Secure Execution Engine for Encrypted Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cryptosystems protect data confidentiality but make it vulnerable during computations, and secure multiparty computation protocols are complex and out of reach for most organizations due to the need for deep cryptographic expertise and rigorous security analysis.

Innovation Solution

A secure collaborative processing system using a group of servers with a secure execution engine that includes a secure virtual machine, secure multi-party computation protocol, and multi-party oblivious random access memory (ORAM) protocol, allowing encrypted data to be processed without revealing the data to any party and enabling collaboration without decrypting the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptosystems are used to protect data confidentiality, then data security is improved, but data utility deteriorates because computations cannot be performed on encrypted data

Engineering Contradiction:
Improvedata securityVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces homomorphic encryption as an intermediary mechanism that allows computations to be performed on encrypted data without decryption. The encrypted data acts as a mediator between the need for security and the need for computation, enabling both confidentiality and data utility to coexist. The system processes ciphertext directly through specialized hardware circuits that implement cryptographic operations, eliminating the need to decrypt data for computation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure multiparty computation protocols are used to enable collaboration, then data privacy is improved, but device complexity worsens due to the need for deep cryptographic expertise and rigorous security analysis

Engineering Contradiction:
Improvedata privacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically performs cryptographic operations through dedicated hardware circuits without requiring manual cryptographic expertise. The secure execution engine autonomously manages encryption, decryption, and computation on encrypted data, eliminating the need for users to implement or understand complex cryptographic protocols. The system serves itself by embedding security functionality directly in the hardware architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal secure execution engine that can handle multiple types of computations and cryptographic operations through a single integrated platform. The hardware circuit is designed to be multi-functional, supporting various homomorphic encryption schemes and cryptographic primitives, thereby simplifying the system by consolidating multiple security functions into one unified device rather than requiring separate implementations for each cryptographic need.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If data is decrypted to perform computations, then data utility is improved, but data security worsens because the data becomes vulnerable

Engineering Contradiction:
Improvedata utilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring hardware circuits with cryptographic functionality before data processing occurs. The system is prepared in advance to perform computations on encrypted data through dedicated homomorphic encryption circuits, eliminating the need to decrypt data during the computation process. This preliminary setup of cryptographic capabilities in hardware ensures that data remains encrypted throughout the entire computation lifecycle.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12111938B2Secure collaborative processing of private inputs
Publication Date: 2024.10.08 CIPHERMODE LABS INC
  • US12111938B2 patent drawing
  • US12111938B2 patent drawing
  • US12111938B2 patent drawing

AI summary

The described technology is generally directed towards secure collaborative processing of private inputs. A secure execution engine can process encrypted data contributed by multiple parties, without revealing the encrypted data to any of the parties. The encrypted data can be processed according to any program written in a high-level programming language, while the secure execution engine handles cryptographic processing.