Cloud service system and data processing method based on cloud service
View Patent ↗A cloud service system includes a first server and a physical device. The first server and the physical device are coupled through a physical channel. The first server includes a cloud instance. The physical device includes a trusted execution environment corresponding to the cloud instance. The physical device is configured to perform confidential calculation on data from the cloud instance through the trusted execution environment, and send a calculation result to the cloud instance.
1 . A system comprising:
a first server comprising:
a cloud instance, wherein the cloud instance comprises data; and
a first operating system; and
a physical device coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server, and wherein the physical device comprises a trusted execution environment corresponding to the cloud instance, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system, and wherein the physical device is configured to:
obtain, from the cloud instance, the data;
perform a confidential scheming on the data through the trusted execution environment to obtain a result;
send, to the cloud instance, the result; and
reject operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when the first operating system is compromised.
2 . The system of claim 1 , wherein the physical device further comprises a second operating system, and wherein the physical device is further configured to:
receive, from the first operating system through the second operating system, the data; and
send, to the first operating system through the second operating system, the result to enable the first operating system to send the result to the cloud instance.
3 . The system of claim 2 , wherein the physical device is further configured to:
obtain a key corresponding to the cloud instance through the second operating system; and
further perform, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.
4 . The system of claim 1 , wherein the physical device is the second server, a smart card, or an offload card.
5 . The system of claim 4 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.
6 . The system of claim 4 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).
7 . The system of claim 1 , wherein the cloud instance is a first virtual machine, a first container, or a first bare metal server, and wherein the trusted execution environment is a second virtual machine, a second container, or a second bare metal server.
8 . A method implemented by a physical device, wherein the method comprises:
obtaining, from a cloud instance of a first server, data, wherein the physical device is coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server, and wherein the physical device comprises a trusted execution environment corresponding to the cloud instance, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system;
performing, through the trusted execution environment, a confidential scheming on the data to obtain a result;
sending, to the cloud instance, the result; and
rejecting operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when a first operating system of the first server is compromised.
9 . The method of claim 8 , further comprising:
receiving, through a second operating system of the physical device and from the first operating system of the first server, the data; and
sending, to the first operating system, and through the second operating system, the result to enable the first operating system to send the result to the cloud instance.
10 . The method of claim 9 , further comprising:
obtaining, through the second operating system, a key corresponding to the cloud instance; and
further performing, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.
11 . The method of claim 8 , wherein the physical device is the second server, a smart card, or an offload card.
12 . The method of claim 11 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.
13 . The method of claim 11 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).
14 . The method of claim 8 , wherein the cloud instance is a first virtual machine, a first container, or a first bare metal server, and wherein the trusted execution environment is a second virtual machine, a second container, or a second bare metal server.
15 . A physical device comprising:
a memory configured to store instructions and a trusted execution environment; and
one or more processors coupled to the memory and configured to execute the instructions to cause the physical device to:
obtain, from a cloud instance of a first server, data, wherein the physical device is coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server;
perform a confidential scheming on the data through the trusted execution environment to obtain a result;
send, to the cloud instance, the result; and
reject operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when a first operating system of the first server is compromised, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system.
16 . The physical device of claim 15 , wherein the memory further comprises a second operating system, and wherein the one or more processors are further configured to execute the instructions to cause the physical device to:
receive, from the first operating system through the second operating system, the data; and
send, to the first operating system through the second operating system, the result to enable the first operating system to send the result to the cloud instance.
17 . The physical device of claim 16 , wherein the one or more processors are further configured to execute the instructions to cause the physical device to:
obtain a key corresponding to the cloud instance through the second operating system; and
further perform, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.
18 . The physical device of claim 15 , wherein the physical device is the second server, a smart card, or an offload card.
19 . The physical device of claim 18 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.
20 . The physical device of claim 18 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).