TEE Attestation Models for Multi-Tenant Confidential Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems lack a means for clients to verify the integrity of cloud environments against non-trivial requirements, making it difficult to build automated and configured trusted environments for multi-party operations.
Innovation Solution
A multi-party Attestation Model is implemented within a trusted execution environment (TEE) of a multi-tenant cloud infrastructure, receiving tenant-specific requirements to build and deploy a smart contract that separates components based on compliance with the Attestation Model, ensuring only trusted components are used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a multi-tenant cloud infrastructure is used to provide shared resources and services, then resource utilization and productivity are improved, but the ability to verify integrity and ensure compliance with different tenant requirements deteriorates
Solution Approach 1:
The patent segments the cloud infrastructure into isolated execution environments (enclaves) for each tenant, where each enclave maintains its own attestation model and integrity verification mechanisms. This allows multiple tenants to share the same physical infrastructure while each tenant's data and computations remain isolated and verifiable according to their specific requirements.
Solution Approach 2:
The patent introduces an attestation model as an intermediary layer between the cloud provider and tenants. This attestation model includes smart contracts that mediate verification of environment integrity, enabling tenants to verify compliance without directly accessing or trusting the underlying infrastructure, thus maintaining both multi-tenant efficiency and verification capability.
2Adaptability or versatility
If automated environment configuration is implemented to meet different tenant requirements, then adaptability is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent implements self-service through automated attestation model deployment and smart contract execution. The system automatically configures trusted execution environments for each tenant based on their requirements, with the attestation model self-verifyring compliance through blockchain-based smart contracts, eliminating the need for manual configuration and reducing operational complexity.
Solution Approach 2:
The patent creates a universal attestation framework that can accommodate different tenant requirements through a standardized interface. The same underlying infrastructure and attestation model architecture serves multiple tenants with diverse needs, providing tailored environments through configuration rather than structural complexity.
3Reliability
If strict attestation verification is enforced to ensure compliance, then data confidentiality and security are improved, but operational speed and deployment efficiency deteriorate
Solution Approach 1:
The patent performs attestation verification in advance through pre-deployment smart contract validation and environment attestation. By verifying integrity requirements before data processing or deployment occurs, the system ensures confidentiality without adding verification overhead during critical operations, thus maintaining deployment speed while ensuring security.
Data Source
AI summary
A computer-implemented method for building and using a multi-party Attestation Model for controlling operation of a multi-tenant cloud infrastructure which includes providing a trusted execution environment (TEE) within the multi-tenant cloud infrastructure, receiving a set of requirements from each of a plurality of tenants of the multi-tenant cloud infrastructure, building an Attestation Model according to the sets of requirements, and deploying the Attestation Model within the TEE. In response to a determination that a change does not satisfy the Attestation Model for each of the plurality of tenants, a function is performed to separate components shared between tenants for which the change satisfies the Attestation Model from components shared between tenants for which the change does not satisfy the Attestation Model, and the change is deployed on the multi-tenant cloud infrastructure for the tenants for which the change satisfies the Attestation Model.


