Secure Content Packaging via Trusted Execution Enclaves

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content security systems lack customization of security policies by content creators and end users, require centralized systems, and lack interoperability, limiting secure content access and sharing outside of controlled environments.

Innovation Solution

A system utilizing trusted execution environments (TEEs) on computing devices to create and manage secure content packages with customizable access policies, allowing secure content sharing and enforcement outside of centralized systems, using Intel SGX technology for secure enclaves and a policy enforcement engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized enterprise rights management systems are used to secure content, then content security control is improved, but system complexity and lack of interoperability worsen

Engineering Contradiction:
Improvecontent security controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized ERM system into distributed trusted execution environments (TEEs) on individual computing devices. Each TEE independently enforces security policies locally, eliminating the need for a complex centralized server infrastructure while maintaining security control through cryptographic proof of policy compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal secure content access mechanism that works across different computing devices and platforms through standardized TEE interfaces. This multi-functional approach allows the same security framework to operate on diverse hardware architectures, improving interoperability without requiring device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If centralized document stores and proprietary websites are required for secure content access, then content security enforcement is improved, but ease of operation and accessibility worsen

Engineering Contradiction:
Improvecontent security enforcementVSAvoidcontent accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables computing devices to self-verify security policies and autonomously enforce access controls through local TEE execution. Content creators can embed security policies directly in secure packages, which are then automatically validated and enforced by receiving devices without requiring manual intervention from centralized document stores or proprietary website administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs security policy validation and cryptographic verification in advance during the secure package creation process. Security policies are pre-configured and embedded within secure packages, allowing receiving devices to immediately enforce access controls without real-time communication with centralized systems, thereby improving accessibility while maintaining enforcement reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the same toolset is mandated for all users in existing security systems, then security consistency is improved, but adaptability and customization worsen

Engineering Contradiction:
Improvesecurity consistencyVSAvoidpolicy customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static, one-size-fits-all security policies into dynamic, customizable policies that can be independently configured by content creators. Each secure package contains its own policy definitions that adapt to specific content requirements, while the TEE framework dynamically evaluates and enforces these customized policies without requiring uniform toolsets across all users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent allows different security policies to be applied to different content items based on local requirements. Content creators can define specific access control rules, encryption methods, and usage restrictions tailored to each secure package, enabling policy customization at the content level while maintaining overall system consistency through standardized TEE enforcement mechanisms.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3175575B1Secure content packaging using multiple trusted execution environments
Publication Date: 2019.04.10 MCAFEE LLC
  • EP3175575B1 patent drawingFigure 1
  • EP3175575B1 patent drawingFigure 2~3
  • EP3175575B1 patent drawingFigure 4A

AI summary

Technologies for secure content packaging include a source computing device that transmits a secure package to a destination computing device. The destination computing device establishes a content policy trusted execution environment and a key policy trusted execution environment. The content policy trusted execution environment may be established in a secure enclave using processor support. The key policy trusted execution environment may be established using a security engine. The key policy trusted execution environment evaluates a key access policy and decrypts a content key using a master wrapping key. The content policy trusted execution environment evaluates a content access policy and decrypts the content using the decrypted content key. Similarly, the source computing device authors the secure package using a content policy trusted execution environment and a key policy trusted execution environment. The master wrapping key may be provisioned to the computing devices during manufacture. Other embodiments are described and claimed.