Netinfo Security ›› 2025, Vol. 25 ›› Issue (11): 1774-1791.doi: 10.3969/j.issn.1671-1122.2025.11.010

Previous Articles     Next Articles

Cloud-Native TEE Service Sharing Mechanism for Secure Edge Computing

LU Di1, LIU Yujia1(), LYU Chaoyue2, SUN Mengna1, ZHANG Qingwen1, YANG Li1   

  1. 1. School of Computer Science and Technology, Xidian University, Xi’an 710126, China
    2. VeriSilicon (Chengdu) Co., Ltd., Chengdu 610041, China
  • Received:2025-06-20 Online:2025-11-10 Published:2025-12-02

Abstract:

Networked intelligent terminals are constantly exposed to diverse security threats in open environments. Although trusted execution environment (TEE) technology provides a hardware-based isolated execution environment for sensitive applications, its security capabilities are confined to individual devices, making it difficult to establish cross-device secure services. As a result, a large number of terminals without TEE support cannot perform hardware-level confidential computing, leading to insufficient TEE coverage. To address this issue, this paper proposed a cloud-native TEE sharing mechanism that leverages cloud-based TEE and abundant computing resources to provide remote confidential computing capabilities for non-TEE terminals. The mechanism employed a lightweight cloud confidential virtual machine (CVM) as the isolated execution environment to deliver TEE services to remote terminals. Furthermore, a secure communication channel, combined with a zero-knowledge proof-based device authentication and key agreement protocol, ensured the confidentiality, integrity, and replay-resistance of remote TEE services. A prototype system was implemented on the Intel TDX platform. Experimental results demonstrate that the proposed mechanism effectively extends TEE security capabilities to terminal devices, with remote execution performance approaching that of conventional virtual machines, thereby validating the effectiveness and practicality of the approach.

Key words: trusted execution environment, cloud-native, service sharing, confidential computing

CLC Number: