火星链 火星链
Ctrl+D收藏火星链
首页 > Pol币 > 正文

ION:英特尔SGX和区块链安全:iExec的端到端解决方案

作者:

时间:1900/1/1 0:00:00

点击蓝字关注我们

英特尔SGX和区块链

iExec端到端解决方案

iExec很荣幸地宣布即将推出首个集成英特尔SGX的端到端解决方案,用于分布式计算的安全技术应用。在2018年10月30日布拉格Devcon4会议上,iExec和英特尔将宣布重大合作新闻。

张磊,iExec安全总监介绍了英特尔SGXEnclave技术,以及如何保证参与区块链网络的用户和应用的安全问题,特别是基于区块链的分布式云技术方面。

敬请关注!

正文相关链接

IntelSGX:https://software.intel.com/en-us/sgx

Thechallenge:Howcanweguaranteesecurityondecentralizedanddistributednetworks?

Blockchain-basedapplicationsandcomputingarenotownedorcontrolledbyonespecificentitybutratherpoweredbyadistributednetworkofmultiplemachinesor‘nodes’.Thedistributednatureofdecentralizedcloudcomputingnetworkspresentachallengetoguaranteesecurityasanyrootprivilegeusermayeasilyinspectthesensitivedataandtamperwiththeapplicationrunningonthedecentralizedhost.Fortraditionalcentralizedcloudcomputingproviders,itiseasiertoemployexistingsecuritymechanismsprotecttheinvolvedapplication.

Fordecentralizedblockchain-basedclouds,asilicon-basedsecuritysolution,called‘IntelSGX’,istheonlyefficientsolutiontoprotectusersandapplicationsinvolvedinBlockchain-baseddecentralizedcomputing.

IntelSGX(IntelSoftwareGuardExtensions),isasetofCPUinstructioncodesthatenabletheexecutionofselectpiecescodeanddatainprotectedareascalledenclaves.Basically,whileyouhaveanapplicationrunningonahostmachine,SGXenclavesessentiallyactasabubble,isolatingandprotectingtheapplicationfromthehostmachine,inthisway,eventherootprivilegeadministratorofthehostmachineisnotabletopenetratethisbubbletoaccessandtamperwiththeapplication.

英特尔执行长基辛格:芯片制造设备交货时间已大幅拉长:5月25日消息,英特尔执行长基辛格23日在达沃斯世界经济论坛(WEF)场边受访时表示,芯片短缺问题预料将持续到2024年。他也警告,半导体短缺问题同时造成先进芯片制造设备也供不应求,可能阻碍全球晶片产能的扩张计划。他说,新晶圆厂的芯片制造设备交货时间,已相当大幅度地拉长。他认为当前扩增产能的最重要壅塞点,是芯片制造设备的供应。(财联社)[2022/5/25 3:39:46]

AnintroductiontoIntelSGXEnclaves-iExecSecurityR&D,LeiZhang

“WhatmakesIntelSGXcompellingisthatitprovidesahardwaretrustedexecutionenvironment(TEE),allowingbetterprotectionsfordatain-use,at-restandin-transit,built-inCPUinstructionsandplatformenhancementsprovidecryptographicassertionsforthecodethatispermittedtoaccessthedata.Ifthecodeisalteredortampered,thenaccessisdeniedandtheenvironmentdisabled.”

—RickEchevarria,VicepresidentofIntel’sSoftwareandServicesGroup.

1.TheiExecE2ESGXsolution

iExecispioneeringthebuildingofablockchain-enableddecentralizedanddistributedcloudnetwork.Theyhavenowprovidedthefirsteverfullandend-to-endsolutionintegratingSGXfortheblockchain-basedcloud.SomeofourinitialworkwithintelSGXcanbereadinthisblogpostandiscoveredinthisvideopresentation.iExecpresentedthefirstphaseofworkonSGXinMarch2018attheIBMThinkConferenceinLasVegasandco-presentedalongsideIntelinMay2018atConsensusinNewYork..Thisfirstphasefocusedontheprotectionofthesecretsbuiltindecentralizedapplications:althoughtheapplicationsrunsondecentralizednodes,theinvolvedsensitivedatacannotbeinspectedoralteredwithbymaliciousattackersonthenetwork.Howeverthefirststageofworkwasbasedonsomesophisticated(raw)frameworksandthefunctionalityofthesolutionwaslimitedtoonlyprotectnativesecretsoftheapplication,furthermorethesolutioncouldbecomplicatedforappdevelopersandusers,especiallyforthosewhoarenotinthefieldofITandcomputing.

欧盟内部市场委员:英特尔将很快宣布在欧洲建立大型芯片工厂:11月27日,欧盟内部市场委员布雷顿表示,英特尔将很快宣布在欧洲建立大型芯片工厂。欧盟将像美国和日本一样,给予半导体制造商同样的支持,欧盟的规则令半导体制造商得到支持。(金十)[2021/11/27 12:35:53]

iExechastocontinuedtomakesignificantcontributions,workingdiligentlywithourpartners,topushforwardapowerfulanduser-friendlyend-to-endSGXsolution.Thissolutionisintendedtobeusedasanindustryreferencetoenhancetheoverallsecurityofdecentralizedcloudcomputing.ThisnewSGXsolution,combinedwithBlockchain,allowsforunmatchedleveloftrustforDecentralizedApplications(Dapps)andexecution/dataprocessingondecentralizednodes.TheiExecapproachspecificallyallowsBlockchaintoworkwithSGXinorderto:

ProtecttheDAppandprovidefulldataprotectionthatcannotbeaccessedbytheexecutionhost,especiallyforuser’sinputandoutputdata.

GuaranteetheintegrationoftheDapp/Data,makingsurethecorrectandexpectedDApporDataisrunningonthedecentralizednode.

Provideblockchain-basedvalidationforoff-chaincomputing,verifyingthattheDappiscorrectlyexecutedinanenclaveandisneithertamperednorinterruptedbythedecentralizednode.Asmart-contractsignatureissignedinsidethissecureenclavebeforetheverificationisdonebytheblockchainnetwork.

MakesuretheexecutionandDAppresultisvalid,neithercopied,norfabricatedbymaliciousdecentralizednode.

英特尔的新GPU产品未限制加密货币挖矿功能:10月12日消息,芯片制造商英特尔(Intel)的客户端图形产品和解决方案集团总经理Roger Chandler在接受Gadgets360采访时表示,英特尔正在设计的Arc和炼金术士(Alchemist)系列GPU产品没有任何专门针对矿工的功能,不会限制加密货币挖矿。

此前报道,今年6月份另一家芯片制造商英伟达宣布在其RTX30系列的所有显卡上添加了Lite Hash Rate算法,该算法可在显卡运行时检测是否为挖矿算法,如果被检测到显卡用于挖矿,则会将显卡的计算能力降低一半。[2021/10/12 20:23:56]

Protecttheend-to-endprivacyofDAppresult,whichcanneverbeinspectedbyanyoneelsebuttheuser.

Afriendly-userinterface:significantsimplificationforuserstoencrypt/decrypttheinput/outputdataandtriggertheSGXapplicationexecution.

EasyusabilityisakeyelementofUserExperience;withthenewiExecE2ESGXsolution,useronlyneeds3simplestepstorunanE2ESGXapplicationandtoprovideafullprotectionofuser’sinputandoutputdata.

Let’sthinkaboutatypicalSGXapplication,sayforexampleaFinTechapplication.Theapplicationisfedbysomeuserinputdatawhichcontainssomeuser’spersonalandsensitivesecrets(e.g.bankaccountinformation,personalprivacy,etc…),theoutputresultsoftheapplicationalsocontainsomesensitivedataandareonlyintendedtouserwhotriggerstheapplication.Theinputdataandtheoutputresultsneedtobestrictlyprotectedduringthewholeprocedure.Thenon-encryptedsensitivedataneverleavesuserlocalscopeorhigh-securedtrustedexecutionenvironment:SXGenclave.Hereisagenericdescriptionofthe3simplestepsofiExec’sSGXsolution.

John McAfee称英特尔公司起诉其使用“GhostbyMcAfee”名称:John McAfee 7月23日发布推文称,英特尔公司正在起诉他使用“GhostbyMcAfee”这个名字。据悉,McAfee是第一批杀软件的创始人之一,英特尔在2010年收购了McAfee公司。英特尔此举似乎是对 McAfee自己的隐私币公司和杀公司使用同一“McAfee”名称感到不满。[2020/7/23]

Step1:Useronlyneedstorunonesimplecommandwhichallowstoautomatically:

Encryptuser’sinputdata

Pushtheencrypteddatatoaremotefilesystem(i.e.theremotefilesystemcanbeanypublicfilesharingserviceandenduserisfreetochoosehis/herpreferredone,pleasenotethatthisserviceisnotprovidedbyiExec)

Updaterelatedsessiondata(i.e.eachuser’striggeringoftheapplicationisasession)toaSGXbasedsecretmanagementservice.Secretmanagementservicecanbedeployedinaflexibleway:itcanbeatuser’sside,orscheduler’sside(i.e.SGXworkpool).

Step2:UsertriggersthetargetapplicationviasimpleclicksfromtheiExecDappstoreandmarketplaceviaauser-friendlyUIinterface.

OncethetargetapplicationistriggeredatremoteSGXdecentralizednode,theapplicationwillfirstlyautomaticallypulltheencrypteduserinputdatafromremotefilesystem(i.e.pushedinstep1);retrievethesecretkeyviasecuredSGXprovisionchannel,whichisthenusedtodecrypttheuserinputdata,thedecryptionisdoneonlyinsidethehigh-securedtrustedenvironment—SGXenclave;thedecrypteddatacanthenbeusedtofeedtheapplicationexecution,assoonastheapplicationresultisavailable,asignatureisprecededbasedontheprivatekeyprotectedinsidetheSGXenclave,whichcannotbeinspectedbytheoutsideworld.TheapplicationresultisfinallyencryptedandthentheiExec’sverificationprocedure(i.e.ProofofContribution)istriggered.EverythingissecurelyhappenedinsidetheIntelSGXenclaveensuredbyIntelhardwareCPUandnosecretisabletorevealedtotheoutsideworld.

动态 | 英特尔SGX被突破 部分区块链项目受影响:根据coindesk报道,英特尔芯片SGX部分被发现致命漏洞,研究人员找到一种办法可以突破保护从而篡改数据。而一些数字货币项目已经有意使用该硬件来进行安全防护。不过好消息是研究人员在发现后通知了英特尔,而英特尔已经找到一种解决方案,但升级并未全部完成。比特币的核心维护者Wladimir van der Laan回应说:“即使比特币在某种程度上是完美的,但将比特币的安全性根植于芯片供应商某项技术中也绝不是个好主意。”[2018/8/16]

Thesignatureisfinallytransferredtoon-chainnetworkandverifiedbyon-chainsmartcontractviatheregisteredcorrespondingpublickey.Ifthesignatureverificationpassesandapplicationresult’strustlevelachievesagiventhreshold.Theuserwillbeinformedtodownloadtheencryptedresult.

Thewholeprocedureisdoneautomaticallyinahighsecureway,andthisprocedureistriggeredbyonlysomesimpleclicksfromuserviathefriendlyUIinterface.

Fig.1iExec’sE2ESGXworkflow

Step3:Usercandownloadtheencryptedresultpackage,andusercanjustrunonesimplecommandtodecrypttheresult.Pleasenotethatonlytheuserwhotriggersthetask(i.e.SGXapplication)isabletodownloadtheencryptedresult,andonlytheuserownsthekeytodecrypttheapplicationresult.

Pleasenotethattheprocedureisplatformindependent,andthereforeiscompatiblewithdifferentoperatingsystems:Windows,Linux,MacOS.

Inthenearfuture,wewillfurthersimplifyuser’sprocedure—allthethreestepswillbeintegratedintoonesimplestep,andcanbedonebyseveralsimpleclicksfromuserviauserfriendlyuserinterface—https://market.iex.ec/.

2.TheiExecSolutionisSGXVendorAgnostic

TheiExecplatformisopentodifferentSGXsolutionvendors.Specifically,iExechasbeencollaboratingwithSCONEandFortanixtointegratetheirSGXframeworksintoiExec’sE2ESGXsolution.WearealsointhephaseofevaluatingIntel’sPDOframework.Inthefuture,wewillalsoconsidertheSGXframeworkofGraphene/Graphene-ng.AllthemainstreamSGXsolutionswillbe100%compatiblewithiExec’splatform,andwewillleaveiExecDappdevelopersanduserstofreelychoosetheirpreferredSGXframeworks.OurobjectistopromotetheemergenceofanecosystemwhichprovidestrustedexecutionforBlockchainbasedcomputing,andthesetrustedservicecanbemonetizedviaiExec’smarketplace.

3.iExecContributionstowardsIndustryStandardization

iExecarepioneersinthefieldofblockchain-basedTrustComputing,andisveryactiveinleadingandpushingforwardtheindustrialstandardizationforinthiscontextforBlockchaintechnology.

Especially:

iExecisveryactiveinEEA(EnterpriseEthereumAlliance):iExecischairingtheTrustedComputeWorkGroup,andkeepscontributingandpushingforwardtheEEAspecifications,especiallytheOff-chainTrustedComputeSpecificationwhichistobepubliclyreleasedsoon.

iExecisactiveinIEEEaswell.iExecismemberofIEEEP2418,andisinvolvedinIEEEstandardprojectonDLT-basedFederatedIdentity,CredentialandTrustManagement.iExecleadsthestandardizationworkinseveralBlockchainbaseddomains,especiallythesecurityandTEE(TrustedExecutionEnvironment)

iExeciscollaboratingwithhardwaretrustedexecutionvendorstomoveforwardthishardwarebasedsecuritysolution(SGX)tobefullystandard-compliant,staytunedforthecomingupdatesduringDevcon4.

iExecisalsocollaboratingwithourpartnerstomoveforwardthestandardizationforBlockchainbasedFogComputinginthecontextofOpenFogconsortium.SomeresultofthefirststagecollaborationwithourpartnersonFogComputingwillbereleasedsoon,pleasestaytunedinthefollowingdays.

长按扫码关注公众号

点“阅读原文”了解更多

标签:THEIONANDICAether币对人民币汇率Mission HeliosshowhandQubitica

Pol币热门资讯
区块链:为什么我们认为TPS不是最重要的

根据DAppRadar的数据显示,以太坊上所有的DApp的日活合计不达1万。众所周知,底层区块链基础设施性能差是DApp部署的最大障碍,导致了成本高,用户体验差等问题.

1900/1/1 0:00:00
TOKE:(公告)H网第七、八期HTA分红发放公告

尊敬的HashToken用户:您好,H网于新加坡时间2018年10月07日14:00正式发放第八期HTA分红,共计50000HHT/H网通证,以及09月30日第七期HTA分红补发.

1900/1/1 0:00:00
HTT:【系統】BCEX全新上線SPG/CK.USD交易對

尊敬的BCEX用戶:????????BCEX即將上線SPG,開放SPG/CK.USD交易對,具體如下:開放充提時間:2018年10月27日15:00開放交易時間:2018年10月28日18:00.

1900/1/1 0:00:00
TOKE:(公告)热烈祝贺知名区块链项目奥斯卡通(OSSC)即将上线H网

尊敬的HashToken用户:热烈祝贺知名区块链项目铂寓链全球首发即将上线H网。上线Token名称:OSSC.

1900/1/1 0:00:00
NULS:关于NULS测试网v1.0.2-beta上线的公告∣ 该测试环境长期有效

背景2018年9月28日NULS主网上线v1.1.0版本,但在主网运行过程中,发现出现分叉情况后区块回滚处理逻辑有问题,导致不能回滚或者回滚后不能正确出块,对部分用户正常使用钱包造成了一定影响.

1900/1/1 0:00:00
888:周报|知产链IPChain项目进度汇报(10.17-10.23)

呐,等你关注都等出蜘蛛网了~各位IPC知产链的伙伴儿:大家好!区块链+物流,全球首个智能物流“区块链”项目--骊盾通证模型论证会在京举行;现在IPC好物市场也已上线.

1900/1/1 0:00:00