Secure Enclave Database Attestation for Customer-Managed Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing database systems fail to provide customers with secure environments and independent verification of their own encryption keys, leading to minimal customer visibility and increased security risks.

Innovation Solution

Implement a secure database system that allows customers to use their own encryption keys, secured by hardware protections and trusted execution environments (TEEs) with attestation mechanisms to verify encryption and secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If database systems use provider-controlled encryption, then system simplicity is maintained, but customer security verification capability deteriorates

Engineering Contradiction:
Improvecustomer security verification capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces Trusted Execution Environments (TEEs) as intermediary hardware components that enable customer verification of encryption without requiring full system access. The TEEs act as mediators between the database system and customer verification processes, providing security guarantees through hardware-enforced isolation and attestation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional software-based security verification with hardware-based Trusted Execution Environments. By substituting the mechanical/software layer with hardware-level TEEs, the system achieves stronger verification capabilities while maintaining operational simplicity through hardware abstraction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If customers use their own encryption keys, then security verification is improved, but system complexity increases

Engineering Contradiction:
Improveindependent verification capabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables customers to use their own encryption keys while the system automatically handles key management through TEE-protected operations. The hardware environment provides self-service capabilities where customers can independently verify encryption without manual key management overhead, as the TEEs handle key protection and verification automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The TEEs serve as intermediaries that manage customer encryption keys securely, isolating key storage and operations within hardware-enforced boundaries. This intermediary layer handles the complexity of key management while presenting simple interfaces to customers for encryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware security protections are implemented, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidhardware integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes complex software-based security implementations with hardware-based Trusted Execution Environments. By replacing software security mechanisms with hardware TEEs, the system achieves superior security reliability while managing complexity through hardware abstraction layers that simplify integration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The TEEs provide universal security functionality across multiple database operations and encryption schemes, consolidating hardware complexity into a single multi-functional platform. This universal approach allows the same hardware security infrastructure to support various security requirements without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260034349A1Secure database environment with third-party verification
Publication Date: 2026.02.05 SNOWFLAKE INC
  • US20260034349A1 patent drawing
  • US20260034349A1 patent drawing
  • US20260034349A1 patent drawing

AI summary

Systems and methods are provided for creating a secure database execution environment. The system generates, by a database system executing on a secure enclave, attestation information. The system transmits the attestation information to a remote entity. The system obtains, by the database system executing on the secure enclave, one or more encryption keys in response to the remote entity authenticating the attestation information. The system performs, by the database system executing on the secure enclave, one or more database operations on encrypted data stored on the database system using the one or more encryption keys.