Trusted Execution Environment Data Individualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Attackers can manipulate trusted execution environments, allowing access to and altering the behavior and data of user applications, compromising the security of computer systems.

Innovation Solution

A method and device for processing data in a protected trusted execution environment, where data is individualized using a second application identification, and access is restricted by comparing an expected identification with the actual identification, preventing execution in manipulated environments and encrypting individualized data for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is individualized using a second application identification, then data integrity and security are improved, but device complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identification system is segmented into multiple components: a first application identification and a configuration identification that are combined to form a second application identification. This segmentation allows for more granular control and tracking of data integrity without requiring a complete redesign of the entire system architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The second application identification is determined in advance before data processing operations occur. By pre-establishing the individualized identification based on the first application identification and configuration identification, the system can verify data integrity proactively rather than reactively, reducing the need for complex post-processing verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access to configuration data is restricted through identification comparison, then security against attacks is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary verification mechanism that compares the determined second application identification with an expected application identification. This intermediary step acts as a mediator between the application and the configuration data, providing automated security verification without requiring manual access control procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-verification by automatically determining the second application identification and comparing it against the expected identification. This self-service approach to access control eliminates the need for manual security checks while maintaining robust security, thereby improving ease of operation despite the enhanced security measures.

Inventive Principle:
Principle #25Self-service

3Reliability

If trusted execution environment is protected against manipulation, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against manipulationVSAvoidenvironment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent protects the trusted execution environment by changing key parameters such as the configuration identification and the derived second application identification. By varying these parameters based on the specific application and its configuration, the system creates a unique protective signature for each execution environment without requiring fundamental changes to the environment's core architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11783038B2Device and method for computer-aided processing of data
Publication Date: 2023.10.10 TECHNISCHE UNIVERSITAT DRESDEN
  • US11783038B2 patent drawing
  • US11783038B2 patent drawing
  • US11783038B2 patent drawing

AI summary

A device and a method for computer-aided processing of data are disclosed, the method including: providing configuration data of an application, determining a first application identification, wherein the first application identification is assigned to the application, determining a configuration identification, wherein the configuration identification is assigned to the configuration data of the application, individualizing the data by means of a second application identification, wherein the second application identification is determined using the first application identification and the configuration identification.