宇宙链 宇宙链
Ctrl+D收藏宇宙链
首页 > KuCoin > 正文

英特尔SGX和区块链安全:iExec的端到端解决方案

作者:

时间:1900/1/1 0:00:00

点击蓝字关注我们

英特尔SGX和区块链

iExec端到端解决方案

iExec很荣幸地宣布即将推出首个集成英特尔SGX的端到端解决方案,用于分布式计算的安全技术应用。在2018年10月30日布拉格Devcon4会议上,iExec和英特尔将宣布重大合作新闻。

张磊,iExec安全总监介绍了英特尔SGXEnclave技术,以及如何保证参与区块链网络的用户和应用的安全问题,特别是基于区块链的分布式云技术方面。

敬请关注!

正文相关链接

IntelSGX:https://software.intel.com/en-us/sgx

Thechallenge:Howcanweguaranteesecurityondecentralizedanddistributednetworks?

Blockchain-basedapplicationsandcomputingarenotownedorcontrolledbyonespecificentitybutratherpoweredbyadistributednetworkofmultiplemachinesor‘nodes’.Thedistributednatureofdecentralizedcloudcomputingnetworkspresentachallengetoguaranteesecurityasanyrootprivilegeusermayeasilyinspectthesensitivedataandtamperwiththeapplicationrunningonthedecentralizedhost.Fortraditionalcentralizedcloudcomputingproviders,itiseasiertoemployexistingsecuritymechanismsprotecttheinvolvedapplication.

Fordecentralizedblockchain-basedclouds,asilicon-basedsecuritysolution,called‘IntelSGX’,istheonlyefficientsolutiontoprotectusersandapplicationsinvolvedinBlockchain-baseddecentralizedcomputing.

IntelSGX(IntelSoftwareGuardExtensions),isasetofCPUinstructioncodesthatenabletheexecutionofselectpiecescodeanddatainprotectedareascalledenclaves.Basically,whileyouhaveanapplicationrunningonahostmachine,SGXenclavesessentiallyactasabubble,isolatingandprotectingtheapplicationfromthehostmachine,inthisway,eventherootprivilegeadministratorofthehostmachineisnotabletopenetratethisbubbletoaccessandtamperwiththeapplication.

英特尔锐炫独显A380确认暂不支持挖矿:7月21日消息,英特尔锐炫Arc独立显卡A380已开始在国内上架销售,该卡暂不支持挖矿。YouTube主播DJ Mines通过在尝试了 NiceHashMining、trex miner、lolminer、teamreeminer之后确认,目前似乎还没有任何以太坊挖矿程序支持英特尔锐炫独显。据悉,目前英特尔锐炫桌面显卡包括 A770、A750、A580、A380和A310。目前只有A380一款进行了售卖。(IT之家)[2022/7/21 2:28:43]

AnintroductiontoIntelSGXEnclaves-iExecSecurityR&D,LeiZhang

“WhatmakesIntelSGXcompellingisthatitprovidesahardwaretrustedexecutionenvironment(TEE),allowingbetterprotectionsfordatain-use,at-restandin-transit,built-inCPUinstructionsandplatformenhancementsprovidecryptographicassertionsforthecodethatispermittedtoaccessthedata.Ifthecodeisalteredortampered,thenaccessisdeniedandtheenvironmentdisabled.”

—RickEchevarria,VicepresidentofIntel’sSoftwareandServicesGroup.

1.TheiExecE2ESGXsolution

iExecispioneeringthebuildingofablockchain-enableddecentralizedanddistributedcloudnetwork.Theyhavenowprovidedthefirsteverfullandend-to-endsolutionintegratingSGXfortheblockchain-basedcloud.SomeofourinitialworkwithintelSGXcanbereadinthisblogpostandiscoveredinthisvideopresentation.iExecpresentedthefirstphaseofworkonSGXinMarch2018attheIBMThinkConferenceinLasVegasandco-presentedalongsideIntelinMay2018atConsensusinNewYork..Thisfirstphasefocusedontheprotectionofthesecretsbuiltindecentralizedapplications:althoughtheapplicationsrunsondecentralizednodes,theinvolvedsensitivedatacannotbeinspectedoralteredwithbymaliciousattackersonthenetwork.Howeverthefirststageofworkwasbasedonsomesophisticated(raw)frameworksandthefunctionalityofthesolutionwaslimitedtoonlyprotectnativesecretsoftheapplication,furthermorethesolutioncouldbecomplicatedforappdevelopersandusers,especiallyforthosewhoarenotinthefieldofITandcomputing.

英特尔和微软携手打击加密劫持:金色财经报道,英特尔和微软正携手打击恶意加密货币挖矿。用于帮助抵御高级安全威胁的企业级解决方案Microsoft Defender for Endpoint已扩大了英特尔威胁检测技术(TDT)的使用范围,以打击非法加密货币挖矿(即“加密劫持”)。该解决方案依靠遥测数据来检测CPU性能中的任何异常情况。与其他类型的防御不同,TDT能够在恶意软件设法感染受害者的计算机以挖掘加密货币之前对其进行检测。[2021/4/27 21:01:36]

iExechastocontinuedtomakesignificantcontributions,workingdiligentlywithourpartners,topushforwardapowerfulanduser-friendlyend-to-endSGXsolution.Thissolutionisintendedtobeusedasanindustryreferencetoenhancetheoverallsecurityofdecentralizedcloudcomputing.ThisnewSGXsolution,combinedwithBlockchain,allowsforunmatchedleveloftrustforDecentralizedApplications(Dapps)andexecution/dataprocessingondecentralizednodes.TheiExecapproachspecificallyallowsBlockchaintoworkwithSGXinorderto:

ProtecttheDAppandprovidefulldataprotectionthatcannotbeaccessedbytheexecutionhost,especiallyforuser’sinputandoutputdata.

GuaranteetheintegrationoftheDapp/Data,makingsurethecorrectandexpectedDApporDataisrunningonthedecentralizednode.

Provideblockchain-basedvalidationforoff-chaincomputing,verifyingthattheDappiscorrectlyexecutedinanenclaveandisneithertamperednorinterruptedbythedecentralizednode.Asmart-contractsignatureissignedinsidethissecureenclavebeforetheverificationisdonebytheblockchainnetwork.

历史上的今天丨英特尔已联合Hyperledger发起新区块链编程项目:2019年6月30日,全球科技巨头英特尔与区块链技术公司Hyperledger共同发起了新区块链编程项目Hyperledger Transact。该项目是一种新工具,旨在通过提供标准接口或用于智能合约执行的共享软件库来提高区块链网络的兼容性。[2020/6/30]

MakesuretheexecutionandDAppresultisvalid,neithercopied,norfabricatedbymaliciousdecentralizednode.

Protecttheend-to-endprivacyofDAppresult,whichcanneverbeinspectedbyanyoneelsebuttheuser.

Afriendly-userinterface:significantsimplificationforuserstoencrypt/decrypttheinput/outputdataandtriggertheSGXapplicationexecution.

EasyusabilityisakeyelementofUserExperience;withthenewiExecE2ESGXsolution,useronlyneeds3simplestepstorunanE2ESGXapplicationandtoprovideafullprotectionofuser’sinputandoutputdata.

Let’sthinkaboutatypicalSGXapplication,sayforexampleaFinTechapplication.Theapplicationisfedbysomeuserinputdatawhichcontainssomeuser’spersonalandsensitivesecrets(e.g.bankaccountinformation,personalprivacy,etc…),theoutputresultsoftheapplicationalsocontainsomesensitivedataandareonlyintendedtouserwhotriggerstheapplication.Theinputdataandtheoutputresultsneedtobestrictlyprotectedduringthewholeprocedure.Thenon-encryptedsensitivedataneverleavesuserlocalscopeorhigh-securedtrustedexecutionenvironment:SXGenclave.Hereisagenericdescriptionofthe3simplestepsofiExec’sSGXsolution.

英特尔吴闻新:借助区块链技术,帮助pc租赁市场的健康发展:5月27日,“英特尔X蚂蚁区块链普惠科技助力中小发布会直播”在线上进行。在圆桌论坛《新基建浪潮下,普惠科技为中小企业带来的发展新机遇》中,英特尔行业解决方案集团首席技术官吴闻新指出,在PC租赁的市场,借助区块链技术,使得在这一链条上的数据是分布式的且不可篡改的,帮助pc租赁市场的健康发展。英特尔提供了一个技术平台的支撑,帮助整个PC租赁市场相对健康发展。信息技术是一个高科技,但信息技术的服务并不是高高在上的服务,中小企业可以利用我们的租赁平台,可以在较低成本下使用科技的便利,透过这个平台英特尔通过现有技术能力帮助中小企业解决在使用电脑过程中的一些问题,促进企业用起来且用的好。[2020/5/27]

Step1:Useronlyneedstorunonesimplecommandwhichallowstoautomatically:

Encryptuser’sinputdata

Pushtheencrypteddatatoaremotefilesystem(i.e.theremotefilesystemcanbeanypublicfilesharingserviceandenduserisfreetochoosehis/herpreferredone,pleasenotethatthisserviceisnotprovidedbyiExec)

Updaterelatedsessiondata(i.e.eachuser’striggeringoftheapplicationisasession)toaSGXbasedsecretmanagementservice.Secretmanagementservicecanbedeployedinaflexibleway:itcanbeatuser’sside,orscheduler’sside(i.e.SGXworkpool).

Step2:UsertriggersthetargetapplicationviasimpleclicksfromtheiExecDappstoreandmarketplaceviaauser-friendlyUIinterface.

OncethetargetapplicationistriggeredatremoteSGXdecentralizednode,theapplicationwillfirstlyautomaticallypulltheencrypteduserinputdatafromremotefilesystem(i.e.pushedinstep1);retrievethesecretkeyviasecuredSGXprovisionchannel,whichisthenusedtodecrypttheuserinputdata,thedecryptionisdoneonlyinsidethehigh-securedtrustedenvironment—SGXenclave;thedecrypteddatacanthenbeusedtofeedtheapplicationexecution,assoonastheapplicationresultisavailable,asignatureisprecededbasedontheprivatekeyprotectedinsidetheSGXenclave,whichcannotbeinspectedbytheoutsideworld.TheapplicationresultisfinallyencryptedandthentheiExec’sverificationprocedure(i.e.ProofofContribution)istriggered.EverythingissecurelyhappenedinsidetheIntelSGXenclaveensuredbyIntelhardwareCPUandnosecretisabletorevealedtotheoutsideworld.

动态 | 报告:区块链平台软件市场的主要参与者包括IBM、英特尔、微软等:据Industry Today消息,根据Reports And Markets的《2019-2025年全球区块链平台软件市场研究报告》,区块链技术最初用于金融交易,但可以应用于各种行业,如电子商务、供应链管理和数据集成。企业可以使用这个可自我维持的数据库来记录交易并消除欺诈交易。这些软件解决方案提供了创建依赖于任何类型交易的应用程序的框架。 该报告提供了该行业的基本概况,包括定义和分类。区块链平台软件市场分析面向国际市场,包括发展趋势、竞争格局分析和关键区域发展状况。这个市场的一些关键角色包括IBM、英特尔、微软、Ethereum、Ripple、Quorum、Hyperledger、R3 Corda、EOS、OpenChain、SAP、SAP、亚马逊、万事达。[2019/6/11]

Thesignatureisfinallytransferredtoon-chainnetworkandverifiedbyon-chainsmartcontractviatheregisteredcorrespondingpublickey.Ifthesignatureverificationpassesandapplicationresult’strustlevelachievesagiventhreshold.Theuserwillbeinformedtodownloadtheencryptedresult.

Thewholeprocedureisdoneautomaticallyinahighsecureway,andthisprocedureistriggeredbyonlysomesimpleclicksfromuserviathefriendlyUIinterface.

Fig.1iExec’sE2ESGXworkflow

Step3:Usercandownloadtheencryptedresultpackage,andusercanjustrunonesimplecommandtodecrypttheresult.Pleasenotethatonlytheuserwhotriggersthetask(i.e.SGXapplication)isabletodownloadtheencryptedresult,andonlytheuserownsthekeytodecrypttheapplicationresult.

Pleasenotethattheprocedureisplatformindependent,andthereforeiscompatiblewithdifferentoperatingsystems:Windows,Linux,MacOS.

Inthenearfuture,wewillfurthersimplifyuser’sprocedure—allthethreestepswillbeintegratedintoonesimplestep,andcanbedonebyseveralsimpleclicksfromuserviauserfriendlyuserinterface—https://market.iex.ec/.

2.TheiExecSolutionisSGXVendorAgnostic

TheiExecplatformisopentodifferentSGXsolutionvendors.Specifically,iExechasbeencollaboratingwithSCONEandFortanixtointegratetheirSGXframeworksintoiExec’sE2ESGXsolution.WearealsointhephaseofevaluatingIntel’sPDOframework.Inthefuture,wewillalsoconsidertheSGXframeworkofGraphene/Graphene-ng.AllthemainstreamSGXsolutionswillbe100%compatiblewithiExec’splatform,andwewillleaveiExecDappdevelopersanduserstofreelychoosetheirpreferredSGXframeworks.OurobjectistopromotetheemergenceofanecosystemwhichprovidestrustedexecutionforBlockchainbasedcomputing,andthesetrustedservicecanbemonetizedviaiExec’smarketplace.

3.iExecContributionstowardsIndustryStandardization

iExecarepioneersinthefieldofblockchain-basedTrustComputing,andisveryactiveinleadingandpushingforwardtheindustrialstandardizationforinthiscontextforBlockchaintechnology.

Especially:

iExecisveryactiveinEEA(EnterpriseEthereumAlliance):iExecischairingtheTrustedComputeWorkGroup,andkeepscontributingandpushingforwardtheEEAspecifications,especiallytheOff-chainTrustedComputeSpecificationwhichistobepubliclyreleasedsoon.

iExecisactiveinIEEEaswell.iExecismemberofIEEEP2418,andisinvolvedinIEEEstandardprojectonDLT-basedFederatedIdentity,CredentialandTrustManagement.iExecleadsthestandardizationworkinseveralBlockchainbaseddomains,especiallythesecurityandTEE(TrustedExecutionEnvironment)

iExeciscollaboratingwithhardwaretrustedexecutionvendorstomoveforwardthishardwarebasedsecuritysolution(SGX)tobefullystandard-compliant,staytunedforthecomingupdatesduringDevcon4.

iExecisalsocollaboratingwithourpartnerstomoveforwardthestandardizationforBlockchainbasedFogComputinginthecontextofOpenFogconsortium.SomeresultofthefirststagecollaborationwithourpartnersonFogComputingwillbereleasedsoon,pleasestaytunedinthefollowingdays.

长按扫码关注公众号

点“阅读原文”了解更多

标签:THEIONANDICATheresa May CoinIONX币BIGPANDAethicalstandards

KuCoin热门资讯
ArcBlock 正式成为亚马逊网络服务全球合作伙伴 将区块链开发平台融入 AWS

今天,ArcBlock区块基石,全球首个区块链应用开发部署云计算服务平台,正式宣布加入亚马逊网络服务合作伙伴计划,将ArcBlock区块链开发平台及生态系统融入遍布全球的AWS合作伙伴网络.

1900/1/1 0:00:00
BikiCoin关于上线阿尔法顺风车积分ACAR的公告

尊敬的用户: BikiCoin交易所即将上线阿尔法顺风车积分代币ACAR,并开放ACAR/USDT的交易市场,具体时间如下:1.

1900/1/1 0:00:00
DragonEx社区投票——周年庆活动:10万DT红包雨-调整方案

DragonEx社区投票——周年庆活动:10万DT红包雨-调整方案 2018-10-29 亲爱的用户: DragonEx11月2日喜迎周年庆,原定将于2018年11月01日-11月03日为交易手续费满1USDT的账户进行红包雨空投.

1900/1/1 0:00:00
关于启动FCoin原创大赛的公告

亲爱的社区用户: FCoin原创大赛现已开启,活动详情如下:1.活动参与者正面传播FCoin;2.参赛作品需在论坛作品专用贴下跟帖发布(点击链接)?按照作品名、作者、作品链接的方式发布作品.

1900/1/1 0:00:00
?庆LendChain(LV)上线DigiFinex,150万LV糖果空投

亲爱的用户: DigiFinex将于2018年11月03日15:00(GMT8)上线LendChain并同步开启充币服务,并将于2018年11月05日10:00(GMT8)开启交易和提币服务.

1900/1/1 0:00:00
IPC公链生态骊盾LID 将于10月28日首发场外交易平台OTCoin

你不一定要点蓝字关注我的当前浏览器不支持播放音乐或语音,请在微信或其他浏览器中播放理想赵雷-吉姆餐厅本周日,即10月28日,IPC公链生态骊盾LID,将首发场外交易平台OTCoin.

1900/1/1 0:00:00