PROVISION OF DATA TO BE PROTECTED IN A SECURE EXECUTION ENVIRONMENT OF A DATA PROCESSING SYSTEM

DE502022003771D1Active Publication Date: 2025-05-15SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022003771
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-03-24
Filing Date
2022-03-07
Publication Date
2025-05-15
Estimated Expiration
2042-03-07

AI Technical Summary

Technical Problem

Existing methods for protecting sensitive code or data on external devices fail to provide a high level of protection while maintaining resource efficiency, as they often require decryption keys to be available on the external device, making them vulnerable to misuse and reverse engineering.

Method used

A procedure that utilizes a secure execution environment, such as a Trusted Execution Environment (TEE), to execute enclave code, generate a key pair, and encrypt data using a hybrid encryption process, ensuring that sensitive data is protected and only accessible within the secure environment.

Benefits of technology

This approach provides a high level of protection for sensitive code or data by ensuring that it remains encrypted and accessible only within the secure execution environment, while maintaining resource efficiency and preventing misuse on external devices.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND OF THE INVENTION Field of the invention

[0001] The invention provides a method for providing data to be protected in a secure execution environment of a data processing system. Furthermore, the invention provides a data processing system, a computer program product, and a computer-readable medium. Description of the state of the art

[0002] When delivering code and / or data to "third-party devices," the creator of the code or data often faces a dilemma: On the one hand, the code or data must be available there and function as intended to serve the intended use case. On the other hand, it may contain sensitive information (e.g., company know-how) that one would prefer to keep secret from the user or a platform operator, especially a cloud provider.

[0003] In principle, the "third-party device" can be any type of information processing system that the creator or owner of the code or data does not have full control over and where there is a possibility of misuse of the code or data, particularly through analysis / reverse engineering, modification, cloning, etc.; in particular, a server in the cloud, but also a user's private PC.

[0004] In this case, simply encrypting the code or data used and decrypting it again when needed using software developed according to standard programming standards is insufficient, since then all information, especially the keys necessary to decrypt the code or data, must obviously be available in this software and thus on the third-party device. In this case, the software and possibly also the decrypted form of the code or data it outputs would become the target of an attack.

[0005] One of the main approaches to protecting software or the data it handles is obfuscation, i.e. the transformation of code and data into an equivalent, but more difficult to understand form. Some automated tools available on the market allow this transformation step to be carried out with comparatively little effort; however, obfuscation naturally only takes place at a very general level - in particular by translating the machine code instructions 1:1 into the corresponding instructions for a virtual machine with its own instruction set - which limits the achievable level of protection. More sophisticated obfuscation techniques usually start at the algorithmic level and logically change the program steps there. However, this often requires very complex, algorithm-specific work steps. In general, obfuscation at a higher level (i.e."good" obfuscation with a high level of protection) usually leads to a significantly increased resource consumption in terms of memory and runtime of the software.

[0006] The object of the invention is to provide a generally applicable solution with a high level of protection and low resource requirements for making sensitive code or data executable or analyzable on a third-party device without disclosing the code or data itself. US2020287901 discloses an out-of-band authentication that uses a secure communication channel to a secure execution environment (TEE). The TEE provides a public key for the provision of secured data by external participants.

[0007] XP055543828 discloses the interoperation of an insecure execution environment with a TEE using attestation and obfuscation.

[0008] US2021064765 discloses the protection of program code on external systems by a TEE using attestation and obfuscation. SUMMARY OF THE INVENTION

[0009] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention will become apparent from the following description and the drawings.

[0010] The invention relates to a method for providing data to be protected in a secure execution environment of a data processing system.

[0011] The procedure includes the following steps: Executing an enclave code in the secure execution environment, generating a key pair by the enclave code, wherein the key pair comprises a public key and a private key, sending the public key to an insecure execution environment of the data processing system, wherein the insecure execution environment is outside the secure execution environment, sending the public key and sending first encrypted data to an obfuscate program code, wherein the obfuscate program code is provided by the insecure execution environment, verifying the public key by the obfuscate program code, and depending on the results of the verification, converting the first encrypted data into second encrypted data, wherein the second encrypted data is encrypted with the public key,Sending the second encrypted data to the enclave code in the secure execution environment and decrypting the second encrypted data into the data to be protected using the private key by the enclave code in the secure execution environment.

[0012] The data to be protected can then be processed in the secure execution environment by the enclave code.

[0013] One aspect of the invention is to decrypt data to be protected directly on a third-party device, but to make it available there only for enclave code in a secure execution environment, while re-encrypting the data to be protected takes place in an insecure execution environment.

[0014] In a further development of the invention, an access restriction to the secure execution environment is provided, which denies the insecure execution environment access to the secure execution environment. This has the advantage that an attacker cannot access the secure execution environment and the data contained therein.

[0015] Thus, according to the invention, for the protection of the data to be protected, in particular a code to be protected, it is assumed that a secure execution environment, a so-called Trusted Execution Environment (TEE), is present on the data processing system, in particular a third-party device, which differs from an insecure (i.e. controlled by the user / platform operator) execution environment on the data processing system by the following properties.

[0016] The secure execution environment allows enclave code, particularly in an enclave, to be executed whose memory contents are not accessible from another enclave or the insecure execution environment (neither by other running applications nor by the operating system of the data processing system).

[0017] Furthermore, the secure execution environment offers the enclave code running within the enclave the ability to attest to the outside world, i.e., to the insecure execution environment or outside the data processing system, that certain data, particularly cryptographic keys, were generated by the unmodified enclave code within the enclave in the secure execution environment. This attestation can be verified externally by code, particularly obfuscated program code, which can be developed without specific knowledge of the data processing system. However, the obfuscated program code may receive information about the data processing system as input at runtime.

[0018] Thus, obfuscated program code is implemented for execution in the insecure execution environment of a data processing system, in particular a third-party device, with the following properties.

[0019] The obfuscated program code can verify the attestation of a public key generated by the enclave code using the properties mentioned in the previous paragraph. Thus, the obfuscated program code verifies whether the public key was generated in a secure execution environment (by a trusted enclave).

[0020] If the attestation was successful, obfuscated program code encrypts first encrypted data, especially pre-encrypted data, into second encrypted data.

[0021] In an advantageous embodiment of the invention, this is done with a symmetric decryption function Dec_sym under a symmetric key K_sym together with an asymmetric encryption Enc_asym by means of D'=Enc_asym(Dec_sym(D'', K_sym), K_pub), with D' = second encrypted data, and D'' = first encrypted data. Note: Dec_sym(D'', K_sym)=D.

[0022] In an advantageous embodiment of the invention, Enc_asym is a hybrid encryption method in which a symmetric key randomly generated at the time of encryption is encrypted with K_pub, which in turn is used, particularly for performance and resource reasons, to encrypt the payload of the data to be protected.

[0023] Due to the obfuscation applied by the obfuscated program code, the above-mentioned subfunctions, in particular the verification of the attestation, the symmetric decryption of the first encrypted data into the data to be protected, and the hybrid encryption of the data to be protected into the second encrypted data in the obfuscated program code, are neither analyzable nor separable for an attacker. In particular, it is not possible for an attacker to deduce their logical counterparts, in particular decrypted portions of the data to be protected, from obfuscated intermediate results of the subfunctions.

[0024] Nor can the attestation verification of the public key in the obfuscated code be manipulated in such a way that a non-attested or incorrectly attested public key can be used to generate the output of the second encrypted data. This must be prevented, because otherwise an attacker could decrypt the second encrypted data using the private counterpart of the non-attested public key.

[0025] The steps mentioned for creating the obfuscated program code only need to be performed once per key K_sym and can be carried out without knowledge of the data processing system, in particular of the third-party devices on which the obfuscated program code will later be used.

[0026] In particular, the same obfuscated program code can be deployed on various third-party devices. For attestation, only a small portion of the obfuscated program code needs to be adapted to the enclave code, specifically in the form of a constant that corresponds to a hash of the enclave code and can be used during attestation verification to determine the integrity (i.e., "unchanged") of the enclave code.

[0027] The data to be protected is pre-encrypted into the first encrypted data before being transferred to the data processing system. In an advantageous embodiment of the invention, this is done using the symmetric encryption function. This step only needs to be performed once per data record of the data to be protected, provided the symmetric key K_sym remains the same. This step can also be performed without knowledge of the third-party devices on which the obfuscated program code will later be used. In particular, the same obfuscated program code can be used on various third-party devices.

[0028] For each third-party device, the obfuscated program code and the first encrypted data are transferred to the insecure execution environment, either online or offline, e.g., via an installation disk, which may also contain additional software intended to use the results calculated by the enclave code based on the data to be protected.

[0029] In a variant of the invention, sending the second encrypted data from the obfuscated program code to the insecure execution environment may take place before sending the second encrypted data to the enclave in the secure execution environment.

[0030] In a further development of the invention, the data processing system is designed as: Server, cloud server, third-party system, computer and / or mobile information processing device.

[0031] In a further development of the invention, the secure execution environment is designed as a Trusted Execution Environment (TEE).

[0032] In a further development of the invention, the enclave code is configured to generate random numbers, with at least one of the random numbers being used to generate the asymmetric key pair. The random numbers can be true random numbers or pseudorandom numbers, whereby the pseudorandom number generation must be based on a secret (seed) known only within the enclave. The random numbers are unpredictable, even with knowledge of the enclave code.

[0033] In a further development of the invention, the second encrypted data is encrypted using a hybrid encryption method. If the attestation was successful, obfuscated program code encrypts the first encrypted data, in particular pre-encrypted data, to convert it into second encrypted data.

[0034] In an advantageous embodiment of the invention, this is done with a symmetric decryption function Dec_sym under a symmetric key K_sym together with an asymmetric encryption Enc_asym by means of D'=Enc_asym(Dec_sym(D'', K_sym), K_pub), with D' = second encrypted data, and D'' = first encrypted data. Note: Dec_sym(D'', K_sym)=D and D''=Enc_sym(D, K_Sym) with the encryption function Enc_sym being inversely symmetric to Dec_sym.

[0035] In an advantageous embodiment of the invention, Enc_asym is a hybrid encryption method in which a symmetric key randomly generated at the time of encryption is encrypted with K_pub, which in turn is used, particularly for performance and resource reasons, to encrypt the payload of the data to be protected. In a variant of this embodiment, the symmetric key for the hybrid encryption method is not randomly generated, but deterministically derived using a process kept secret by the obfuscated code. This means that the invention can also be used when a truly random (non-deterministic) generation of a key is not possible in the insecure execution environment. The first encrypted data D'' or the decrypted data D can be included in the derivation process. This guarantees that for different data D'' orD a different symmetric key is used for the hybrid encryption method.

[0036] In a further development of the invention, the first encrypted data is stored on the data processing system in the insecure working environment. The first encrypted data can thus be stored on the data processing system once and in advance.

[0037] In a further development of the invention, asymmetric encryption and decryption functions are used instead of the symmetric encryption and decryption functions enc_sym and dec_sym (possibly different from enc_asym and dec_asym). However, the complexity of asymmetric methods in obfuscated program code is likely to lead to increased resource requirements in terms of memory and runtime.

[0038] In a further development of the invention, obfuscated intermediate results are created when converting the first encrypted data into second encrypted data. Due to the obfuscation applied by the obfuscated program code, the above-mentioned subfunctions, in particular the verification of the attestation, the symmetric decryption of the first encrypted data into the data to be protected, and the hybrid encryption of the data to be protected into the second encrypted data, are neither analyzable nor separable from one another in the obfuscated program code by an attacker. In particular, it is not possible for an attacker to deduce the logical counterpart, in particular decrypted portions of the data to be protected, from obfuscated intermediate results of the subfunctions.

[0039] In a further development of the invention, when verifying the public key, the obfuscated program code checks whether a valid attestation of the public key exists. The conversion of the first encrypted data into the second encrypted data is only performed if a valid attestation is present. The obfuscated program code can verify the attestation of a public key generated by the enclave code using the properties mentioned in the previous paragraph. Thus, the obfuscated program code verifies the public key to determine whether the attestation was created in a secure execution environment (by a trusted enclave).

[0040] If the attestation was successful, obfuscated program code encrypts first encrypted data, especially pre-encrypted data, into second encrypted data.

[0041] In a further development of the invention, the obfuscated code is stored on the data processing system in the insecure working environment. The obfuscated code is thus stored once and in advance on the data processing system, just like the first encrypted data.

[0042] In a further development of the invention, the data to be protected are: Program code, interpretable code, parameterizations for algorithms, numerical data and / or weights of a neural network, trained.

[0043] The distinction between whether the data to be protected is code or data can be considered fluid. The invention is also applicable, for example, if the secure execution environment, in particular TEE, does not support the execution of externally introduced native code, i.e., code that is not part of the fixed enclave code. In this case, the data to be protected can be interpretable code, also referred to as data, which is implemented within the enclave by an interpreter contained in the enclave code. Furthermore, several different data sets D1, D2, etc. to be protected can be used simultaneously with the same obfuscated program code.

[0044] In another application example, the data to be protected may be parameterizations of algorithms that are necessary for their efficient execution, especially in condition monitoring systems and for predictive maintenance.

[0045] In a further application example, the data to be protected may include executable or interpretable code that includes internal company know-how, in particular trade secrets, which is protected by execution or interpretation in the secure execution environment, in particular a trusted execution environment.

[0046] In a further development of the invention, the execution of the enclave code, as mentioned above, is carried out in an enclave, wherein the enclave is provided by the secure execution environment.

[0047] The invention also includes a data processing system for implementing a method according to the invention. The data processing system has the following components: a secure execution environment, wherein the secure execution environment is configured to: execute an enclave code, thereby generating a key pair, wherein the key pair comprises a public key and a private key, send the public key, an insecure working environment, wherein the insecure execution environment is located outside the secure execution environment, wherein the insecure working environment is configured to receive the public key, an obfuscate program code, wherein the obfuscate program code is located within the insecure execution environment, wherein the insecure execution environment is configured to send the public key and first encrypted data to the obfuscated program code, wherein the obfuscated program code is configured to perform a verification of the public key and, depending on the results of the verification, to perform a conversion of the first encrypted data into second encrypted data, wherein the second encrypted data is encrypted with the public key, wherein the obfuscated program code is further configured to send the second encrypted data, and wherein the secure execution environment is configured to receive the second encrypted data and to decrypt the second encrypted data using the enclave code.

[0048] The invention also comprises a computer program product comprising a computer program, wherein the computer program is loadable into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit.

[0049] The invention further comprises a computer-readable medium on which a computer program is stored, wherein the computer program can be loaded into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit.

[0050] It should be noted that at first glance, it might seem possible that the obfuscated program code could run directly as part of the enclave code in the secure execution environment, specifically in an enclave, instead of in the insecure execution environment. After successfully verifying that the enclave code, which in this case would contain the obfuscated program code, runs unchanged in the enclave, the first encrypted data could be decrypted into the data to be protected (eliminating the need for conversion to the second encrypted data). The problem is that having the obfuscated program code as part of the enclave code creates a reflexivity problem: As soon as the obfuscated program code specifies what the unmodified enclave code must look like, specifically based on a hash of the enclave code that is confirmed during attestation, the enclave code also changes.Regardless of this fundamental problem, depending on the circumstances of the secure execution environment, it may also generally make sense to run the obfuscation code outside the secure execution environment, particularly due to resource bottlenecks or restrictions on the form of the obfuscation code.

[0051] The invention offers the advantage that any content, in particular data to be protected, which can also be embodied as code, can be distributed pre-encrypted to third-party devices and securely converted there using obfuscated code for use within a secure execution environment, in particular a TEE. The data processing system, in particular the third-party devices, do not need to be known in advance.

[0052] The invention offers the further advantage that both the encryption and the decision as to whether such encryption is permitted at all are performed in obfuscated code locally on the data processing system, particularly on the third-party device. Consequently, no connection to a trusted remote site is necessary, which offers advantages in terms of availability for the user and advantages in terms of handling for the distributor / creator of the content.

[0053] The invention offers the further advantage that the obfuscation can be designed in such a way that it encrypts for any enclaves that can present a suitable certificate, ie the obfuscation then only has to be carried out once for different third-party devices.

[0054] The invention offers the further advantage that the obfuscation code can be applied to any pre-encrypted data, ie even with multiple (e.g. temporally offset) distributed contents, the obfuscation only needs to be performed once.

[0055] The invention offers the further advantage that, compared to the obfuscation of the application-specific code running in the enclave or the data processed there, much individual effort is eliminated, since the method according to the invention can be applied generically.

[0056] The invention offers the further advantage that it is a pure software solution, i.e. no additional hardware dongle is necessary.

[0057] The aforementioned advantages of the invention are achieved by the fact that the joint obfuscation of the verification of the attestation of the public key and the conversion of the first encrypted data into the second encrypted data in an inseparable block, the obfuscate program code, allows this block to be executed even in untrusted, insecure environments. Assuming good obfuscation techniques, an attacker cannot separate the two individual operations from each other, nor can he manipulate the obfuscate program code in such a way that it would accept forged, i.e., incorrectly attested, asymmetric public keys. This ensures that the security-critical conversion of the first encrypted data into the second encrypted data only occurs for public keys that are known exclusively in the enclave of the secure execution environment.

[0058] Because the public key was generated within the secure execution environment of a data processing system, in particular an individual third-party device, but the attestation can be verified with obfuscated program code independent of the specific data processing system, the same obfuscated program code can be used for various third-party devices. The conversion of the first encrypted data into the second encrypted data by the obfuscated program code does not depend on the specific data to be protected or the first encrypted data, so the obfuscated program code can also be reused for different data to be protected.

[0059] Furthermore, the obfuscation code does not depend on the application-specific part of the enclave code running in the enclave and can therefore be used generically across many applications.

[0060] In addition, the method according to the invention enables a comparatively cost-effective approach to protecting company know-how in data to be protected, in particular code, which is present or must be executed on previously unknown third-party devices, compared to individual obfuscation. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.

[0062] It shows Fig. 1 is a flowchart of the method according to the invention and Fig. 2 is the sequence of an inventive method in a data processing system according to the invention. DETAILED DESCRIPTION OF THE INVENTION

[0063] Fig. 1 shows a flowchart of the method according to the invention for providing data D to be protected in a secure execution environment TEE of a data processing system F and Fig. 2 shows the sequence of a method according to the invention using a data processing system according to the invention.

[0064] According to Fig. the method comprises the following steps. The components are each in Fig. 2 shown. Step S1: Execution of an enclave code C in the secure execution environment TEE, Step S2: Generation S2 of a key pair K_pub / K_priv by the enclave code C, wherein the key pair K_pub / K_priv has a public key K_pub and a private key K_priv, Step S3: Sending the public key K_pub to an insecure execution environment U of the data processing system F, wherein the insecure execution environment U lies outside the secure execution environment TEE, Step S4: Sending the public key K_pub and sending first encrypted data D'' to an obfuscate program code O, wherein the obfuscate program code O is provided by the insecure execution environment U, Step S5: Verification of the public key P_pub by the obfuscate program code O and, depending on the results of the verification, conversion of the first encrypted data D'' into second encrypted data D',where the second encrypted data D' is encrypted with the public key K_pub, Step S6: Sending the second encrypted data D' to the enclave E in the secure execution environment TEE and Step S7: Decrypting the second encrypted data D' into the data D to be protected.

[0065] The data processing system F for executing a procedure according to Fig. 1 has the following components: a secure execution environment TEE, wherein the secure execution environment TEE is designed to: execute an enclave code C, thereby generating a key pair K_pub / K_priv, wherein the key pair K_pub / K_priv has a public key K_pub and a private key K_priv, send the public key K_pub, an insecure working environment U, wherein the insecure execution environment U is outside the secure execution environment TEE, wherein the insecure working environment U is designed to receive the public key K_pub, an obfuscate program code O, wherein the obfuscate program code O is located within the insecure execution environment U, wherein the insecure execution environment U is designed to send the public key K_pub and first encrypted data D'' to the obfuscate program code O, wherein the obfuscate program code O is designed to verify the public key K_pub and, depending on the results of the verification, to convert the first encrypted data D'' into second encrypted data D', wherein the second encrypted data D' is encrypted with the public key K_pub, wherein the obfuscate program code O is also designed to send the second encrypted data D', and wherein the secure execution environment TEE is designed to receive the second encrypted data D' through the enclave E and to decrypt the second encrypted data D'.

[0066] The execution of the enclave code C is performed in an enclave E, where the enclave E is provided by the secure execution environment TEE

[0067] A specific embodiment of the invention is described below. A key subfunction in a piece of software that the manufacturer offers for public sale is calculated by a neural network. The weights learned by the network contain proprietary know-how of the manufacturer, so they should not be disclosed. However, the software should, of course, run correctly on the buyers' devices; therefore, the neural network, along with the input for the function, must be able to be evaluated in some form.

[0068] To date, software has not made any use of a Trusted Execution Environment (TEE), meaning the entire code runs in an insecure execution environment (U). This makes it easy for an attacker or potential competitor to acquire the software for execution on their own device and analyze its execution, including the evaluation of the neural network. This problem can be solved with the method of the invention, provided that the purchaser's devices are equipped with a TEE that meets the requirements described in the invention.

[0069] The weights of the neural network correspond to the data D to be protected. During the software development process, they are pre-encrypted with a symmetric key into the first encrypted data D'', and obfuscated program code O is created. Both the first encrypted data D'' and the obfuscated program code O are stored on the data processing system F.

[0070] The enclave code C is implemented in such a way that, after decrypting the second encrypted data D' into the data D to be protected (i.e., the weights of the neural network), it can perform the evaluation of the neural network for any inputs received from the insecure execution environment U and return the result to the insecure execution environment U in the secure execution environment TEE.

[0071] The part of the software that previously evaluated the neural network for a specific input is replaced by one that forwards the input to the enclave code C and receives the result from there.

[0072] The entire software, including the obfuscated program code O, the enclave code C and the first encrypted data D'', can be delivered to customers in one go as before, e.g. via installation disk or download.

[0073] The weights D of the neural network are present in the insecure execution environment U in the encrypted form D'', while the decrypted weights are only present within the enclave code C, which is not accessible to anyone there - not even the user.

[0074] Although the invention has been illustrated and described in detail by the embodiments, the invention is not limited by the disclosed examples and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.

Claims

1. Method for providing data (D) to be protected in a secure execution environment (TEE) of a data processing system (F), comprising the steps: - executing (S1) an enclave code (C) in the secure execution environment (TEE), - generating (S2) a key pair (K_pub / K_priv) by means of the enclave code (C), wherein the key pair (K_pub / K_priv) comprises a public key (K_pub) and a private key (K_priv), - sending (S3) the public key (K_pub) to an insecure execution environment (U) of the data processing system (F), wherein the insecure execution environment (U) is outside the secure execution environment (TEE), - sending (S4) the public key (K_pub) and sending first encrypted data (D'') to an obfuscated program code (0), wherein the obfuscated program code (0) is part of the insecure execution environment (U), - verifying (S5) the public key (P_pub) by means of the obfuscated program code (0) and, depending on results of the verification, converting the first encrypted data (D'') into second encrypted data (D'), wherein the second encrypted data (D') are encrypted with the public key (K_pub), wherein, when the public key (K_pub) is verified by the obfuscated program code (0), a check is made to determine whether a valid attestation of the public key (K_pub) is present, and wherein the conversion of the first encrypted data (D'') into the second encrypted data (D') is carried out only if a valid attestation is present, - sending (S6) the second encrypted data (D') to the enclave (E) in the secure execution environment (TEE), - decrypting (S7) the second encrypted data (D') into the data (D) to be protected, and - executing or interpreting the data to be protected in the secure execution environment.

2. Method according to Claim 1, wherein the data processing system (F) is configured as a: - server, - cloud server, - third-party system, - computer and / or - mobile information processing device.

3. Method according to one of the preceding claims, wherein there is restricted access to the secure execution environment (TEE) that denies the insecure execution environment (U) access to the secure execution environment (TEE).

4. Method according to one of the preceding claims, wherein the enclave code (C) is configured to generate random numbers, wherein at least one of the random numbers is used to generate the key pair (K_pub / K_priv).

5. Method according to one of the preceding claims, wherein the second encrypted data (D') are encrypted using a purely asymmetric or hybrid encryption method.

6. Method according to one of the preceding claims, wherein the first encrypted data (D'') are stored on the data processing system (F) in the insecure working environment (U).

7. Method according to one of the preceding claims, wherein the key pair (K_pub / K_priv) is configured as an asymmetric key pair.

8. Method according to one of the preceding claims, wherein during the conversion of the first encrypted data (D'') to produce second encrypted data (D') obfuscated intermediate results are created.

9. Method according to one of the preceding claims, wherein the obfuscated code (0) is stored on the data processing system (F) in the insecure working environment.

10. Method according to one of the preceding claims, wherein the data (D) to be protected are configured as: - program code, - interpretable code, - parametrizations for algorithms, - numerical data and / or - weights of a neural network.

11. Method according to one of the preceding claims, wherein the execution of the enclave code (C) is performed in an enclave (E), wherein the enclave (E) is part of the secure execution environment (TEE).

12. Data processing system (F) for carrying out a method according to one of the preceding claims, the data processing system (F) comprising: - a secure execution environment (TEE), wherein the secure execution environment (TEE) is configured to: - execute an enclave code (C), thereby generating a key pair (K pub / K priv), wherein the key pair (K_pub / K_priv) comprises a public key (K_pub) and a private key (K_priv), - send the public key (K_pub), - an insecure working environment (U), wherein the insecure execution environment (U) is outside the secure execution environment (TEE), wherein the insecure working environment (U) is configured to receive the public key (K_pub), - an obfuscated program code (0), wherein the obfuscated program code (0) is within the insecure execution environment (U), wherein the insecure execution environment (U) is configured to send the public key (K_pub) and first encrypted data (D'') to the obfuscated program code (0), wherein the obfuscated program code (0) is configured to perform a verification of the public key (K_pub) and, depending on results of the verification, to perform a conversion of the first encrypted data (D'') into second encrypted data (D'), wherein the second encrypted data (D') are encrypted with the public key (K_pub), wherein, when the public key (K_pub) is verified by the obfuscated program code (0), a check is made to determine whether a valid attestation of the public key (K_pub) is present, and wherein the conversion of the first encrypted data (D'') into the second encrypted data (D') is carried out only if a valid attestation is present, wherein the obfuscated program code (0) is further configured to send the second encrypted data (D'), and wherein the secure execution environment (TEE) is configured to receive the second encrypted data (D') and to decrypt and execute or interpret the second encrypted data (D').

13. Computer program product comprising a computer program, wherein the computer program can be loaded into a storage device of a computing unit, wherein the computer program is used to perform the steps of a method according to one of Claims 1 to 11 when the computer program is executed on the computing unit.

14. Computer-readable medium on which a computer program is stored, wherein the computer program can be loaded into a storage device of a computing unit, wherein the computer program is used to perform the steps of a method according to one of Claims 1 to 11 when the computer program is executed on the computing unit.