IP Library Granted Patent US 11,356,285
Granted Patent B2
US 11,356,285 · App. 17/347,037 · Granted Jun 7, 2022

Distributed key management for trusted execution environments

Inventors: Changzheng Wei (Hangzhou, CN); Ying Yan (Hangzhou, CN); Boran Zhao (Hangzhou, CN); Xuyang Song (Hangzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
H04L9/3273H04L9/0637H04L9/0819H04L9/0894H04L9/14H04L9/321H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,285
App. No.
17/347,037
Granted
Jun 7, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and apparatus, for securely executing smart contract operations in a trusted execution environment (TEE). One of the methods includes establishing, by a key management (KM) TEE of a KM node, a trust relationship with a plurality of KM TEEs in a plurality of KM nodes based on performing mutual attestations with the plurality of KM TEEs; initiating a consensus process with the plurality of KM TEEs for reaching consensus on providing one or more encryption keys to a service TEE of the KM node; in response to reaching the consensus with the plurality of KM TEEs, initiating a local attestation process with a service TEE in the KM node; determining that the local attestation process is successful; and in response to determining that the local attestation process is successful, providing one or more encryption keys to the TEE executing on the computing device.

Claims (50)

1. A computer-implemented method comprising:

receiving, by a client that is authorized by a key management center to perform encryption and decryption of data associated with a service trusted execution environment (TEE), a seal public key from the key management center;

identifying, by the client, a requested contract operation that is to be executed by a virtual machine deployed in the service TEE;

generating, by the client, a digital envelope by encrypting the requested contract operation that is to be executed by the virtual machine deployed in the service TEE using the seal public key that was received from the key management center that authorized the client to perform the encryption and decryption; and

sending, by the client, the digital envelope to a node that provides the digital envelope to the service TEE.

2. The method of claim 1 , wherein the key management center authorizes the client based on consulting a permissions resource.

3. The method of claim 1 , wherein the seal public key is associated with an unseal private key stored in the service TEE, and wherein the seal public key and the unseal private key form a key pair.

4. The method of claim 1 , wherein the requested contract operation includes one or more instructions encoded in a smart contract programming language for execution by the virtual machine operable to execute instruction in the smart contract programming language.

5. The method of claim 1 , wherein the requested contract operation includes an execution state for a smart contract associated with the requested contract operation.

6. The method of claim 1 , wherein generating the digital envelope comprises:

generating, by the client, a temporary key;

encrypting, by the client, the requested contract operation using the temporary key;

encrypting, by the client, the temporary key using the seal public key; and

generating, by the client, the digital envelope by concatenating the encrypted requested contract operation and the encrypted temporary key.

7. The method of claim 1 , wherein sending the digital envelope to the node comprises:

broadcasting, by the client, the digital envelope to multiple nodes including the node.

8. The method of claim 1 , comprising:

performing, by the client, verification on a signed result generated by the service TEE based on the requested contract operation.

9. The method of claim 8 , wherein performing verification on the signed result generated by the service TEE comprises:

retrieving, by the client, a verification public key from the key management center; and

decrypting, by the client, the signed result using the verification public key.

10. The method of claim 9 , comprising:

requesting, by the client, a next operation be executed by the service TEE, wherein the signed result includes the next operation and an execution state of a smart contract associated with the requested contract operation.

11. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, by a client that is authorized by a key management center to perform encryption and decryption of data associated with a service trusted execution environment (TEE), a seal public key from the key management center;

identifying, by the client, a requested contract operation that is to be executed by a virtual machine deployed in the service TEE;

generating, by the client, a digital envelope by encrypting the requested contract operation that is to be executed by the virtual machine deployed in the service TEE using the seal public key that was received from the key management center that authorized the client to perform the encryption and decryption; and

sending, by the client, the digital envelope to a node that provides the digital envelope to the service TEE.

12. The medium of claim 11 , wherein the key management center authorizes the client based on consulting a permissions resource.

13. The medium of claim 11 , wherein the seal public key is associated with an unseal private key stored in the service TEE, and wherein the seal public key and the unseal private key form a key pair.

14. The medium of claim 11 , wherein the requested contract operation includes one or more instructions encoded in a smart contract programming language for execution by the virtual machine operable to execute instruction in the smart contract programming language.

15. The medium of claim 11 , wherein generating the digital envelope comprises:

generating, by the client, a temporary key;

encrypting, by the client, the requested contract operation using the temporary key;

encrypting, by the client, the temporary key using the seal public key; and

generating, by the client, the digital envelope by concatenating the encrypted requested contract operation and the encrypted temporary key.

16. The medium of claim 11 , comprising:

performing, by the client, verification on a signed result generated by the service TEE based on the requested contract operation.

17. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, by a client that is authorized by a key management center to perform encryption and decryption of data associated with a service trusted execution environment (TEE), a seal public key from the key management center;

identifying, by the client, a requested contract operation that is to be executed by a virtual machine deployed in the service TEE;

generating, by the client, a digital envelope by encrypting the requested contract operation that is to be executed by the virtual machine deployed in the service TEE using the seal public key that was received from the key management center that authorized the client to perform the encryption and decryption; and

sending, by the client, the digital envelope to a node that provides the digital envelope to the service TEE.

18. The system of claim 17 , wherein generating the digital envelope comprises:

generating, by the client, a temporary key;

encrypting, by the client, the requested contract operation using the temporary key;

encrypting, by the client, the temporary key using the seal public key; and

generating, by the client, the digital envelope by concatenating the encrypted requested contract operation and the encrypted temporary key.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2025
From: ADVANCED NEW TECHNOLOGIES CO., LTD.
To: ANTCHAIN TECHNOLOGY PTE. LTD.
Reel/Frame 070253/0064 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 057182/0713 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 057182/0796 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: WEI, CHANGZHENG; YAN, YING; ZHAO, BORAN; SONG, XUYANG
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 057185/0213 →
Continuity (4)
Continuation 16893122 · Jun 4, 2020
Continuation 16671024 · Oct 31, 2019
Continuation PCTCN2019084530 · Apr 26, 2019
Related Publication 20210306164A1 · Sep 30, 2021