Credential-Mediated Data Access for Secure Cloud Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing importance of data security in data interaction between user terminals and clouds necessitates ensuring the security of user-generated data, particularly in preventing unauthorized access, snooping, and leakage during transmission and processing.

Innovation Solution

A data access method involving a trusted execution environment (TEE) and credential management service (TKS) that ensures secure data access by sending authorization requests to clients, obtaining access credentials, and processing data within a secure computing environment, using access credentials to prevent unauthorized access and leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted and processed between user terminals and clouds, then data interaction functionality is improved, but data security and risk of unauthorized access deteriorate

Engineering Contradiction:
Improvedata interaction functionalityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a credential management service as an intermediary between user terminals and cloud services. This service manages access credentials and controls data access permissions, preventing direct unauthorized access while enabling legitimate data interaction. The credential management service acts as a trusted mediator that verifies identities and enforces access policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data access control mechanism into multiple components: credential generation at user terminals, credential storage in secure elements, credential verification by the credential management service, and access decision enforcement. This segmentation distributes security responsibilities and creates multiple layers of protection against unauthorized access.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access credentials are implemented to prevent unauthorized access, then data security is improved, but system complexity and authentication overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service credential management where user terminals autonomously generate, store, and manage their own access credentials using secure elements or trusted execution environments. The credential management service autonomously verifies credentials and makes access decisions without requiring manual intervention. This automation reduces operational complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary credential generation and storage in secure elements before any data access operations. Access credentials are created and protected in advance within trusted environments, so that when data access is needed, the verification process can proceed efficiently without complex real-time credential generation or manual authentication procedures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260064871A1Data access method, apparatus, device and readable storage medium
Publication Date: 2026.03.05 BEIJING ZITIAO NETWORK TECH CO LTD
  • US20260064871A1 patent drawing
  • US20260064871A1 patent drawing
  • US20260064871A1 patent drawing

AI summary

Embodiment of the disclosure provide a data access method and an apparatus, a device and a readable storage medium. The method includes: in response to a demand of processing the data resource generated in a target application, sending a data access authorization request for the data resource to a plurality of clients of the target application, the plurality of clients being associated with the data resource. The authorization information for the data access authorization request is received respectively from at least one of the plurality of clients. At least one access credential respectively corresponding to the at least one client is obtained based on the authorization information. The target data associated with the at least one client in the data resource is accessed with the at least one access credential to process the target data.