Secure Enclave Processor for Cloud Data Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The concern over the security of corporate secrets and customer data in public cloud environments, where customers must trust cloud software vendors and operators, is a significant barrier to adoption, as existing Hardware Security Module (HSM) solutions do not adequately address the need for secure storage and access.

Innovation Solution

A system where a processor manufacturer provides processors with secure enclave capability to a cloud provider, enabling content owners to receive processor-specific public encryption keys to encrypt content, which can only be decrypted within a secure enclave, thereby allowing secure storage and access without relying on cloud vendors or operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If content is stored in a public cloud using traditional HSM solutions, then cloud storage functionality is achieved, but security trust requirements increase as customers must trust cloud software vendors and operators

Engineering Contradiction:
Improvecloud storage functionalityVSAvoidsecurity trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a hardware-based root of trust (secure enclave) as an intermediary between the content owner and cloud provider. This secure enclave acts as a mediator that holds the private key, allowing cryptographic operations to be performed without exposing the key to the cloud provider or software vendors, thus enabling cloud storage functionality while maintaining security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the software-based HSM trust model with a hardware-based secure enclave trust model. By substituting the mechanical/software system with a hardware-rooted system that has physical security properties, the patent achieves cloud storage functionality while reducing reliance on trust in cloud software vendors and operators.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based root of trust is implemented in cloud environment, then security trust is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity trustVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure enclave functionality directly into the processor (CPU), combining the computing resources with the security functions. This integration reduces overall system complexity by eliminating separate HSM hardware components while maintaining hardware-based security trust.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the processor universal by enabling it to serve both as the main computing unit and as a secure enclave providing hardware-based root of trust. This multi-functionality reduces device complexity by eliminating the need for separate dedicated security hardware while maintaining security trust.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3606003B1Securely storing content within public clouds
Publication Date: 2022.04.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3606003B1 patent drawingFigure 1
  • EP3606003B1 patent drawingFigure 2
  • EP3606003B1 patent drawingFigure 3

AI summary

Systems, methods, and computer-readable storage media are provided for securely storing and accessing content within a public cloud. A processor manufacturer provides processors having secure enclave capability to a cloud provider. The provider makes available a listing of processor identifiers (CPUIDs) for processors available for storing content and having secure enclave capability. A content owner provides CPUIDs for desired processors from the listing to the manufacturer which provides the content owner with a processor-specific public code encryption key (CEK) for encrypting content to be stored on each processor identified. Each processor is constructed such that content encrypted with the public CEK may only be decrypted within a secure enclave thereof. The content owner encrypts the desired content with the public CEK and returns the encrypted content and the CPUID for the appropriate processor to the cloud provider. The cloud provider then stores the encrypted content on the particular processor.