Secure Enclave Processor for Cloud Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The concern over the security of corporate secrets and customer data in public cloud environments, where customers must trust cloud software vendors and operators, is a significant barrier to adoption, as existing Hardware Security Module (HSM) solutions do not adequately address the need for secure storage and access.
Innovation Solution
A system where a processor manufacturer provides processors with secure enclave capability to a cloud provider, enabling content owners to receive processor-specific public encryption keys to encrypt content, which can only be decrypted within a secure enclave, thereby allowing secure storage and access without relying on cloud vendors or operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If content is stored in a public cloud using traditional HSM solutions, then cloud storage functionality is achieved, but security trust requirements increase as customers must trust cloud software vendors and operators
Solution Approach 1:
The patent introduces a hardware-based root of trust (secure enclave) as an intermediary between the content owner and cloud provider. This secure enclave acts as a mediator that holds the private key, allowing cryptographic operations to be performed without exposing the key to the cloud provider or software vendors, thus enabling cloud storage functionality while maintaining security trust.
Solution Approach 2:
The patent replaces the software-based HSM trust model with a hardware-based secure enclave trust model. By substituting the mechanical/software system with a hardware-rooted system that has physical security properties, the patent achieves cloud storage functionality while reducing reliance on trust in cloud software vendors and operators.
2Reliability
If hardware-based root of trust is implemented in cloud environment, then security trust is improved, but device complexity increases
Solution Approach 1:
The patent merges the secure enclave functionality directly into the processor (CPU), combining the computing resources with the security functions. This integration reduces overall system complexity by eliminating separate HSM hardware components while maintaining hardware-based security trust.
Solution Approach 2:
The patent makes the processor universal by enabling it to serve both as the main computing unit and as a secure enclave providing hardware-based root of trust. This multi-functionality reduces device complexity by eliminating the need for separate dedicated security hardware while maintaining security trust.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, and computer-readable storage media are provided for securely storing and accessing content within a public cloud. A processor manufacturer provides processors having secure enclave capability to a cloud provider. The provider makes available a listing of processor identifiers (CPUIDs) for processors available for storing content and having secure enclave capability. A content owner provides CPUIDs for desired processors from the listing to the manufacturer which provides the content owner with a processor-specific public code encryption key (CEK) for encrypting content to be stored on each processor identified. Each processor is constructed such that content encrypted with the public CEK may only be decrypted within a secure enclave thereof. The content owner encrypts the desired content with the public CEK and returns the encrypted content and the CPUID for the appropriate processor to the cloud provider. The cloud provider then stores the encrypted content on the particular processor.