Secure Content Packaging via Trusted Execution Enclaves
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content security systems lack customization of security policies by content creators and end users, require centralized systems, and lack interoperability, limiting secure content access and sharing outside of controlled environments.
Innovation Solution
A system utilizing trusted execution environments (TEEs) on computing devices to create and manage secure content packages with customizable access policies, allowing secure content sharing and enforcement outside of centralized systems, using Intel SGX technology for secure enclaves and a policy enforcement engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized enterprise rights management systems are used to secure content, then content security control is improved, but system complexity and lack of interoperability worsen
Solution Approach 1:
The patent segments the centralized ERM system into distributed trusted execution environments (TEEs) on individual computing devices. Each TEE independently enforces security policies locally, eliminating the need for a complex centralized server infrastructure while maintaining security control through cryptographic proof of policy compliance.
Solution Approach 2:
The patent creates a universal secure content access mechanism that works across different computing devices and platforms through standardized TEE interfaces. This multi-functional approach allows the same security framework to operate on diverse hardware architectures, improving interoperability without requiring device-specific implementations.
2Reliability
If centralized document stores and proprietary websites are required for secure content access, then content security enforcement is improved, but ease of operation and accessibility worsen
Solution Approach 1:
The patent enables computing devices to self-verify security policies and autonomously enforce access controls through local TEE execution. Content creators can embed security policies directly in secure packages, which are then automatically validated and enforced by receiving devices without requiring manual intervention from centralized document stores or proprietary website administrators.
Solution Approach 2:
The patent performs security policy validation and cryptographic verification in advance during the secure package creation process. Security policies are pre-configured and embedded within secure packages, allowing receiving devices to immediately enforce access controls without real-time communication with centralized systems, thereby improving accessibility while maintaining enforcement reliability.
3Reliability
If the same toolset is mandated for all users in existing security systems, then security consistency is improved, but adaptability and customization worsen
Solution Approach 1:
The patent transforms static, one-size-fits-all security policies into dynamic, customizable policies that can be independently configured by content creators. Each secure package contains its own policy definitions that adapt to specific content requirements, while the TEE framework dynamically evaluates and enforces these customized policies without requiring uniform toolsets across all users.
Solution Approach 2:
The patent allows different security policies to be applied to different content items based on local requirements. Content creators can define specific access control rules, encryption methods, and usage restrictions tailored to each secure package, enabling policy customization at the content level while maintaining overall system consistency through standardized TEE enforcement mechanisms.
Data Source
Figure 1
Figure 2~3
Figure 4A
AI summary
Technologies for secure content packaging include a source computing device that transmits a secure package to a destination computing device. The destination computing device establishes a content policy trusted execution environment and a key policy trusted execution environment. The content policy trusted execution environment may be established in a secure enclave using processor support. The key policy trusted execution environment may be established using a security engine. The key policy trusted execution environment evaluates a key access policy and decrypts a content key using a master wrapping key. The content policy trusted execution environment evaluates a content access policy and decrypts the content using the decrypted content key. Similarly, the source computing device authors the secure package using a content policy trusted execution environment and a key policy trusted execution environment. The master wrapping key may be provisioned to the computing devices during manufacture. Other embodiments are described and claimed.