信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1194-1208.doi: 10.3969/j.issn.1671-1122.2026.08.003

• 学术研究 • 上一篇    下一篇

可信执行环境在隐私计算中的研究现状、关键问题与发展方向综述

史俊1,2,3, 王浩1, 李增鹏1,4, 顾益宇5(), 马惠铃6   

  1. 1 山东大学网络空间安全学院青岛 266237
    2 山东大学国家卓越工程师学院济南 250102
    3 麒麟软件有限公司天津 300459
    4 密码与数字经济安全全国重点实验室青岛 266237
    5 北京科技大学计算机与通信工程学院北京 100083
    6 贵州省信息中心贵阳 550001
  • 收稿日期:2026-02-27 出版日期:2026-08-10 发布日期:2026-09-23
  • 通讯作者: 顾益宇 E-mail:guyy0808@163.com
  • 作者简介:史俊(1986—),男,上海,工程师,博士研究生,主要研究方向为可信计算、远程证明|王浩(2002—),男,陕西,硕士研究生,主要研究方向为远程证明、可信执行环境|李增鹏(1989—),男,山东,副教授,博士,CCF会员,主要研究方向为网络数据安全、密码协议、安全多方计算|顾益宇(1986—),男,浙江,博士研究生,主要研究方向为网络认证|马惠铃(1987—),女,贵州,高级工程师,硕士,主要研究方向为数据处理、网络工程
  • 基金资助:
    国家自然科学基金(62472255);国家自然科学基金(62302271);山东省自然科学基金(ZR2026QB26);山东省自然科学基金(ZR2023MF045);山东省自然科学基金(ZR2023QF088);山东省高等学校青年创新科技支持计划(2024KJH179)

Survey on the research status, key issues, and development directions of trusted execution environment in privacy computing

Shi Jun1,2,3, Wang Hao1, Li Zengpeng1,4, Gu Yiyu5(), Ma Huiling6   

  1. 1 School of Cyber Science and Technology, Shandong University, Qingdao 266237, China
    2 National Graduate School for Elite Engineers, Shandong University, Jinan 250102, China
    3 KylinSoft Co., Ltd., Tianjin 300459, China
    4 State Key Laboratory of Cryptography and Digital Economy Security, Qingdao 266237, China
    5 School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing 100083, China
    6 Guizhou Provincial Information Center, Guiyang 550001, China
  • Received:2026-02-27 Online:2026-08-10 Published:2026-09-23
  • Contact: Gu Yiyu E-mail:guyy0808@163.com

摘要:

随着隐私计算技术的快速发展,基于硬件安全隔离的可信执行环境已成为保护数据隐私安全的关键技术。当前,可信执行环境技术体系涵盖Intel SGX、Intel TDX、AMD SEV、ARM TrustZone、RISC-V Keystone等各类架构,并扩展至GPU/FPGA等异构计算领域。这些架构在安全性提升、性能优化和生态系统建设方面取得重大进展,广泛应用于云计算平台、移动设备和边缘计算场景。然而,可信执行环境技术在实际工程部署中仍面临诸多挑战,尤其在安全性、跨平台兼容性和标准化统一等方面。文章对当前可信执行环境技术的前沿研究成果进行系统梳理,并总结其在隐私计算场景下面临的五大核心问题。在此基础上,文章提出未来研究的关键方向,旨在为可信执行环境技术的创新与应用提供理论支持和实践指导。

关键词: 可信执行环境, 隐私计算, 安全隔离, 侧信道攻击防护, 远程认证

Abstract:

With the rapid development of privacy computing technologies, trusted execution environment based on hardware-level security isolation has become a key technology for protecting data privacy and security. Currently, the trusted execution environment technology ecosystem includes various architectures such as Intel SGX, Intel TDX, AMD SEV, ARM TrustZone, and RISC-V Keystone, and has extended into GPU and FPGA heterogeneous computing domains. These architectures have made significant advancements in enhancing security mechanisms, optimizing performance efficiency, and building ecosystems, with widespread applications in cloud computing platforms, mobile devices, and edge computing scenarios. However, the technology still faces numerous challenges in engineering practice, particularly regarding security, cross-platform compatibility, and standardization. This paper systematically reviewed and compared cutting-edge research achievements in trusted execution environment, summarized five key research challenges faced by trusted execution environment technologies in privacy-preserving computing scenarios. On this basis, this paper outlined future research directions to provide theoretical support and practical guidance for the innovation and application of trusted execution environment technologies.

Key words: trusted execution environment, privacy computing, security isolation, side-channel attack defense, remote attestation

中图分类号: