Cloud Enclave Remote Attestation for Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security methods in software applications are insufficient to comply with the General Data Protection Regulation (GDPR), leaving organizations at risk of significant penalties due to potential data breaches and unauthorized access.

Innovation Solution

A method involving remote attestation, where a provider agent in the cloud service system requests a cryptographic quote of an instantiated enclave, verifying its integrity against a provider quote verification service, ensuring the application's security by validating the quote enclave signature against a provider attestation data storage, thereby enhancing data protection across client, service provider, and cloud systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security solutions are used to encrypt data, then data protection from theft is improved, but data integrity and protection against corruption worsen

Engineering Contradiction:
Improvedata protectionVSAvoiddata corruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces hardware-based security modules (HSMs) and secure enclaves as intermediary layers between the software application and the data storage. These hardware components act as mediators that provide cryptographic protection and integrity verification, preventing both theft and corruption by isolating the data in a physically protected environment that software cannot directly access or modify.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines software-based encryption with hardware-based security mechanisms to create a composite security architecture. This includes layering software encryption protocols with hardware security modules, secure enclaves, and remote attestation mechanisms, where each layer provides complementary protection against different types of threats including theft, corruption, and unauthorized access.

Inventive Principle:
Principle #40Composite materials

2Reliability

If hardware-based security solutions are used to prevent read and write access, then data integrity is improved, but system usability and flexibility worsen

Engineering Contradiction:
Improvedata integrityVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the hardware security modules automatically perform cryptographic operations, integrity verification, and access control without requiring manual intervention. The system autonomously manages security policies, performs remote attestation, and handles key management, reducing the operational burden while maintaining strict security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the security functions into distinct modular components including hardware security modules, secure enclaves, remote attestation services, and policy management systems. This modular architecture allows different security mechanisms to be independently configured and activated based on specific operational requirements, providing flexibility while maintaining data integrity through hardware enforcement.

Inventive Principle:
Principle #1Segmentation

3Reliability

If remote attestation and quote verification are implemented, then data security compliance is improved, but computational overhead and processing time worsen

Engineering Contradiction:
Improvesecurity complianceVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs remote attestation and quote verification as preliminary actions during system initialization, application deployment, and before critical data operations. By completing these computationally intensive security verification processes in advance, the system establishes trusted execution environments beforehand, avoiding repeated verification overhead during normal operations and reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4478228A1Method for improving data security
Publication Date: 2024.12.18 NUUDAY AS
  • EP4478228A1 patent drawingFigure 1
  • EP4478228A1 patent drawingFigure 2
  • EP4478228A1 patent drawingFigure 3

AI summary

Disclosed is a method for improving data security in an application, the method being performed in a client system, a service provider system and/or a cloud service system, the method comprising: - requesting (320) a quote by a provider agent in the cloud service system, the quote being a cryptographic measurement of an instantiated enclave, - performing remote attestation, wherein the remote attestation comprises: - initiating (350) the remote attestation by the provider agent, to a provider attestation service, in the cloud service system; - verifying (225) the quote against a provider quote verification service (QVS) in the service provider system; and - validating an integrity of the application by verifying (235) a quote enclave signature against a provider attestation data storage in the service provider system, thereby improving data security in the application.