Enclave Data Verification via Integrity Attestation Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems using enclaves for data verification are vulnerable to attacks during execution, especially when dealing with untrusted data input, as they rely on whitelists for attestation and may be compromised in heterogeneous environments containing both enclave-aware and enclave-ignorant systems.

Innovation Solution

A communication system employing an integrity verification module with an attestation channel for data integrity verification, using a trusted execution environment (TEE) to isolate and validate untrusted data through input data attestation services, with policies applied locally or remotely to ensure data integrity and detect malicious code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If whitelists are used for attestation in enclaves, then data verification can be performed, but the system becomes vulnerable to attacks during execution in heterogeneous environments

Engineering Contradiction:
Improvedata verification reliabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing data integrity verification before the untrusted data enters the enclave execution environment. The integrity verification module checks data integrity policies and validates data before it is loaded into the enclave, preventing malicious data from compromising the enclave during execution. This proactive approach addresses the vulnerability by establishing trust before execution rather than relying on post-execution whitelisting.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - the integrity verification module - that sits between the untrusted data source and the enclave. This module acts as a mediator that performs data integrity checks, policy validation, and verification before data enters the enclave. The intermediary approach resolves the contradiction by providing a dedicated layer for security verification that operates independently of the enclave's execution environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If enclaves process untrusted data input, then functionality is enhanced, but data integrity can be compromised by malicious code

Engineering Contradiction:
Improveability to process untrusted dataVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary data integrity verification before untrusted data enters the enclave. The integrity verification module checks data against predefined policies and validates integrity before execution, ensuring that even though the enclave can process diverse untrusted data, the data integrity is established in advance to prevent compromise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The integrity verification module serves as an intermediary between untrusted data sources and the enclave execution environment. It provides a dedicated verification layer that maintains data integrity while allowing the enclave to process untrusted data, thus enabling both adaptability and reliability simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If remote integrity verification is implemented, then data integrity can be verified externally, but system complexity increases

Engineering Contradiction:
Improvedata integrity verificationVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The integrity verification module is designed with multi-functionality, handling both local and remote verification scenarios through a unified architecture. The same module can operate in different modes depending on whether verification is performed locally or remotely, reducing the need for separate complex systems and simplifying the overall architecture while maintaining reliable data integrity verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10176344B2Data verification using enclave attestation
Publication Date: 2019.01.08 MCAFEE LLC
  • US10176344B2 patent drawing
  • US10176344B2 patent drawing
  • US10176344B2 patent drawing

AI summary

Particular embodiments described herein provide for an electronic device that can be configured to receive untrusted input data at an enclave in an electronic device, isolate the untrusted input data from at least a portion of the enclave, communicate at least a portion of the untrusted data to an integrity verification module using an attestation channel, and receive data integrity verification of the untrusted input data from the integrity verification module. The integrity verification module can perform data integrity attestation functions to verify the untrusted data and the data integrity attestation functions include a data attestation policy and a whitelist.