點擊藍字關注我們
英特爾SGX和區塊鏈
iExec端到端解決方案
iExec很榮幸地宣布即將推出首個集成英特爾SGX的端到端解決方案,用于分布式計算的安全技術應用。在2018年10月30日布拉格Devcon4會議上,iExec和英特爾將宣布重大合作新聞。
張磊,iExec安全總監介紹了英特爾SGXEnclave技術,以及如何保證參與區塊鏈網絡的用戶和應用的安全問題,特別是基于區塊鏈的分布式云技術方面。
敬請關注!
正文相關鏈接
IntelSGX:https://software.intel.com/en-us/sgx
Thechallenge:Howcanweguaranteesecurityondecentralizedanddistributednetworks?
Blockchain-basedapplicationsandcomputingarenotownedorcontrolledbyonespecificentitybutratherpoweredbyadistributednetworkofmultiplemachinesor‘nodes’.Thedistributednatureofdecentralizedcloudcomputingnetworkspresentachallengetoguaranteesecurityasanyrootprivilegeusermayeasilyinspectthesensitivedataandtamperwiththeapplicationrunningonthedecentralizedhost.Fortraditionalcentralizedcloudcomputingproviders,itiseasiertoemployexistingsecuritymechanismsprotecttheinvolvedapplication.
Fordecentralizedblockchain-basedclouds,asilicon-basedsecuritysolution,called‘IntelSGX’,istheonlyefficientsolutiontoprotectusersandapplicationsinvolvedinBlockchain-baseddecentralizedcomputing.
IntelSGX(IntelSoftwareGuardExtensions),isasetofCPUinstructioncodesthatenabletheexecutionofselectpiecescodeanddatainprotectedareascalledenclaves.Basically,whileyouhaveanapplicationrunningonahostmachine,SGXenclavesessentiallyactasabubble,isolatingandprotectingtheapplicationfromthehostmachine,inthisway,eventherootprivilegeadministratorofthehostmachineisnotabletopenetratethisbubbletoaccessandtamperwiththeapplication.
Bitcoin Magazine:新的英特爾比特幣礦機比ASIC成本低一半,效率高15%:金色財經報道,Bitcoin Magazine發推稱,新的英特爾比特幣礦機比競爭對手ASIC成本低一半,效率高15%。[2022/2/28 12:29:41]
AnintroductiontoIntelSGXEnclaves-iExecSecurityR&D,LeiZhang
“WhatmakesIntelSGXcompellingisthatitprovidesahardwaretrustedexecutionenvironment(TEE),allowingbetterprotectionsfordatain-use,at-restandin-transit,built-inCPUinstructionsandplatformenhancementsprovidecryptographicassertionsforthecodethatispermittedtoaccessthedata.Ifthecodeisalteredortampered,thenaccessisdeniedandtheenvironmentdisabled.”
—RickEchevarria,VicepresidentofIntel’sSoftwareandServicesGroup.
1.TheiExecE2ESGXsolution
iExecispioneeringthebuildingofablockchain-enableddecentralizedanddistributedcloudnetwork.Theyhavenowprovidedthefirsteverfullandend-to-endsolutionintegratingSGXfortheblockchain-basedcloud.SomeofourinitialworkwithintelSGXcanbereadinthisblogpostandiscoveredinthisvideopresentation.iExecpresentedthefirstphaseofworkonSGXinMarch2018attheIBMThinkConferenceinLasVegasandco-presentedalongsideIntelinMay2018atConsensusinNewYork..Thisfirstphasefocusedontheprotectionofthesecretsbuiltindecentralizedapplications:althoughtheapplicationsrunsondecentralizednodes,theinvolvedsensitivedatacannotbeinspectedoralteredwithbymaliciousattackersonthenetwork.Howeverthefirststageofworkwasbasedonsomesophisticated(raw)frameworksandthefunctionalityofthesolutionwaslimitedtoonlyprotectnativesecretsoftheapplication,furthermorethesolutioncouldbecomplicatedforappdevelopersandusers,especiallyforthosewhoarenotinthefieldofITandcomputing.
傳AMD與英特爾已暫停向俄交付產品:2月27日,據俄媒RBC報道,IT市場兩位消息人士向其證實,AMD和英特爾已暫停向俄羅斯交付其產品。其中一位表示,這些公司口頭告訴俄羅斯制造商,AMD 和英特爾的產品暫時不運往俄羅斯,俄羅斯開發商和電子制造商協會人士也予以證實。英特爾駐俄代表處沒有直接回答其是否停止供應處理器的問題,但表示“公司正在密切關注情況并正在執行適用的制裁和出口管制規則”。 (金十)[2022/2/27 10:19:11]
iExechastocontinuedtomakesignificantcontributions,workingdiligentlywithourpartners,topushforwardapowerfulanduser-friendlyend-to-endSGXsolution.Thissolutionisintendedtobeusedasanindustryreferencetoenhancetheoverallsecurityofdecentralizedcloudcomputing.ThisnewSGXsolution,combinedwithBlockchain,allowsforunmatchedleveloftrustforDecentralizedApplications(Dapps)andexecution/dataprocessingondecentralizednodes.TheiExecapproachspecificallyallowsBlockchaintoworkwithSGXinorderto:
ProtecttheDAppandprovidefulldataprotectionthatcannotbeaccessedbytheexecutionhost,especiallyforuser’sinputandoutputdata.
GuaranteetheintegrationoftheDapp/Data,makingsurethecorrectandexpectedDApporDataisrunningonthedecentralizednode.
Provideblockchain-basedvalidationforoff-chaincomputing,verifyingthattheDappiscorrectlyexecutedinanenclaveandisneithertamperednorinterruptedbythedecentralizednode.Asmart-contractsignatureissignedinsidethissecureenclavebeforetheverificationisdonebytheblockchainnetwork.
英特爾和微軟攜手打擊加密劫持:金色財經報道,英特爾和微軟正攜手打擊惡意加密貨幣挖礦。用于幫助抵御高級安全威脅的企業級解決方案Microsoft Defender for Endpoint已擴大了英特爾威脅檢測技術(TDT)的使用范圍,以打擊非法加密貨幣挖礦(即“加密劫持”)。該解決方案依靠遙測數據來檢測CPU性能中的任何異常情況。與其他類型的防御不同,TDT能夠在惡意軟件設法感染受害者的計算機以挖掘加密貨幣之前對其進行檢測。[2021/4/27 21:01:36]
MakesuretheexecutionandDAppresultisvalid,neithercopied,norfabricatedbymaliciousdecentralizednode.
Protecttheend-to-endprivacyofDAppresult,whichcanneverbeinspectedbyanyoneelsebuttheuser.
Afriendly-userinterface:significantsimplificationforuserstoencrypt/decrypttheinput/outputdataandtriggertheSGXapplicationexecution.
EasyusabilityisakeyelementofUserExperience;withthenewiExecE2ESGXsolution,useronlyneeds3simplestepstorunanE2ESGXapplicationandtoprovideafullprotectionofuser’sinputandoutputdata.
Let’sthinkaboutatypicalSGXapplication,sayforexampleaFinTechapplication.Theapplicationisfedbysomeuserinputdatawhichcontainssomeuser’spersonalandsensitivesecrets(e.g.bankaccountinformation,personalprivacy,etc…),theoutputresultsoftheapplicationalsocontainsomesensitivedataandareonlyintendedtouserwhotriggerstheapplication.Theinputdataandtheoutputresultsneedtobestrictlyprotectedduringthewholeprocedure.Thenon-encryptedsensitivedataneverleavesuserlocalscopeorhigh-securedtrustedexecutionenvironment:SXGenclave.Hereisagenericdescriptionofthe3simplestepsofiExec’sSGXsolution.
英特爾吳聞新:借助區塊鏈技術,幫助pc租賃市場的健康發展:5月27日,“英特爾X螞蟻區塊鏈普惠科技助力中小發布會直播”在線上進行。在圓桌論壇《新基建浪潮下,普惠科技為中小企業帶來的發展新機遇》中,英特爾行業解決方案集團首席技術官吳聞新指出,在PC租賃的市場,借助區塊鏈技術,使得在這一鏈條上的數據是分布式的且不可篡改的,幫助pc租賃市場的健康發展。英特爾提供了一個技術平臺的支撐,幫助整個PC租賃市場相對健康發展。信息技術是一個高科技,但信息技術的服務并不是高高在上的服務,中小企業可以利用我們的租賃平臺,可以在較低成本下使用科技的便利,透過這個平臺英特爾通過現有技術能力幫助中小企業解決在使用電腦過程中的一些問題,促進企業用起來且用的好。[2020/5/27]
Step1:Useronlyneedstorunonesimplecommandwhichallowstoautomatically:
Encryptuser’sinputdata
Pushtheencrypteddatatoaremotefilesystem(i.e.theremotefilesystemcanbeanypublicfilesharingserviceandenduserisfreetochoosehis/herpreferredone,pleasenotethatthisserviceisnotprovidedbyiExec)
Updaterelatedsessiondata(i.e.eachuser’striggeringoftheapplicationisasession)toaSGXbasedsecretmanagementservice.Secretmanagementservicecanbedeployedinaflexibleway:itcanbeatuser’sside,orscheduler’sside(i.e.SGXworkpool).
Step2:UsertriggersthetargetapplicationviasimpleclicksfromtheiExecDappstoreandmarketplaceviaauser-friendlyUIinterface.
OncethetargetapplicationistriggeredatremoteSGXdecentralizednode,theapplicationwillfirstlyautomaticallypulltheencrypteduserinputdatafromremotefilesystem(i.e.pushedinstep1);retrievethesecretkeyviasecuredSGXprovisionchannel,whichisthenusedtodecrypttheuserinputdata,thedecryptionisdoneonlyinsidethehigh-securedtrustedenvironment—SGXenclave;thedecrypteddatacanthenbeusedtofeedtheapplicationexecution,assoonastheapplicationresultisavailable,asignatureisprecededbasedontheprivatekeyprotectedinsidetheSGXenclave,whichcannotbeinspectedbytheoutsideworld.TheapplicationresultisfinallyencryptedandthentheiExec’sverificationprocedure(i.e.ProofofContribution)istriggered.EverythingissecurelyhappenedinsidetheIntelSGXenclaveensuredbyIntelhardwareCPUandnosecretisabletorevealedtotheoutsideworld.
英特爾聯手螞蟻金服助力產業升級 雙方進行普惠科技戰略合作簽約:5月27日,“英特爾X螞蟻區塊鏈普惠科技助力中小發布會直播”在線上進行。螞蟻集團副總裁、螞蟻智能科技事業群總裁蔣國飛與英特爾公司市場營銷集團副總裁、中國區行業解決方案總經理梁雅莉進行普惠科技戰略合作簽約。英特爾商用客戶端技術+螞蟻金服區塊鏈創造新型商業模式,租賃—設備即服務(DaaS),解決租賃企業痛點,加速中小企業數字化轉型,助力中小企業創造商機,為中小企業減負。[2020/5/27]
Thesignatureisfinallytransferredtoon-chainnetworkandverifiedbyon-chainsmartcontractviatheregisteredcorrespondingpublickey.Ifthesignatureverificationpassesandapplicationresult’strustlevelachievesagiventhreshold.Theuserwillbeinformedtodownloadtheencryptedresult.
Thewholeprocedureisdoneautomaticallyinahighsecureway,andthisprocedureistriggeredbyonlysomesimpleclicksfromuserviathefriendlyUIinterface.
Fig.1iExec’sE2ESGXworkflow
Step3:Usercandownloadtheencryptedresultpackage,andusercanjustrunonesimplecommandtodecrypttheresult.Pleasenotethatonlytheuserwhotriggersthetask(i.e.SGXapplication)isabletodownloadtheencryptedresult,andonlytheuserownsthekeytodecrypttheapplicationresult.
Pleasenotethattheprocedureisplatformindependent,andthereforeiscompatiblewithdifferentoperatingsystems:Windows,Linux,MacOS.
Inthenearfuture,wewillfurthersimplifyuser’sprocedure—allthethreestepswillbeintegratedintoonesimplestep,andcanbedonebyseveralsimpleclicksfromuserviauserfriendlyuserinterface—https://market.iex.ec/.
2.TheiExecSolutionisSGXVendorAgnostic
TheiExecplatformisopentodifferentSGXsolutionvendors.Specifically,iExechasbeencollaboratingwithSCONEandFortanixtointegratetheirSGXframeworksintoiExec’sE2ESGXsolution.WearealsointhephaseofevaluatingIntel’sPDOframework.Inthefuture,wewillalsoconsidertheSGXframeworkofGraphene/Graphene-ng.AllthemainstreamSGXsolutionswillbe100%compatiblewithiExec’splatform,andwewillleaveiExecDappdevelopersanduserstofreelychoosetheirpreferredSGXframeworks.OurobjectistopromotetheemergenceofanecosystemwhichprovidestrustedexecutionforBlockchainbasedcomputing,andthesetrustedservicecanbemonetizedviaiExec’smarketplace.
3.iExecContributionstowardsIndustryStandardization
iExecarepioneersinthefieldofblockchain-basedTrustComputing,andisveryactiveinleadingandpushingforwardtheindustrialstandardizationforinthiscontextforBlockchaintechnology.
Especially:
iExecisveryactiveinEEA(EnterpriseEthereumAlliance):iExecischairingtheTrustedComputeWorkGroup,andkeepscontributingandpushingforwardtheEEAspecifications,especiallytheOff-chainTrustedComputeSpecificationwhichistobepubliclyreleasedsoon.
iExecisactiveinIEEEaswell.iExecismemberofIEEEP2418,andisinvolvedinIEEEstandardprojectonDLT-basedFederatedIdentity,CredentialandTrustManagement.iExecleadsthestandardizationworkinseveralBlockchainbaseddomains,especiallythesecurityandTEE(TrustedExecutionEnvironment)
iExeciscollaboratingwithhardwaretrustedexecutionvendorstomoveforwardthishardwarebasedsecuritysolution(SGX)tobefullystandard-compliant,staytunedforthecomingupdatesduringDevcon4.
iExecisalsocollaboratingwithourpartnerstomoveforwardthestandardizationforBlockchainbasedFogComputinginthecontextofOpenFogconsortium.SomeresultofthefirststagecollaborationwithourpartnersonFogComputingwillbereleasedsoon,pleasestaytunedinthefollowingdays.
長按掃碼關注公眾號
點“閱讀原文”了解更多
尊敬的用戶: 香港CEO交易所旗下品牌CEO、COO今日分紅于2018年10月10日14:00發放.
1900/1/1 0:00:00尊敬的用戶: ????鑒于平臺用戶的飛速增長和社群用戶的強烈呼吁,平臺決定新上線一批幣種,以豐富廣大用戶的交易選擇,豐富平臺現有交易對.
1900/1/1 0:00:00親愛的用戶:?? IDAX將上線MEDIBIT。開通MEDIBIT/BTC、MEDIBIT/ETH交易,立即前往.
1900/1/1 0:00:00致我們各位亦來云社區成員:啟動亦來云是我一生引以為傲的工作。這項工作致力于構建我們的下一代區塊鏈驅動的智能互聯網、配套的互聯網設施,以及強大的社區自運營組織.
1900/1/1 0:00:0010月9日,福建省發展和改革委員會黨組成員、副主任詹晨輝一行蒞臨沃爾頓鏈中國技術支持方思力科旗下艾歐特科技有限公司調研指導.
1900/1/1 0:00:00親愛的用戶:?? ??IDAX將上線ANON。開通ANON/BTC、ANON/ETH交易。??充值開放時間:10月13日23:00(UTC08:00)??交易開放時間:10月14日23:00(U.
1900/1/1 0:00:00