Secure Execution Environment for Encrypted Software Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting executable software code, such as homomorphic encryption, are computationally expensive and not compatible with existing infrastructure, making them inefficient for securing sensitive data processing.
Innovation Solution
A system and method for encrypting or obfuscating executable software code and creating a secure execution environment, allowing for faster execution times compared to homomorphic encryption, while providing similar security benefits by using pre-execution code processing and execution modules with hardware acceleration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If homomorphic encryption is used to protect executable software code, then data confidentiality and security benefits are improved, but computational cost and execution time increase significantly
Solution Approach 1:
The patent applies preliminary action by encrypting or obfuscating the executable code before execution, and preparing a secure execution environment in advance that contains decryption keys and security modules. This allows the code to be protected during storage and transmission, then efficiently executed in the pre-prepared secure environment, resolving the contradiction between maintaining confidentiality and achieving fast execution.
Solution Approach 2:
The patent introduces an intermediary secure execution environment that acts as a mediator between the encrypted code and the hardware processor. This environment includes security control modules, decryption mechanisms, and isolation layers that enable efficient execution of encrypted code without requiring the entire system to use computationally expensive homomorphic encryption operations.
2Reliability
If homomorphic encryption is used to secure sensitive data processing, then security benefits are improved, but compatibility with existing compute infrastructure deteriorates
Solution Approach 1:
The secure execution environment serves as an intermediary layer between existing compute infrastructure and the encrypted code. It provides compatibility by translating and managing encrypted operations within a controlled environment that leverages existing hardware capabilities while maintaining security benefits, thus bridging the gap between homomorphic encryption concepts and current infrastructure.
Solution Approach 2:
The patent creates a copy of the execution environment with security controls and decryption capabilities that can be deployed alongside existing systems. This copied secure environment can run on existing hardware while providing encryption and security features, enabling compatibility with current infrastructure without requiring complete system replacement.
3Reliability
If code encryption and obfuscation are applied, then protection against unauthorized copying and reverse engineering is improved, but code execution complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-processing the code to encrypt or obfuscate it before execution, and pre-configuring the secure execution environment with all necessary decryption keys and security modules. This separates the complexity of code protection from the execution process, as the environment is already prepared to handle the encrypted code efficiently, thus reducing execution complexity while maintaining protection.
Solution Approach 2:
The secure execution environment acts as an intermediary that handles the complexity of code execution for encrypted and obfuscated code. It provides abstraction layers that manage decryption, obfuscation reversal, and security controls automatically, shielding the user from execution complexity while maintaining strong protection against reverse engineering and unauthorized copying.
Data Source
AI summary
Security enhancement herein primarily relate to digital code undergoing a first fortification protocol by which a digital package is prepared, a secure execution environment being configured for use with the package at or via a source facility, and at least some of the package being executed in in the secure execution environment at a destination facility. Such enhanced configurations may arrive to or from a remote facility, for example, without a concomitant loss of performance.


