Runtime Attestation for Sovereign Group Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring data sovereignty in a cloud environment is challenging, as data can be accessed, transferred, and processed outside their intended location without strong guarantees, and unencrypted data can be transferred outside sovereign constraints.
Innovation Solution
A method involving an application host requesting attestation reports from a runtime environment attester, followed by verification from a verifier device, and then acquiring a data attestation from a data attester to ensure data sovereignty, using a data ledger to track operations and maintain data constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data are stored and processed in a cloud environment, then accessibility and processing capability are improved, but data sovereignty and security control deteriorate
Solution Approach 1:
The patent introduces a data attester as an intermediary component that mediates between the cloud environment and the data sovereignty requirements. The data attester verifies data constraints and generates attestations that confirm data remains within sovereign boundaries, enabling cloud accessibility while maintaining sovereignty control through this intermediate verification layer
Solution Approach 2:
The system implements feedback mechanisms where the data attester continuously monitors and verifies data location and constraints, providing feedback to the application host. This feedback loop ensures that data processing operations comply with sovereignty requirements by confirming data remains within authorized environments before allowing operations to proceed
2Adaptability or versatility
If data are transferred outside the sovereign environment, then processing flexibility is improved, but data security and sovereignty constraints deteriorate
Solution Approach 1:
The patent applies preliminary anti-action by having the data attester verify data constraints and generate attestations before data transfer or processing operations occur. This preventive verification ensures data remains within sovereign boundaries before any potentially harmful transfer can occur, blocking unauthorized data movement rather than detecting it after the fact
Solution Approach 2:
The data attester serves as an intermediary that stands between the data and the external environment, verifying that any data transfer or processing operation complies with sovereignty constraints. This intermediate verification layer prevents unauthorized data exfiltration while allowing legitimate flexible processing within defined boundaries
3Productivity
If data are processed without encryption, then processing speed is improved, but data security and sovereignty protection deteriorate
Solution Approach 1:
The system implements feedback mechanisms where the data attester verifies data constraints and encryption status before processing operations. The feedback loop ensures encrypted data is properly handled while maintaining processing efficiency by verifying security constraints beforehand rather than continuously monitoring during processing
Data Source
Figure 1
Figure 2~5
Figure 6
AI summary
The present invention provides first method for securely processing a group of data within a runtime environment, wherein said first method comprises: - requesting by an application host to a runtime environment attester device for an attestation report, said application host and said runtime environment attester being part of said runtime environment, - sending back by said runtime environment attester device to said application host said attestation report, - requesting by said application host a verifier device to verify said attestation report, - receiving by said verifier device from said application host said request for verifying said attestation report, - verifying by said verifier device said attestation report, said verifier device being part of a trusted environment, - upon said verification, sending back by said verifier device to said application host a runtime proof token, - receiving by said application host from said verifier device said runtime proof token, - requesting by said application host to a data attester device a data attestation, said request comprising a group data identifier and said runtime proof token, - receiving by said data attester device said request for a data attestation, - assessing by said data attester device said runtime proof token, - upon said assessment, acquiring by said data attester device a data attestation and sending it back to said application host, - receiving by said application host from said data attester device said data attestation and verifying by said application host data constraints based on said data attestation, - upon said verification, processing by said application host said group of data with an operation.