Dual TEE Audit Verification Across Trust Boundaries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-party computing environments, ensuring independent zones of trust to verify and isolate data access and execution behavior across organizational boundaries is challenging due to differing security and compliance requirements.
Innovation Solution
The implementation of dual trusted execution environments (TEEs), one operated by the host entity and one by the remote entity, with independent roots of trust, generates and verifies audit data to ensure secure processing and monitoring of sensitive data, using hardware-assisted isolation and cryptographic verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual trusted execution environments are implemented with independent roots of trust, then security and verification capability is improved, but device complexity increases
Solution Approach 1:
The system is divided into two independent trusted execution environments (TEEs), each with its own root of trust and security domain. The first TEE is operated by the host entity while the second TEE is operated by the remote entity, allowing independent security verification without requiring a single complex trust model.
Solution Approach 2:
Audit data serves as an intermediary mechanism that bridges the two independent TEEs. The audit data is signed by both TEEs and can be verified by either party, enabling mutual verification without direct trust establishment between the host and remote entities.
2Measurement precision
If independent zones of trust are established across organizational boundaries, then data access verification is improved, but system complexity increases
Solution Approach 1:
Independent trust zones are segmented into separate TEEs operated by different entities. Each TEE maintains its own security boundaries and verification mechanisms, allowing precise tracking of data access within each organizational boundary without requiring a monolithic trust management system.
Solution Approach 2:
The system implements mutual verification through signed audit data that provides feedback about data access and execution behavior. Each TEE can verify the other's actions through cryptographically signed audit trails, creating a feedback loop that enhances verification accuracy without proportional increases in complexity.
3Reliability
If audit data is signed by multiple independent TEEs, then tamper evidence capability is improved, but processing overhead increases
Solution Approach 1:
Multiple audit data signatures from independent TEEs are combined into a single verifiable audit record. The audit data structure integrates signatures from both the host-operated TEE and the remote-operated TEE, allowing tamper evidence from multiple sources to be verified together rather than as separate operations.
Data Source
AI summary
It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to receive data from a remote entity for handling by a computing system. The machine-readable instructions further include instructions to instantiate a first TEE and a second TEE. The machine-readable instructions further include instructions to generate log data corresponding to predefined activities of the computing system and to generate system record data of a system log of the computing system at predetermined times. The machine-readable instructions further include instructions to generate first audit data by the first TEE and second audit data by the second TEE. The machine-readable instructions further include instructions to transmit the first and the second audit data to a detection system for data aggregation and anomaly detection.


