Sealing Key Management Service for Cross-Platform Data Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current privacy computing-based trusted sealing technologies, such as Intel SGX, are inflexible and unable to facilitate the large-scale migration of encrypted data across platforms due to keys being bound to specific hardware, making data recovery difficult if the original host is damaged.
Innovation Solution
A method involving a sealing key management service (SKMS) that establishes trusted connections and provides download links for authorized platforms to decrypt and use privacy data, using a mapping table and data signature packets to ensure secure and flexible data migration across platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using CPU-level privacy computing trusted sealing technology, then data security is improved, but data migration flexibility deteriorates
Solution Approach 1:
The patent introduces a sealing key management service (SKMS) as an intermediary between the encrypted data and the platforms. The SKMS holds and manages the sealing keys, allowing authorized platforms to retrieve keys and decrypt data without the data being directly bound to specific hardware. This mediator resolves the contradiction by maintaining security through controlled key access while enabling migration through key distribution to multiple platforms.
2Reliability
If sealing keys are bound to specific host hardware, then data privacy protection is improved, but data recovery capability deteriorates
Solution Approach 1:
The patent segments the security architecture by separating the sealing key management function from the host hardware. Instead of binding keys directly to hardware, the system divides key management into a dedicated service (SKMS) that can be accessed by multiple platforms. This segmentation allows data recovery on alternative platforms by retrieving keys from the SKMS, while maintaining privacy protection through controlled access mechanisms.
3Reliability
If trusted sealing technology is implemented at CPU level, then data operation credibility is improved, but system complexity increases
Solution Approach 1:
The patent extracts the sealing key management functionality from the CPU-level trusted execution environment and places it in a separate sealing key management service. This extraction reduces the complexity burden on individual platforms while maintaining the credibility benefits of trusted sealing. The SKMS handles key management operations centrally, simplifying the system architecture compared to implementing full trusted sealing capabilities on every platform.
Data Source
AI summary
A privacy computing-enabled migration method for large-scale persistent data across platforms is provided. By virtue of a sealing key management service SKMS, based on trusted sealing and trusted connection which are the basic functions of privacy computing, large-scale migration of privacy data with low deployment cost, high security and high efficiency can be realized by providing download links to platforms that meet requirements, thus greatly improving the flexibility of data deployment and use and the landing of trusted sealing technology.


