节点文献

基于SGX的区块链隐私保护系统关键技术的研究与实现

Research and Implementation of Key Technologies of Blockchain Privacy Protection System Based on SGX

【作者】 李军;

【导师】 陈显毅;

【作者基本信息】 海南大学 , 软件工程, 2021, 硕士

【摘要】 随着物联网(Internet of Things,IoT)中轻量级移动终端设备的性能和处理能力不断提高,愈来愈多的用户把隐私数据存储在不够安全的轻量级移动设备上。但是,由于数据的复杂性、多样性和数据量大等特性,使用传统的软件或硬件来保护用户隐私数据是困难的。面对传统数据保护方法的种种弊端,随着TEE(Trusted Execution Environment,TEE)技术的发展,基于可信硬件保护隐私数据的完整性、机密性和真实性被认为是保障数据安全的候选方案之一。另外,区块链技术和智能合约两个新兴技术,前者具有的去中心化、不可篡改和公开透明等特性,后者具有自动执行的特点,两者在保护数据安全方面具有潜在的巨大价值。因此,本文针对轻量级移动终端隐私数据安全性和隐私性的问题,提出了一种基于SGX(Intel Software Guard Extensions,SGX)的区块链隐私保护模型,设计并实现了基于Intel SGX的区块链隐私保护系统。本文具体研究工作如下:1.首先对轻量级移动终端中用户隐私数据保护进行深入的研究和分析,根据国内外研究现状总结当前传统隐私数据保护方法的优点和不足。然后,对Intel SGX的技术原理进行了深入研究;接着对一些经典的密码学技术进行分类阐述,包括对称加密算法、非对称加密算法和哈希算法;最后分析研究区块链技术和边缘计算的原理。2.提出了一种基于Intel SGX的隐私保护模型。首先,设计Intel SGX可信平台,包括远程认证和身份认证模块,数据加解密和完整性检查的隐私保护模块,利用密码学技术对数据进行加解密和完整性检查,实现硬件增强的数据隐私保护。实验表明,较其他同类方法,基于Intel SGX的隐私保护模型能有效的提高用户数据的安全性和隐私性。3.提出了一种基于区块链的访问控制模型。设计多个访问控制合约,注册合约和历史合约,揭示了智能合约的关键作用。访问控制合约为不同的用户提供数据访问控制方法;注册合约包含用户属性信息,Intel SGX可信平台信息,访问控制和历史合约信息等,并提供诸如注册,更新和删除的功能;历史合约记录恶意用户的历史行为信息,检查用户是否存在恶意行为的历史记录;执行访问控制策略旨在物联网环境中对隐私数据实现分布式的访问控制管理。4.设计并实现了基于SGX的区块链隐私保护系统,在缺少第三方可信机构的情况下构建分布式可信的隐私保护系统,保护用户隐私数据。系统测试表明,该系统具有可行性、实用性和低性能开销,本文提出的方法能有效提高数据访问的及时性,保证数据的安全性、可靠性,尤其是隐私性,且该系统具有一定的可扩展性。

【Abstract】 As the performance and processing capabilities of lightweight mobile terminal devices in the Internet of Things(Internet of Things,IoT)continue to improve,more and more private data that users do not want to leak are stored on unsecured lightweight mobile devices.Previous studies have proved that due to the complexity,diversity,and a large amount of data,it is difficult to use traditional software or hardware to protect user privacy data.Facing the various drawbacks of traditional data protection,with the development of TEE(Trusted Execution Environment,TEE)technology,protecting the integrity,confidentiality,and authenticity of private data based on trusted hardware is considered one of the candidates for data security.Besides,blockchain technology and smart contracts are two emerging technologies.The former has the characteristics of decentralization,non-tamperability,and openness and transparency,while the latter has the characteristics of automatic execution.Both have potentially great value in protecting data security.Therefore,this paper proposes a blockchain privacy protection model based on SGX(Intel Software Guard Extensions,SGX),designs and implements a blockchain privacy protection system based on Intel SGX to solve the security and privacy problems of private data.The specific research work of this paper is as follows:1.Firstly,conduct an in-depth analysis of the research on user privacy data protection in lightweight mobile terminals and summarizes the advantages and disadvantages of current research methods for privacy data protection based on the current research status at home and abroad.Then,conducted in-depth research on the technical principles of Intel SGX;then classified and explained some classic cryptographic technologies,including symmetric encryption algorithms,asymmetric encryption algorithms,and hash algorithms;finally analyzed and studied the principles of blockchain technology and edge computing.2.Proposed a privacy protection model based on Intel SGX.First,design the Intel SGX trusted platform model,including remote authentication and identity authentication modules,privacy protection modules for data encryption,decryption,and integrity checking.Cryptography is used to encrypt and decrypt data and integrity checks to achieve hardwareenhanced data privacy protection.Experiments show that compared with other similar methods,the privacy protection model based on Intel SGX can effectively improve the security and privacy of user data.3.Proposed an access control model based on blockchain.The crucial role of the smart contract was revealed by designing multiple access control contracts,register contracts,and history contracts.The access control contract provides data access control methods for different users;the registration contract contains user attribute information,Intel SGX trusted platform information,access control,and history contract information,etc.,and provides functions such as registration,update,and deletion;history contract records malicious User’s historical behavior information,check whether the user has a history of malicious behavior;The implementation of the access control strategy aims to achieve distributed data access control management for private data in the Internet of Things environment.4.This paper designs and implements a blockchain privacy data protection system based on SGX and realizes the construction of a distributed trusted system architecture without a trusted third party to protect user privacy data.Experiments show that this system has feasibility,practicability,and low-performance overhead,our method can effectively improve the timeliness of data,reduce network delays,and ensure data security,reliability,privacy,and security,and the system has certain scalability.

【关键词】 SGX; 智能合约; 隐私保护; 物联网;
【Key words】 SGX; smart contract; privacy protection; IoT;
  • 【网络出版投稿人】 海南大学
  • 【网络出版年期】2024年 04期
  • 【分类号】TP309;TP311.13
节点文献中: