Confidential Computing for Secure Data Correction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing, correcting past data to enhance products or services while ensuring data quality and security is challenging due to the risk of improper conduct and cyberattacks, necessitating appropriate authority management and clear correction grounds.

Innovation Solution

An information processing apparatus with a processor holding public and private keys decrypts and executes an encrypted data correction program within a confidential computing environment, identifying and correcting target data using production-equipment time-series data while ensuring confidentiality, and generates correction ground data for traceability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If past data is corrected unlimitedly to enhance products or services, then data quality and service improvement are enhanced, but the risk of improper conduct and cyberattacks increases

Engineering Contradiction:
Improvedata qualityVSAvoidcyberattack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A confidential computing environment acts as an intermediary between the data correction program and the time-series data. This environment enables secure data correction while preventing unauthorized access and cyberattacks, as the environment isolates the correction process and controls access to sensitive data through encryption and secure execution boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The information processing apparatus automatically manages the correction process by acquiring the data correction program, executing it within the confidential computing environment, and generating correction ground data. This self-service mechanism reduces human intervention and potential improper conduct while maintaining auditability through automated ground data generation.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If past data is corrected with appropriate authority management to prevent improper conduct, then security is improved, but the complexity of authority management and correction grounds clarification increases

Engineering Contradiction:
Improveimproper conduct riskVSAvoidauthority management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by acquiring and validating the data correction program before execution, and by generating correction ground data that documents the basis for correction. This preliminary preparation ensures that only authorized corrections with proper grounds are performed, reducing the need for complex ongoing authority management while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system generates correction ground data that provides feedback on the correction process, documenting what data was corrected, why it was corrected, and the basis for the correction. This feedback mechanism creates an automated audit trail that simplifies authority management by providing transparent, verifiable records of all correction actions without requiring complex manual approval processes.

Inventive Principle:
Principle #23Feedback

3Loss of information

If confidential computing environment is used to protect time-series data during correction, then data confidentiality is improved, but the processing complexity and key management overhead increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidkey management overhead
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The confidential computing environment serves multiple functions: it protects the confidentiality of time-series data, executes the data correction program securely, and generates correction ground data. This multi-functionality reduces the need for separate security mechanisms and key management systems, as a single confidential computing environment handles all security-critical operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If correction ground data is generated and added to corrected data for traceability, then accountability is improved, but the data storage and processing overhead increase

Engineering Contradiction:
ImprovetraceabilityVSAvoiddata storage overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts only the essential correction ground information needed for traceability and attaches it to the corrected data. Rather than storing complete audit logs or redundant data copies, the system takes out and retains only the critical ground data elements that provide accountability, minimizing storage overhead while maintaining traceability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12019511B2Information processing apparatus, method, and storage medium
Publication Date: 2024.06.25 KK TOSHIBA
  • US12019511B2 patent drawing
  • US12019511B2 patent drawing
  • US12019511B2 patent drawing

AI summary

According to one embodiment, an information processing apparatus is allowed to access a storage device storing time-series data generated by a first device. The information processing apparatus includes a processor holding a first public key and a first private key. The processor is configured to acquire a program for correcting an error in first data on a first product from a first entity. The processor is configured to correct the correction target first data, using data in a predetermined range of the time-series data. The processor is configured to generate ground data indicating correction grounds for the corrected correction target first data, based on the data in the predetermined range, and add the ground data to the corrected correction target first data.