 is used to manage the cryptographic module 20 that performs cryptographic operations, and the cryptographic module manager 21 can use the confidential environment manager 22 to create a confidential computing environment (Confidential Computing Environment, CCE) for the cryptographic module 20 to perform cryptographic operations. Moreover, the confidential computing environment is isolated from the current operating environment of the processor, so that the cryptographic operation process running by the cryptographic module 20 in the confidential computing environment is confidential and completely invisible to the outside. The outside can only see its input and output to the cryptographic operation system, thereby effectively ensuring the security of the cryptographic operation.
[0075] The confidential environment manager 22 manages the confidential computing environment and has the authority to create or destroy the confidential computing environment.
[0076] It should be noted that when the cryptographic operation system of the present embodiment creates a confidential computing environment isolated from the current operating environment of the processor, the processor needs to provide hardware mechanism support. The processor hardware mechanism is basically capable of supporting the confidential computing environment, so that the confidentiality, integrity, and authenticity of the cryptographic application running in the confidential computing environment can be guaranteed based on the processor hardware mechanism. Among them, the hardware mechanism provided by the processor can be, for example, a hardware security module, memory protection, secure boot, etc. In an optional example, secure virtualization technology can be used to create a confidential computing environment through a virtual machine.
[0077] The following describes in detail the confidential computing environment creation scheme of the embodiment of the present disclosure based on the cryptographic operation system architecture described above.
[0078] Figure 4 exemplarily illustrates an optional flow chart of a method for creating a confidential computing environment provided by an embodiment of the present disclosure. This method flow can be implemented by the cryptographic module, cryptographic module manager, and confidential environment manager in the cryptographic computing system shown in Figure 2. As shown in Figure 4 , this method flow can include the following steps.
[0079] Step S30: The cryptographic module manager obtains the image information of the cryptographic module.
[0080] The cryptographic module can be in a standby state, for example, when the system is not powered on or when it is not being used by a cryptographic application. Furthermore, the cryptographic module can have different types of external interfaces, including standard interface types such as those specified in the "GM / T 0018-2012 Cryptographic Device Application Interface Specification" and the "GM / T 0016-2012 Intelligent Cryptographic Key Application Interface Specification," as well as custom interface types.
[0081] When a cryptographic module needs to be started, the cryptographic module manager can obtain the image information of the cryptographic module. This cryptographic module can be the cryptographic module that the cryptographic application needs to call. The image information of the cryptographic module is a copy of the file containing the relevant program code of the cryptographic module. Different image information can be used according to the different uses of the cryptographic module, and different image information can also be developed according to user needs. The image information can also be called a program image.
[0082] In one example, the image information of a cryptographic module may generally include: encryption algorithm programs, such as symmetric encryption algorithms (such as AES, DES), asymmetric encryption algorithms (such as RSA, ECC), hash algorithms (such as MD5, SHA-256), etc., which are used by the cryptographic module to perform encryption, decryption, signing and verification operations; key management programs, which are used by the cryptographic module to generate, store and manage keys, where the keys can be symmetric keys or asymmetric keys, which are used to encrypt and decrypt data; authentication and authorization programs, which are used by the cryptographic module to authenticate users and control their access to system resources based on their permissions; secure communication protocols, such as SSL / TLS and IPsec, which are used by the cryptographic module to protect the security and integrity of data during the communication process; secure storage programs, which are used by the cryptographic module to protect the storage of sensitive data.
[0083] It should be noted that the image information of the cryptographic module is stored in the hard disk. The cryptographic module manager can read the image information of the corresponding cryptographic module directly from the hard disk as needed, or read the image information from the hard disk through the processor. The embodiment of the present disclosure does not limit this and can be set accordingly according to actual needs.
[0084] Step S31 : The cryptographic module manager determines the hardware resources required to run the cryptographic module based on the image information of the cryptographic module.
[0085] It is understandable that different cryptographic modules have different cryptographic operation performance. In the embodiments of the present disclosure, based on the cryptographic module-related program code contained in the cryptographic module image information, the performance of the cryptographic module can be determined, and thus the hardware resources required to run the cryptographic module can be determined. For example, a higher-performance cryptographic module can serve cryptographic applications on multiple different processor cores, thereby storing the data content of different cryptographic applications; or a lower-performance cryptographic module can serve only the cryptographic application on a single processor core, thereby storing the data content of the cryptographic application on that processor core, so that the hardware resources allocated to the cryptographic module are adapted to the performance requirements of the cryptographic module.
[0086] Step S32: The cryptographic module manager generates a confidential computing environment creation request based on the hardware resources required to run the cryptographic module.
[0087] The confidential computing environment creation request is used to request the creation of a confidential computing environment for the cryptographic module, so that the cryptographic module runs in the corresponding confidential computing environment to ensure the security of cryptographic operations.
[0088] The operation of the cryptographic module requires corresponding hardware resources. Therefore, the cryptographic module manager can generate a confidential computing environment creation request based on the hardware resources required to run the cryptographic module so that the confidential computing environment can meet the performance requirements of the cryptographic module.
[0089] Step S33: The cryptographic module manager sends the confidential computing environment creation request to the confidential environment manager.
[0090] When the cryptographic module manager uses the confidential environment manager to create a confidential computing environment in which the cryptographic module performs cryptographic operations, the cryptographic module manager can send a confidential computing environment creation request to the confidential environment manager, so that the confidential environment manager creates a confidential computing environment that matches the cryptographic module's operating requirements based on the confidential computing environment creation request. The cryptographic module's operating requirements can be compatible with the hardware resources required to run the cryptographic module, thereby avoiding waste of hardware resources and fully utilizing the cryptographic module's cryptographic computing capabilities in the created confidential computing environment, thereby improving the overall performance of the electronic device.
[0091] Step S34: The confidential environment manager obtains the confidential computing environment creation request sent by the cryptographic module manager.
[0092] Step S35: The confidential environment manager creates a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request.
[0093] The cryptographic module operation requirements are adapted to the hardware resources required to operate the cryptographic module.
[0094] It can be understood that when the confidential environment manager creates a confidential computing environment based on the confidential computing environment creation request generated by the cryptographic module manager according to the hardware resources required to run the cryptographic module, and the confidential computing environment corresponding to the creation of the cryptographic module is created, the confidential computing environment can meet the performance requirements of the cryptographic module, thereby performing cryptographic operations that are compatible with the performance of the cryptographic module in the confidential computing environment, giving full play to the cryptographic operation capabilities of the cryptographic module, and improving the overall performance of the electronic device.
[0095] As can be seen, in the disclosed embodiments, the cryptographic module manager determines the hardware resources required to run the cryptographic module based on the cryptographic module's image information and generates a confidential computing environment creation request, which enables the confidential environment manager to create a confidential computing environment that matches the cryptographic module's operating requirements. As a result, the confidential computing environment created by the confidential environment manager can meet the performance requirements of the cryptographic module. Furthermore, the cryptographic module's operating requirements matched by the confidential computing environment are compatible with the hardware resources required to run the cryptographic module, thereby preventing waste of hardware resources and improving the overall performance of the electronic device.
[0096] In some embodiments, based on the fact that the image information of the cryptographic module includes program codes related to the cryptographic module, parameter information such as performance of the cryptographic module can be determined through the image information. As shown in FIG5 , step S31 may specifically include the following steps:
[0097] Step S311, determining a performance profile of the cryptographic module based on the image information of the cryptographic module;
[0098] The performance configuration file of the cryptographic module refers to the operating parameters or configuration file of the cryptographic module set based on the system operation requirements. The operation and use strategy, memory use strategy, etc. of the cryptographic module can be set based on the performance configuration file.
[0099] Step S312: Determine the number of processor cores and memory resources required to run the cryptographic module based on the performance profile.
[0100] The performance profile includes the operation and use policy and memory use policy of the cryptographic module, so that the performance profile can reflect the ability of the cryptographic module to perform cryptographic operations.
[0101] It is understandable that electronic devices also include hardware devices such as memory and processors. The cryptographic application on the processor can call the cryptographic module to perform cryptographic operations, which in turn requires caching the data for the cryptographic operations. Moreover, in a processor with multiple processor cores, the cryptographic application can exist in one or more processor cores. Therefore, the number of processor cores and memory resources corresponding to the cryptographic module can be determined based on the performance profile of the cryptographic module. For example, for a processor with multiple processor cores, based on the performance of the cryptographic module, the cryptographic module can be flexibly allocated to multiple processor cores for use, so that the cryptographic module can perform cryptographic operations on multiple processor cores, thereby improving the cryptographic operation efficiency of the device. In terms of memory, based on the performance of the cryptographic module, memory resources that meet the performance requirements of the cryptographic module can be reasonably allocated to avoid insufficient or excessive memory allocation.
[0102] In some embodiments, based on the determined number of processor cores and memory resources required to run the cryptographic module, step S32, based on the hardware resources required to run the cryptographic module, generates a confidential computing environment creation request, which can be specifically: based on the number of processor cores and memory resources required to run the cryptographic module, generates a confidential computing environment creation request.
[0103] Therefore, the confidential computing environment creation request obtained by the confidential environment manager can include the number of processor cores and memory resources required to run the cryptographic module, and then when the confidential environment manager creates a confidential computing environment according to the confidential computing environment creation request, the confidential computing environment it creates can meet the performance requirements of the cryptographic module.
[0104] Furthermore, in the case where the confidential computing environment creation request obtained by the confidential environment manager includes the number of processor cores and memory resources required to run the cryptographic module, as shown in FIG6 , step S35 may specifically include the following steps:
[0105] Step S351, based on the number of processor cores, configuring a corresponding number of processor cores to the confidential computing environment;
[0106] Step S352: Based on the memory resources, the corresponding memory address is configured to the confidential computing environment.
[0107] 4 , in some embodiments, to enable the cryptographic modules managed by the cryptographic module manager to run in the confidential computing environment created by the confidential environment manager, after the confidential environment manager creates the confidential computing environment, the cryptographic module manager needs to send relevant information about the cryptographic modules to the confidential environment manager, and the following steps may be further included:
[0108] Step S36: The cryptographic module manager sends the image information of the cryptographic module to the confidential environment manager.
[0109] By sending the image information of the cryptographic module to the confidential environment manager through the cryptographic module manager, the confidential environment manager can load the image information of the cryptographic module in the created confidential computing environment, so that the cryptographic module can run in the confidential computing environment.
[0110] In step S37, the confidential environment manager obtains the image information of the cryptographic module sent by the cryptographic module manager, and loads the image information of the cryptographic module into the confidential computing environment to run the cryptographic module in the confidential computing environment.
[0111] It should be noted that, based on the confidential computing environment created by the confidential computing environment creation method of the embodiment of the present disclosure, when the cryptographic module manager needs to destroy the cryptographic module, for example, canceling the application of the cryptographic module in the system, the cryptographic module manager can send a confidential computing environment destruction request corresponding to the cryptographic module to the confidential environment manager, so that the confidential environment manager destroys the confidential computing environment, thereby destroying the cryptographic module running in the confidential computing environment.
[0112] As can be seen, in the disclosed embodiments, the cryptographic module manager determines the hardware resources required to run the cryptographic module based on the cryptographic module's image information and generates a confidential computing environment creation request, which enables the confidential environment manager to create a confidential computing environment that matches the cryptographic module's operating requirements. As a result, the confidential computing environment created by the confidential environment manager can meet the performance requirements of the cryptographic module. Furthermore, the cryptographic module's operating requirements matched by the confidential computing environment are compatible with the hardware resources required to run the cryptographic module, thereby preventing waste of hardware resources and improving the overall performance of the electronic device.
[0113] Based on the confidential computing environment created by the above-mentioned confidential computing environment creation method, the embodiment of the present disclosure also provides a cryptographic operation method, which can be applied to the confidential computing environment.
[0114] As an optional implementation, FIG7 exemplarily shows an optional flow chart of a cryptographic operation method provided by an embodiment of the present disclosure, which can be implemented by a cryptographic module and a cryptographic application. As shown in FIG7 , the method flow can include the following steps.
[0115] In step S71 , the cryptographic module obtains a key file and obtains a key for cryptographic operations based on the key file.
[0116] A key file refers to a file that stores the key required to perform cryptographic operations. The key file has a corresponding relationship with the cryptographic module, and this correspondence is maintained by the cryptographic module manager. When the cryptographic module needs to be run, the cryptographic module can accurately obtain the key file based on the correspondence between the cryptographic module and the key file maintained by the cryptographic module manager.
[0117] In an optional example, in order to achieve integrity and security protection of the key file, the key file can be an encrypted file. In order to obtain the key for cryptographic operations recorded in the key file, the cryptographic module may include a sealing key (Sealing Key), which may correspond to the encryption key of the key file, so that the cryptographic module can use the sealing key to decrypt the key file and obtain the key for the cryptographic operation. Among them, the key file of the cryptographic module can be stored in a hard disk, so that the corresponding key file can be read directly from the hard disk as needed, or the key file in the hard disk can be read by the processor. The embodiment of the present disclosure does not limit this and can be set accordingly according to actual needs.
[0118] It should be noted that the cryptographic module's seal key is bound to the program running the cryptographic module within the confidential computing environment (i.e., the cryptographic module's image information). The cryptographic module's seal key can only be obtained within the confidential computing environment and cannot be obtained or forged outside the confidential computing environment. Furthermore, the seal key can be specifically bound to the integrity of the cryptographic module's running program. If the integrity of the cryptographic module's running program is compromised, the corresponding seal key becomes unusable and the key file cannot be decrypted. If the seal key becomes usable and can decrypt the key file, it indicates that the cryptographic module's image information file is intact and has not been tampered with, thereby ensuring the security of the key obtained by decrypting the key file using the seal key.
[0119] In addition, when the seal key is bound to the cryptographic module program running in the confidential computing environment, the seal key can be obtained based on the image information loaded into the confidential computing environment. For example, the seal key can be generated by a hash measurement value of the cryptographic module's image information, so that when the cryptographic module's image information changes, the seal key belonging to the cryptographic module changes accordingly. The generation method of the cryptographic module's seal key can be determined by the hardware characteristics of the processor supporting the confidential computing environment. Different processors have different generation methods, as long as they meet the requirements of binding to the characteristic values of the cryptographic module program running in the confidential computing environment supported by the processor.
[0120] In one example, the key file may contain a user key. When the user calls the cryptographic module to change the user key, the cryptographic module may use the seal key to encrypt the changed user key and store it in the key file to update the user key stored in the key file and ensure the integrity of the key stored in the key file.
[0121] Step S72: The cryptographic application sends a verification request to the cryptographic module to verify the integrity of the cryptographic module.
[0122] When a cryptographic application requires the use of a cryptographic module, in order to ensure the accuracy of cryptographic operations, the cryptographic application can first verify the authenticity of the confidential computing environment and the integrity of the cryptographic module to ensure the accuracy of the data in the cryptographic module, that is, the data has not been lost or tampered with, and then send a verification request to the cryptographic module.
[0123] In a specific example, a cryptographic application may be a remote authentication mechanism based on confidential computing to remotely authenticate a cryptographic module, and send a remote authentication request to the cryptographic module through a confidential computing environment; the cryptographic module obtains the remote authentication request and generates an authentication report using the hardware mechanism of the confidential computing environment provided by the processor, wherein the authentication report may include content such as the image information measurement value of the cryptographic module, and is signed by a key that identifies the identity of the confidential computing environment, and the cryptographic module sends the signed authentication report to the cryptographic application through the confidential computing environment; after obtaining the authentication report, the cryptographic application first verifies the signature of the confidential computing environment to confirm the authenticity of the report, and then verifies information such as the image measurement value of the cryptographic module in the authentication report to confirm the integrity of the cryptographic module.
[0124] It should be noted that the above example is only an optional implementation of a cryptographic application verifying the integrity of a cryptographic module, and corresponding settings can be made according to requirements. The embodiments of the present disclosure are not limited to this.
[0125] If the cryptographic application verifies that the cryptographic module is intact, step S73 may be executed, where the cryptographic application calls the cryptographic module to perform cryptographic operations.
[0126] In some embodiments, to provide efficient cryptographic operations, the cryptographic module may utilize a cryptographic operations module to assist in performing cryptographic operations. The cryptographic operations module may be a hardware module with cryptographic operations capabilities capable of performing various standard-compliant cryptographic algorithms, such as encryption, decryption, signing, signature verification, MAC message authentication code calculation, key generation, and key agreement. Therefore, based on the cryptographic operations module's assistance to the cryptographic module, the cryptographic application calling the cryptographic module to perform cryptographic operations may specifically include: the cryptographic application calling the cryptographic module, and the cryptographic module utilizing the cryptographic operations module to perform cryptographic operations.
[0127] It can be seen that the embodiments of the present disclosure can implement cryptographic operations of the code module in a confidential computing environment, ensure the security of the cryptographic operations, and when the confidential computing environment matches the operating requirements of the cryptographic module, can effectively meet the performance requirements of the cryptographic module, avoid waste of hardware resources, and improve the overall performance of the electronic device.
[0128] The present disclosure also provides a cryptographic computing system. Figure 8 illustrates another exemplary structural diagram of the cryptographic computing system provided by the present disclosure. As shown in Figure 8, the cryptographic computing system may include at least a cryptographic module 81, a cryptographic application 82, a cryptographic module manager 83, and a confidential environment manager 84. The cryptographic module manager 83 and the confidential environment manager 84 may be used to create a confidential computing environment that matches the operating requirements of the cryptographic module 81.
[0129] The cryptographic module 81 is configured to obtain a key file in the confidential computing environment and obtain a key for cryptographic operations based on the key file;
[0130] The cryptographic application 82 is used to send a verification request to the cryptographic module in the confidential computing environment to verify the integrity of the cryptographic module; wherein, if the cryptographic module is intact, the cryptographic application calls the cryptographic module to perform cryptographic operations.
[0131] Optionally, the cryptographic module 81 may include a sealing key;
[0132] The step of the cryptographic module 81 obtaining the cryptographic key based on the key file is specifically: using the sealing key to decrypt the cryptographic file to obtain the cryptographic key.
[0133] Optionally, the cryptographic module 81 may utilize a cryptographic operation module to assist in performing cryptographic operations;
[0134] The steps of the cryptographic application 82 calling the cryptographic module to perform cryptographic operations are specifically as follows: the cryptographic application calls the cryptographic module, and the cryptographic module uses the cryptographic operation module to perform cryptographic operations.
[0135] It should be noted that the cryptographic module, cryptographic application, cryptographic module manager and confidential environment manager are software functional modules required for the cryptographic operation system to implement the confidential computing environment creation method and / or cryptographic operation method provided by the embodiment of the present disclosure. The cryptographic operation system of the embodiment of the present disclosure may also include the hardware composition of the processor 100, system memory 200 and hard disk 300 as shown in Figure 8.
[0136] The processor 100's hardware supports confidential computing features, enabling the confidential environment manager to create or destroy isolated operating environments, known as confidential computing environments, within the processor's current operating environment as needed. Furthermore, the processor 100's hardware mechanisms ensure the confidentiality, integrity, and authenticity of programs running within the confidential computing environment. The processor 100 may be, for example, a CPU (central processing unit).
[0137] System memory 200 is a physical device in a computer used to store data and programs, including runtime memory 210. This runtime memory 210 may be memory allocated based on the confidential computing environment. Therefore, the processor 100 can perform confidentiality and integrity protection on the runtime memory 210 allocated to the confidential computing environment within system memory 200, ensuring that only programs running within the confidential computing environment can normally access this runtime memory 210, preventing unauthorized access to the runtime memory 210 by programs outside the confidential computing environment.
[0138] The hard disk 300 includes information such as the program image 310 and key file 320 of the cryptographic module. The program image 310 is a copy of the file containing the program code related to the cryptographic module, which can be called the image information of the cryptographic module. Based on the program image 310, the cryptographic module's seal key can be obtained. For example, the seal key is generated based on the hash measurement value of the program image. When the program image changes, the seal key belonging to the cryptographic module will also change accordingly. The seal key can be bound to the program image. Thus, based on the cryptographic module running in a confidential computing environment, the seal key can only be obtained within the confidential computing environment and cannot be obtained or forged outside the confidential computing environment. In a specific example, the seal key can be bound to the integrity of the running program of the cryptographic module. If the integrity of the running program of the cryptographic module is destroyed, the corresponding seal key is unusable. In addition, the generation method of the seal key can be determined by the hardware characteristics of the processor that supports the confidential computing environment. Different processors have different generation methods. As long as it meets the requirements of binding with the characteristic values of the cryptographic module program running in the confidential computing environment supported by the processor, it can be used. Key file 320 is a file that stores the key required by the cryptographic module to perform cryptographic operations and has a corresponding relationship with the cryptographic module. Moreover, key file 320 is information that needs to be permanently stored. To ensure the security of the file, key file 320 can be an encrypted file. In one example, based on the corresponding relationship between key file 320 and cryptographic module 81, when a seal key for the cryptographic module is generated, key file 320 can be encrypted using the seal key, thereby storing the encrypted key file 320 on hard disk 300. In a specific example, the seal key can be bound to the integrity of the running program of the cryptographic module. If the integrity of the running program of the cryptographic module is destroyed, the corresponding seal key is unavailable and the key file cannot be decrypted. If the seal key is available, the key file can be decrypted using the seal key.
[0139] In some embodiments, based on creating a confidential computing environment that matches the operating requirements of a cryptographic module, Figure 9 exemplarily illustrates an optional structural diagram of a cryptographic module manager provided by an embodiment of the present disclosure. As shown in Figure 9 , the cryptographic module manager may include: an information acquisition unit 91, a resource determination unit 92, a request generation unit 93, and a request sending unit 94.
[0140] Wherein, the information acquisition unit 91 is used to obtain the image information of the password module;
[0141] The resource determination unit 92 is configured to determine the hardware resources required to run the cryptographic module based on the image information of the cryptographic module;
[0142] The request generating unit 93 is used to generate a confidential computing environment creation request based on the hardware resources required to run the cryptographic module;
[0143] The request sending unit 94 is used to send the confidential computing environment creation request so that the confidential environment manager creates a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request, and the cryptographic module operation requirements are adapted to the hardware resources required to run the cryptographic module.
[0144] Optionally, the resource determining unit 92 determines the hardware resources required to run the cryptographic module based on the image information of the cryptographic module, including:
[0145] Determining a performance profile of the cryptographic module based on the image information of the cryptographic module;
[0146] Based on the performance profile, the number of processor cores and memory resources required to run the cryptographic module are determined.
[0147] Optionally, the request generation unit 93 generates a confidential computing environment creation request based on the hardware resources required to run the cryptographic module, specifically: generating a confidential computing environment creation request based on the number of processor cores and memory resources required to run the cryptographic module.
[0148] Optionally, after the request sending unit 94 sends the confidential computing environment creation request, it is also used to: send the image information of the cryptographic module so that the confidential environment manager loads the image information of the cryptographic module in the created confidential computing environment, so that the cryptographic module runs in the confidential computing environment.
[0149] In some embodiments, based on creating a confidential computing environment that matches the operating requirements of the cryptographic module, Figure 10 exemplarily illustrates an optional structural diagram of a confidential environment manager provided by an embodiment of the present disclosure. As shown in Figure 10 , the confidential environment manager may include: a request acquisition unit 101 and an environment creation unit 102.
[0150] Among them, the request acquisition unit 101 is used to obtain the confidential computing environment creation request sent by the cryptographic module manager.
[0151] The confidential computing environment creation request can be generated by the cryptographic module manager based on the hardware resources required to run the cryptographic module, and the hardware resources required to run the cryptographic module can be determined by the cryptographic module manager based on the acquired image information of the cryptographic module.
[0152] The environment creation unit 102 is used to create a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request.
[0153] The cryptographic module operation requirements may be adapted to the hardware resources required to operate the cryptographic module.
[0154] Optionally, the confidential computing environment creation request obtained by the request acquisition unit 101 may include the number of processor cores and memory resources required to run the cryptographic module.
[0155] Optionally, the step of the environment creation unit 102 creating a confidential computing environment that matches the operation requirements of the cryptographic module based on the confidential computing environment creation request may include:
[0156] Based on the number of processor cores, allocating a corresponding number of processor cores to the confidential computing environment;
[0157] Based on the memory resources, the corresponding memory addresses are configured to the confidential computing environment.
[0158] Optionally, after the environment creation unit 102 creates a confidential computing environment that matches the operating requirements of the cryptographic module, it can also be used to: obtain the image information of the cryptographic module, and load the image information of the cryptographic module into the confidential computing environment to run the cryptographic module in the confidential computing environment.
[0159] In some embodiments, FIG11 exemplarily shows another optional architecture diagram of the cryptographic operation system provided by the embodiments of the present disclosure. As shown in FIG11 , the cryptographic operation system may further include: a cryptographic operation module 111 .
[0160] The cryptographic operation module 111 is a module with cryptographic operation functions. Based on the cryptographic operation requirements of the cryptographic module, in an optional implementation, the cryptographic operation module 111 can be a functional module integrated inside the cryptographic module for performing cryptographic operations, that is, a cryptographic operation unit of the cryptographic module.
[0161] In another optional implementation, the cryptographic operation module 111 can be a hardware module with cryptographic operation capabilities integrated within the processor 100, capable of performing various standard-compliant cryptographic algorithms, such as encryption, decryption, signing, signature verification, MAC message authentication code calculation, key generation, key agreement, etc., and is used to assist the cryptographic modules managed by the cryptographic module manager in performing cryptographic operations. The cryptographic operation module can securely provide cryptographic operation capabilities to the cryptographic modules. For example, based on the hardware support of the processor, the cryptographic operation module is configured to only receive cryptographic operation requests from a certain confidential computing environment. Thus, cryptographic operation requests from cryptographic modules in the confidential computing environment will be labeled with the confidential computing environment. When receiving a cryptographic operation request, the cryptographic operation module will first identify the label of the confidential computing environment to ensure the security of information exchange, thereby improving the cryptographic operation performance of the electronic device.
[0162] In an optional example, when a cryptographic operation system has multiple modules with cryptographic operation functions, the cryptographic module can be selected based on the requirements. For example, if a cryptographic module in a cryptographic operation system has a cryptographic operation unit internally, and the processor has the hardware for the cryptographic operation module internally, when the cryptographic application requires high-performance operation of the cryptographic module, the cryptographic module can choose to use the cryptographic operation module integrated in the processor (as shown in Figure 11).
[0163] It should be noted that the key management unit arranged inside the cryptographic module can realize the full life cycle management of the key, including key generation, storage, use, update, destruction, etc.; the cryptographic operation unit can implement various standard cryptographic algorithms, including encryption, decryption, signing, signature verification, MAC message authentication code calculation, key generation, key negotiation, etc., so that when the cryptographic operation module arranged inside the processor can perform various cryptographic algorithms that comply with the standards, such as encryption, decryption, signing, signature verification, MAC message authentication code calculation, key generation, key negotiation, etc., the key management unit in the cryptographic module can choose whether to use the cryptographic operation module arranged inside the processor to perform cryptographic operations according to the cryptographic module's own computing requirements.
[0164] An embodiment of the present disclosure also provides an electronic device, which may include at least one memory and at least one processor, wherein the memory stores one or more computer-executable instructions, and the processor calls the one or more computer-executable instructions to execute the confidential computing environment creation method provided by the embodiment of the present disclosure, and / or the cryptographic operation method provided by the embodiment of the present disclosure.
[0165] As an optional implementation, Figure 12 is an optional block diagram of an electronic device provided in an embodiment of the present disclosure. As shown in Figure 12, the electronic device may include: at least one processor 1, at least one communication interface 2, at least one memory 3 and at least one communication bus 4.
[0166] In the embodiment of the present disclosure, there is at least one processor 1 , communication interface 2 , memory 3 , and communication bus 4 , and the processor 1 , communication interface 2 , and memory 3 communicate with each other through the communication bus 4 .
[0167] Optionally, the communication interface 2 may be an interface of a communication module for performing network communication.
[0168] Optionally, processor 1 may be a CPU (central processing unit), a GPU (Graphics Processing Unit), an NPU (embedded neural network processor), an FPGA (Field Programmable Gate Array), a TPU (tensor processing unit), an AI chip, an application-specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present disclosure.
[0169] The memory 3 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0170] The memory 3 stores one or more computer-executable instructions, and the processor 1 calls the one or more computer-executable instructions to execute the cryptographic operation method of the embodiment of the present disclosure.
[0171] An embodiment of the present disclosure also provides a storage medium, which stores one or more computer-executable instructions. When the one or more computer-executable instructions are executed, a confidential computing environment creation method and / or a cryptographic operation method as performed by an electronic device in an embodiment of the present disclosure are implemented.
[0172] The above describes multiple embodiment schemes provided by the embodiments of the present disclosure. The various optional methods introduced in each embodiment scheme can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible embodiment schemes, which can all be considered as embodiment schemes disclosed and disclosed by the embodiments of the present disclosure.
[0173] Although the embodiments of the present disclosure are disclosed above, the present disclosure is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present disclosure. Therefore, the scope of protection of the present disclosure shall be based on the scope defined by the claims.
Claims
1. A method for creating a confidential computing environment, applied to a cryptographic module manager, the method for creating a confidential computing environment comprising: Get the image information of the cryptographic module; Determining hardware resources required to run the cryptographic module based on the image information of the cryptographic module; generating a confidential computing environment creation request based on hardware resources required to run the cryptographic module; The confidential computing environment creation request is sent so that the confidential environment manager creates a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request, wherein the cryptographic module operation requirements are compatible with the hardware resources required to run the cryptographic module.
2. The method for creating a confidential computing environment according to claim 1, wherein: The determining, based on the image information of the cryptographic module, the hardware resources required to run the cryptographic module includes: Determining a performance profile of the cryptographic module based on the image information of the cryptographic module; Based on the performance profile, the number of processor cores and memory resources required to run the cryptographic module are determined.
3. The method for creating a confidential computing environment according to claim 2, wherein: The generating a confidential computing environment creation request based on the hardware resources required to run the cryptographic module includes: generating a confidential computing environment creation request based on the number of processor cores and memory resources required to run the cryptographic module.
4. The method for creating a confidential computing environment according to any one of claims 1 to 3, wherein: After sending the confidential computing environment creation request, the confidential computing environment creation method further includes: The image information of the cryptographic module is sent so that the confidential environment manager loads the image information of the cryptographic module in the created confidential computing environment, so that the cryptographic module runs in the confidential computing environment.
5. A method for creating a confidential computing environment, applied to a confidential environment manager, the method for creating a confidential computing environment comprising: Obtaining a confidential computing environment creation request sent by a cryptographic module manager; wherein the confidential computing environment creation request is generated by the cryptographic module manager based on hardware resources required to run the cryptographic module, and the hardware resources required to run the cryptographic module are determined by the cryptographic module manager based on the acquired image information of the cryptographic module; Based on the confidential computing environment creation request, a confidential computing environment matching the cryptographic module operation requirements is created, wherein the cryptographic module operation requirements are compatible with the hardware resources required to run the cryptographic module.
6. The method for creating a confidential computing environment according to claim 5, wherein: The confidential computing environment creation request includes the number of processor cores and memory resources required to run the cryptographic module.
7. The method for creating a confidential computing environment according to claim 6, wherein: The step of creating a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request includes: Based on the number of processor cores, configuring a corresponding number of processor cores to the confidential computing environment; Based on the memory resources, corresponding memory addresses are configured to the confidential computing environment.
8. The method for creating a confidential computing environment according to any one of claims 5 to 7, wherein: After creating the confidential computing environment that matches the cryptographic module operation requirements, the confidential computing environment creation method further includes: Obtain the image information of the cryptographic module sent by the cryptographic module manager, and load the image information of the cryptographic module into the confidential computing environment to run the cryptographic module in the confidential computing environment.
9. A cryptographic operation method, applied to a confidential computing environment created by the method for creating a confidential computing environment as claimed in any one of claims 1 to 4 and / or any one of claims 5 to 8, the cryptographic operation method comprising: The cryptographic module obtains the key file and obtains the key for the cryptographic operation based on the key file; The cryptographic application sends a verification request to the cryptographic module to verify the integrity of the cryptographic module; If the cryptographic module is complete, the cryptographic application calls the cryptographic module to perform cryptographic operations.
10. The cryptographic operation method according to claim 9, wherein: The cryptographic module includes a sealing key; The cryptographic module obtains the cryptographic operation key based on the key file, including: the cryptographic module decrypts the cryptographic file using the seal key to obtain the cryptographic operation key.
11. The cryptographic operation method according to claim 10, wherein: The cryptographic module uses the cryptographic operation module to assist in performing cryptographic operations; The cryptographic application calls the cryptographic module to perform cryptographic operations, including: the cryptographic application calls The cryptographic module is used, and the cryptographic module uses the cryptographic operation module to perform cryptographic operations.
12. A cryptographic computing system, comprising at least a cryptographic module, a cryptographic application, a cryptographic module manager and a confidential environment manager, wherein: The cryptographic module manager and the confidential environment manager are used to create a confidential computing environment that matches the operating requirements of the cryptographic module; The cryptographic module is used to obtain a key file in the confidential computing environment and obtain a key for cryptographic operations based on the key file; The cryptographic application is used to send a verification request to the cryptographic module in the confidential computing environment to verify the integrity of the cryptographic module; wherein, if the cryptographic module is intact, the cryptographic application calls the cryptographic module to perform cryptographic operations.
13. The cryptographic operation system according to claim 12, wherein: The password module manager includes: An information acquisition unit, configured to acquire image information of a cryptographic module; a resource determination unit, configured to determine hardware resources required to run the cryptographic module based on the image information of the cryptographic module; a request generating unit configured to generate a confidential computing environment creation request based on hardware resources required to run the cryptographic module; A request sending unit is configured to send the confidential computing environment creation request so that the confidential environment manager creates a confidential computing environment that matches the cryptographic module operation requirements based on the confidential computing environment creation request, wherein the cryptographic module operation requirements are consistent with the hardware resources required to run the cryptographic module.
14. The cryptographic operation system according to claim 13, wherein: The confidentiality environment manager includes: A request obtaining unit configured to obtain a confidential computing environment creation request sent by a cryptographic module manager; The environment creation unit is configured to create a confidential computing environment that matches the operating requirements of the cryptographic module based on the confidential computing environment creation request.
15. The cryptographic operation system according to any one of claims 12 to 14, further comprising: The cryptographic operation module is configured to assist the cryptographic module in performing cryptographic operations in the confidential computing environment.
16. An electronic device comprising at least one memory and at least one processor, wherein: The memory stores one or more computer-executable instructions, and the processor calls the one or more computer-executable instructions to execute the confidential computing environment creation method as described in claims 1-4 and / or any one of claims 5-8, and / or the cryptographic operation method as described in any one of claims 9-11.
17. A storage medium storing one or more computer executable instructions, wherein: When the one or more computer-executable instructions are executed, the confidential computing environment creation method as described in claims 1-4 and / or any one of claims 5-8, and / or the cryptographic operation method as described in any one of claims 9-11 is implemented.
Citation Information
Patent Citations
Password unit creation method and device, data processing method and device and electronic equipment
CN112052446A
Container creating method, container deleting method, container deleting device, and equipment
CN113312613A
Secure computing method, device, equipment, medium and program product
CN114647868A
Confidential computing environment construction method and system based on ARM architecture
CN115344871A
Creation method and device of computing environment template, computing equipment and storage medium
CN116700897A