Dual TEE Audit Verification Across Trust Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-party computing environments, ensuring independent zones of trust to verify and isolate data access and execution behavior across organizational boundaries is challenging due to differing security and compliance requirements.

Innovation Solution

The implementation of dual trusted execution environments (TEEs), one operated by the host entity and one by the remote entity, with independent roots of trust, generates and verifies audit data to ensure secure processing and monitoring of sensitive data, using hardware-assisted isolation and cryptographic verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual trusted execution environments are implemented with independent roots of trust, then security and verification capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two independent trusted execution environments (TEEs), each with its own root of trust and security domain. The first TEE is operated by the host entity while the second TEE is operated by the remote entity, allowing independent security verification without requiring a single complex trust model.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Audit data serves as an intermediary mechanism that bridges the two independent TEEs. The audit data is signed by both TEEs and can be verified by either party, enabling mutual verification without direct trust establishment between the host and remote entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If independent zones of trust are established across organizational boundaries, then data access verification is improved, but system complexity increases

Engineering Contradiction:
Improvedata access verification accuracyVSAvoidtrust zone management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Independent trust zones are segmented into separate TEEs operated by different entities. Each TEE maintains its own security boundaries and verification mechanisms, allowing precise tracking of data access within each organizational boundary without requiring a monolithic trust management system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements mutual verification through signed audit data that provides feedback about data access and execution behavior. Each TEE can verify the other's actions through cryptographically signed audit trails, creating a feedback loop that enhances verification accuracy without proportional increases in complexity.

Inventive Principle:
Principle #23Feedback

3Reliability

If audit data is signed by multiple independent TEEs, then tamper evidence capability is improved, but processing overhead increases

Engineering Contradiction:
Improvetamper evidence capabilityVSAvoidaudit data processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Multiple audit data signatures from independent TEEs are combined into a single verifiable audit record. The audit data structure integrates signatures from both the host-operated TEE and the remote-operated TEE, allowing tamper evidence from multiple sources to be verified together rather than as separate operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250371141A1Apparatuses for audit data generation and verification
Publication Date: 2025.12.04 VAUGHN ROBERT
  • US20250371141A1 patent drawing
  • US20250371141A1 patent drawing
  • US20250371141A1 patent drawing

AI summary

It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to receive data from a remote entity for handling by a computing system. The machine-readable instructions further include instructions to instantiate a first TEE and a second TEE. The machine-readable instructions further include instructions to generate log data corresponding to predefined activities of the computing system and to generate system record data of a system log of the computing system at predetermined times. The machine-readable instructions further include instructions to generate first audit data by the first TEE and second audit data by the second TEE. The machine-readable instructions further include instructions to transmit the first and the second audit data to a detection system for data aggregation and anomaly detection.