Confidential Computing for Secure Data Correction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing, correcting past data to enhance products or services while ensuring data quality and security is challenging due to the risk of improper conduct and cyberattacks, necessitating appropriate authority management and clear correction grounds.
Innovation Solution
An information processing apparatus with a processor holding public and private keys decrypts and executes an encrypted data correction program within a confidential computing environment, identifying and correcting target data using production-equipment time-series data while ensuring confidentiality, and generates correction ground data for traceability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If past data is corrected unlimitedly to enhance products or services, then data quality and service improvement are enhanced, but the risk of improper conduct and cyberattacks increases
Solution Approach 1:
A confidential computing environment acts as an intermediary between the data correction program and the time-series data. This environment enables secure data correction while preventing unauthorized access and cyberattacks, as the environment isolates the correction process and controls access to sensitive data through encryption and secure execution boundaries.
Solution Approach 2:
The information processing apparatus automatically manages the correction process by acquiring the data correction program, executing it within the confidential computing environment, and generating correction ground data. This self-service mechanism reduces human intervention and potential improper conduct while maintaining auditability through automated ground data generation.
2Object-affected harmful factors
If past data is corrected with appropriate authority management to prevent improper conduct, then security is improved, but the complexity of authority management and correction grounds clarification increases
Solution Approach 1:
The system performs preliminary actions by acquiring and validating the data correction program before execution, and by generating correction ground data that documents the basis for correction. This preliminary preparation ensures that only authorized corrections with proper grounds are performed, reducing the need for complex ongoing authority management while maintaining security.
Solution Approach 2:
The system generates correction ground data that provides feedback on the correction process, documenting what data was corrected, why it was corrected, and the basis for the correction. This feedback mechanism creates an automated audit trail that simplifies authority management by providing transparent, verifiable records of all correction actions without requiring complex manual approval processes.
3Loss of information
If confidential computing environment is used to protect time-series data during correction, then data confidentiality is improved, but the processing complexity and key management overhead increase
Solution Approach 1:
The confidential computing environment serves multiple functions: it protects the confidentiality of time-series data, executes the data correction program securely, and generates correction ground data. This multi-functionality reduces the need for separate security mechanisms and key management systems, as a single confidential computing environment handles all security-critical operations.
4Reliability
If correction ground data is generated and added to corrected data for traceability, then accountability is improved, but the data storage and processing overhead increase
Solution Approach 1:
The system extracts only the essential correction ground information needed for traceability and attaches it to the corrected data. Rather than storing complete audit logs or redundant data copies, the system takes out and retains only the critical ground data elements that provide accountability, minimizing storage overhead while maintaining traceability.
Data Source
AI summary
According to one embodiment, an information processing apparatus is allowed to access a storage device storing time-series data generated by a first device. The information processing apparatus includes a processor holding a first public key and a first private key. The processor is configured to acquire a program for correcting an error in first data on a first product from a first entity. The processor is configured to correct the correction target first data, using data in a predetermined range of the time-series data. The processor is configured to generate ground data indicating correction grounds for the corrected correction target first data, based on the data in the predetermined range, and add the ground data to the corrected correction target first data.


