Sealing Key Management Service for Cross-Platform Data Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current privacy computing-based trusted sealing technologies, such as Intel SGX, are inflexible and unable to facilitate the large-scale migration of encrypted data across platforms due to keys being bound to specific hardware, making data recovery difficult if the original host is damaged.

Innovation Solution

A method involving a sealing key management service (SKMS) that establishes trusted connections and provides download links for authorized platforms to decrypt and use privacy data, using a mapping table and data signature packets to ensure secure and flexible data migration across platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted using CPU-level privacy computing trusted sealing technology, then data security is improved, but data migration flexibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata migration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a sealing key management service (SKMS) as an intermediary between the encrypted data and the platforms. The SKMS holds and manages the sealing keys, allowing authorized platforms to retrieve keys and decrypt data without the data being directly bound to specific hardware. This mediator resolves the contradiction by maintaining security through controlled key access while enabling migration through key distribution to multiple platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sealing keys are bound to specific host hardware, then data privacy protection is improved, but data recovery capability deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoiddata recovery capability
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent segments the security architecture by separating the sealing key management function from the host hardware. Instead of binding keys directly to hardware, the system divides key management into a dedicated service (SKMS) that can be accessed by multiple platforms. This segmentation allows data recovery on alternative platforms by retrieving keys from the SKMS, while maintaining privacy protection through controlled access mechanisms.

Inventive Principle:
Principle #1Segmentation

3Reliability

If trusted sealing technology is implemented at CPU level, then data operation credibility is improved, but system complexity increases

Engineering Contradiction:
Improvedata operation credibilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the sealing key management functionality from the CPU-level trusted execution environment and places it in a separate sealing key management service. This extraction reduces the complexity burden on individual platforms while maintaining the credibility benefits of trusted sealing. The SKMS handles key management operations centrally, simplifying the system architecture compared to implementing full trusted sealing capabilities on every platform.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12021849B2Privacy computing-enabled migration method for large-scale persistent data across platforms
Publication Date: 2024.06.25 NANHU LAB
  • US12021849B2 patent drawing
  • US12021849B2 patent drawing
  • US12021849B2 patent drawing

AI summary

A privacy computing-enabled migration method for large-scale persistent data across platforms is provided. By virtue of a sealing key management service SKMS, based on trusted sealing and trusted connection which are the basic functions of privacy computing, large-scale migration of privacy data with low deployment cost, high security and high efficiency can be realized by providing download links to platforms that meet requirements, thus greatly improving the flexibility of data deployment and use and the landing of trusted sealing technology.