Secure Area Blind Signature for TEE Program Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
General TEEs lack a mechanism to guarantee that a correct program is running in the secure area, which is essential for remote verification and assurance to external entities.
Innovation Solution
An information processing apparatus is designed with a secure area and a security chip, where the secure area conceals information related to the program and requests a blind signature from the security chip, allowing the secure area to acquire a signature for the concealed information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a general TEE is used to execute programs in a secure area, then data confidentiality is improved, but the ability to verify program correctness to external entities deteriorates
Solution Approach 1:
The patent introduces a verification mechanism that acts as an intermediary between the secure area and external entities. This verification unit generates verification information about program execution without exposing the actual program data or secrets, allowing external verification while maintaining confidentiality. The verification information serves as a mediator that proves program correctness without revealing protected information.
Solution Approach 2:
The patent transforms the verification approach by changing parameters from direct program inspection to indirect verification through verification information. Instead of exposing program parameters directly to external entities, the system generates derived verification parameters (hash values, attestation data) that prove program correctness without revealing the actual program state or secrets.
2Reliability
If the secure area conceals all program information, then security is improved, but the ability to provide proof of correct execution deteriorates
Solution Approach 1:
The verification unit creates an intermediary layer that generates verification information without exposing the concealed program data. This verification information acts as a mediator that carries proof of correct execution while maintaining the confidentiality of the actual program and its data.
Solution Approach 2:
The system creates a copy of verification-relevant information (hash values, execution proofs) that can be shared externally without exposing the actual program. This copying approach allows verification while preserving security by working with derived representations rather than the original concealed data.
Data Source
AI summary
An information processing apparatus includes a secure area configured to execute a program in secret, and a security chip. The secure area conceals information related to the program, and requests the security chip to provide a blind signature with respect to the concealed information obtained by the concealing. The security chip calculates the blind signature and returns the blind signature to the secure area. The secure area acquires a signature with respect to the information related to the program from the blind signature.


