信息网络安全 ›› 2023, Vol. 23 ›› Issue (1): 9-17.doi: 10.3969/j.issn.1671-1122.2023.01.002

• 技术研究 • 上一篇    下一篇

基于SM2和SM4的TEE下任务数据迁移方案

刘芹1,2(), 郭凯圆1,2, 涂航1,2   

  1. 1.武汉大学国家网络安全学院,武汉 430072
    2.武汉大学空天信息安全与可信计算教育部重点实验室,武汉 430072
  • 收稿日期:2022-08-10 出版日期:2023-01-10 发布日期:2023-01-19
  • 通讯作者: 刘芹 E-mail:qinliu@whu.edu.cn
  • 作者简介:刘芹(1978—),女,湖北,副教授,博士,主要研究方向为物联网安全、嵌入式系统安全、区块链和移动计算安全|郭凯圆(1998—),男,河南,硕士研究生,主要研究方向为应用密码学、云计算和隐私计算|涂航(1975—),男,湖北,副教授,博士,主要研究方向为密码学、嵌入式安全和物联网安全
  • 基金资助:
    国家自然科学基金(61332019);国家重点研发计划(2018YFC1604000);“十三五”国家密码发展基金(MMJJ201701304)

Task Data Migration Solution Based on SM2 and SM4 Under TEE

LIU Qin1,2(), GUO Kaiyuan1,2, TU Hang1,2   

  1. 1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
    2. Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education, Wuhan University, Wuhan 430072, China
  • Received:2022-08-10 Online:2023-01-10 Published:2023-01-19
  • Contact: LIU Qin E-mail:qinliu@whu.edu.cn

摘要:

可信执行环境(Trusted Execution Environment,TEE)技术常用于保证云服务器上用户关键任务数据的机密性和完整性,考虑云服务器的负载均衡以及服务响应延迟,往往需要对TEE下的用户关键任务数据进行迁移。为了解决TEE下任务数据迁移中如何确认迁移双方身份可信性、保证迁移数据传输安全性和提高迁移速度等问题,文章提出一种高效的TEE下任务数据安全迁移方案。该方案使用软件防护扩展(Software Guard Extension,SGX)远程认证功能对迁移双方进行身份可信性验证,并基于SM2密钥协商算法和SM4分组密码算法保证迁移数据安全传输。安全性分析表明,该方案可以确保迁移双方身份可信性和迁移数据传输安全性;仿真实验结果表明,该迁移方案能够提高TEE下任务数据迁移速度。

关键词: TEE, 云计算, 任务数据迁移, SM2, SM4

Abstract:

Trusted execution environment (TEE) technology is often used to protect the confidentiality and integrity of users’ critical task data on cloud servers, which often need to be migrated considering the load balancing and service response latency of cloud servers. In order to solve the problems of how to confirm the identity credibility of the migration parties, how to ensure the security of migrating data transmission, and how to improve the migration performance. This paper proposed an efficient and secure migration scheme for task data under TEE. The scheme used software guard extension(SGX) remote attestation to verify the identity credibility of the migration parties, and it ensured the secure transmission of the migrated data based on the SM2 and SM4 algorithms. The security analysis shows that the solution can ensure the trustworthiness of the identity of both parties and the security of the migration data transmission. And the simulation results show that the migration solution can improve the speed of task data migration under TEE.

Key words: TEE, cloud computing, task data migration, SM2, SM4

中图分类号: