Phala Network is a blockchain-based confidential computing cloud. This repo includes:
node/
: the main blockchain built on Substratestandalone/pherry/
: the message relayer to connect the blockchain and pRuntimestandalone/pruntime/
: the contract execution kernel running inside TEE enclave
The blockchain is the central component of the system. It records commands (confidential contract invocation), serves as the pRuntime registry, runs the native token and on-chain governance modules.
pherry is the message relayer. It connects the blockchain and pRuntime. It passes the block data from the chain to pRuntime and passes pRuntime side effects back to the chain. A multi-client version of the runtime bridge is being developed here and now in alpha version.
pRuntime (Phala Network Secure Enclave Runtime) is a runtime to execute confidential smart contracts, based on confidential computing.
Expand
-
Rust
curl https://sh.rustup.rs -sSf | sh
-
Substrate dependencies:
git submodule update --init sh ./scripts/init.sh
-
LLVM 10
wget https://apt.llvm.org/llvm.sh chmod +x llvm.sh ./llvm.sh 10
-
Protobuf Compiler
- Ubuntu
apt install -y protobuf-compiler
- macOS
brew install protobuf
- See here for more options
Make sure you have Rust and LLVM-10 installed.
Note for Mac users: you also need
llvm
andbinutils
from Homebrew or MacPort, and to add their binaries to your $PATH
Run git submodule update --init
to fetch submodules before build if you haven't add option --recursive
when clone code.
cargo build --release
The build script enforces LLVM-10 or newer is used. LLVM-10 is needed because of the wasm port of rust
crypto library, ring
. We have to compile the C code into wasm while keeping the compatibility with
the current rustc.
-
Launch a dev node:
./target/release/phala-node --dev
- Can be purged by
./target/release/phala-node purge-chain <args like --dev>
- The Polkadot.js UI can connect to the node at port 9944.
- Can be purged by
-
Compile & launch pRuntime (Simulation mode)
cd standalone/pruntime mkdir -p data cargo run
-
Compile & launch pRuntime (Hardware mode)
Apply for Remote Attestation API keys at Intel IAS service. The SPID must be linkable.
Follow gramine's document to install the gramine toolchain.
After installing the toolchain, you can graminify and run the pRuntime.
export SGX_SIGNER_KEY=path/to/your/key.pem export IAS_SPID=your_spid export IAS_API_KEY=your_api_key_in_hex cd standalone/pruntime/gramine-build make run
-
Run pherry (node and pRuntime required):
./target/release/pherry --dev --no-wait
-
Web UI (TODO: still being refactored)
- phala-wiki: The technical documentation.
- phala-docker: The production dockerfiles, including the blockchain, pherry, and pRuntime.
- Code Bounty Program
- Responsible Disclosure