Secure Execution Environment Services for Cloud Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern distributed and virtual computer systems, ensuring the security of data and applications is challenging, particularly in environments where multiple users and services have access, and there is a risk of malicious applications gaining access to encryption keys or the computing resource service provider discovering sensitive data.

Innovation Solution

A secure execution environment service is provided, allowing customers to configure and control access to a secured execution environment hosted by a computing resource service provider, which instantiates a hardware-secured region for data storage and application execution, preventing external access through encryption and metadata cleansing, and enabling remote attestation for verification of the environment's state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted to protect security, then security is improved, but access control complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure execution environment (SEE) as an intermediary layer between the computing resource service provider and the customer's data. The SEE acts as a mediator that enforces access control policies, manages encryption keys, and verifies application trustworthiness, thereby simplifying the overall access control architecture while maintaining strong security through hardware-based isolation and cryptographic protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a hardware-secured region is instantiated to prevent external access, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested architecture where the secure execution environment is embedded within the virtual machine infrastructure, which itself runs on the computing resource service provider's hardware platform. This nested doll structure allows the SEE to leverage existing virtualization layers while adding an additional hardened containment layer, achieving enhanced security without requiring a complete redesign of the underlying system architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If remote attestation is enabled for verification, then security assurance is improved, but processing time increases

Engineering Contradiction:
Improveenvironment verificationVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs remote attestation measurements and verification checks during the secure execution environment initialization phase, before any sensitive operations begin. By completing the verification of the SEE's trusted state in advance, the system ensures security assurance without introducing delays during critical data processing operations, as the attestation results are cached and validated beforehand.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9521140B2Secure execution environment services
Publication Date: 2016.12.13 AMAZON TECH INC
  • US9521140B2 patent drawing
  • US9521140B2 patent drawing
  • US9521140B2 patent drawing

AI summary

Techniques for managing secure execution environments provided as a service to computing resource service provider customers are described herein. A request to launch a secure execution environment is received from a customer and fulfilled by launching a secure execution environment on a selected computer system. The secure execution environment is then validated and upon a successful validation, one or more applications are provided to the secure execution environment to be executed within the secure execution environment. As additional requests relating to managing the secure execution environment are received, operations are performed based on the requests.