信息网络安全 ›› 2025, Vol. 25 ›› Issue (11): 1774-1791.doi: 10.3969/j.issn.1671-1122.2025.11.010

• 专题论文:机密计算 • 上一篇    下一篇

一种云原生TEE服务共享机制

卢笛1, 刘玉佳1(), 吕超越2, 孙梦娜1, 张清文1, 杨力1   

  1. 1.西安电子科技大学计算机科学与技术学院西安 710126
    2.芯原微电子(成都)有限公司成都 610041
  • 收稿日期:2025-06-20 出版日期:2025-11-10 发布日期:2025-12-02
  • 通讯作者: 刘玉佳 25031212183@stu.xidian.edu.cn
  • 作者简介:卢笛(1983—),男,陕西,教授,博士,CCF高级会员,主要研究方向为可信计算、机密计算、物联网和云计算安全|刘玉佳(2002—),女,山东,硕士研究生,主要研究方向为可信计算、云计算安全|吕超越(1999—),女,四川,硕士,主要研究方向为可信计算和嵌入式系统安全|孙梦娜(2000—),女,河北,硕士研究生,主要研究方向为机密计算|张清文(2003—),女,陕西,硕士研究生,主要研究方向为机密计算|杨力(1977—),男,陕西,教授,博士,CCF高级会员,主要研究方向为移动互联网安全、云计算安全、移动终端安全和可信计算
  • 基金资助:
    国家自然科学基金(62232013);国家自然科学基金(U24A20243);国家自然科学基金(92267204);国家重点研发计划(2023YFB3106900)

Cloud-Native TEE Service Sharing Mechanism for Secure Edge Computing

LU Di1, LIU Yujia1(), LYU Chaoyue2, SUN Mengna1, ZHANG Qingwen1, YANG Li1   

  1. 1. School of Computer Science and Technology, Xidian University, Xi’an 710126, China
    2. VeriSilicon (Chengdu) Co., Ltd., Chengdu 610041, China
  • Received:2025-06-20 Online:2025-11-10 Published:2025-12-02

摘要:

网络化智能终端在开放环境中长期面临多样化的安全威胁。可信执行环境(TEE)虽可为终端敏感程序提供硬件级隔离执行环境,但其安全能力局限于单设备内部,难以构建跨设备的安全服务体系,致使大量不具备TEE的终端无法开展硬件级机密计算,从而造成TEE安全覆盖不足问题。因此,文章提出一种云原生TEE服务共享机制,利用云端TEE及其充裕的计算资源,为缺乏TEE的终端设备提供远程机密计算能力。该机制以轻量化云端机密虚拟机(CVM)作为隔离执行环境,为远程终端提供TEE服务;同时,通过构建安全通信信道以及基于零知识证明的设备认证与密钥协商协议,确保远程TEE服务过程的机密性、完整性及抗重放攻击能力。原型系统基于Intel TDX平台设计并实现。实验结果表明,该机制能够有效将TEE安全能力扩展至终端设备,其远程执行性能接近常规虚拟机,验证了该方案的有效性与可用性。

关键词: 可信执行环境, 云原生, 服务共享, 机密计算

Abstract:

Networked intelligent terminals are constantly exposed to diverse security threats in open environments. Although trusted execution environment (TEE) technology provides a hardware-based isolated execution environment for sensitive applications, its security capabilities are confined to individual devices, making it difficult to establish cross-device secure services. As a result, a large number of terminals without TEE support cannot perform hardware-level confidential computing, leading to insufficient TEE coverage. To address this issue, this paper proposed a cloud-native TEE sharing mechanism that leverages cloud-based TEE and abundant computing resources to provide remote confidential computing capabilities for non-TEE terminals. The mechanism employed a lightweight cloud confidential virtual machine (CVM) as the isolated execution environment to deliver TEE services to remote terminals. Furthermore, a secure communication channel, combined with a zero-knowledge proof-based device authentication and key agreement protocol, ensured the confidentiality, integrity, and replay-resistance of remote TEE services. A prototype system was implemented on the Intel TDX platform. Experimental results demonstrate that the proposed mechanism effectively extends TEE security capabilities to terminal devices, with remote execution performance approaching that of conventional virtual machines, thereby validating the effectiveness and practicality of the approach.

Key words: trusted execution environment, cloud-native, service sharing, confidential computing

中图分类号: