TEE Cloning Service for Low-Latency Elastic Scaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing trusted execution environments face challenges in elastic launching and scaling due to reliance on external attestation services, which can lead to latency, high costs, and security vulnerabilities, especially when private clouds become unavailable or slow down.
Innovation Solution
Implementing a system where each TEE instance maintains an encrypted secret and includes a cloning service to validate and provision newly launched instances, allowing for self-servicing and reducing reliance on external validation, enabling elastic scaling without compromising security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external attestation services are used to validate TEE instances, then security validation is achieved, but latency increases and availability decreases when external services are unavailable
Solution Approach 1:
The patent combines the attestation service functionality directly into each TEE instance through the cloning service. Instead of relying on external attestation services, each TEE instance can independently validate new instances by receiving and verifying cryptographic measurements, eliminating external dependency and reducing latency.
Solution Approach 2:
TEE instances perform self-validation through the cloning service mechanism. Each TEE instance can act as both a client and a server, validating its own clones by receiving cryptographic measurements and verifying them against stored encrypted secrets, thereby serving itself rather than relying on external services.
2Device complexity
If external attestation services are used for TEE validation, then centralized control is maintained, but system complexity and cost increase
Solution Approach 1:
The patent segments the centralized attestation functionality into distributed cloning services within each TEE instance. Each instance maintains encrypted secrets and can independently validate clones, distributing the validation capability across multiple nodes rather than concentrating it in a single external service, thereby reducing architectural complexity while maintaining security.
3Productivity
If cryptographic measurements are validated externally, then security is maintained, but scaling speed is limited
Solution Approach 1:
The cloning service enables TEE instances to perform self-validation by receiving cryptographic measurements from new instances and verifying them against encrypted secrets stored locally. This eliminates the need for external validation, allowing rapid scaling while maintaining security through cryptographic verification.
Solution Approach 2:
Encrypted secrets are pre-provisioned in each TEE instance during initialization. When new instances are launched, the validation process can immediately proceed by comparing cryptographic measurements against these pre-stored secrets, eliminating the need for real-time external attestation and enabling faster scaling.
Data Source
AI summary
A system includes a memory, a processor in communication with the memory, and a first TEE instance. The first TEE instance is configured to maintain an encrypted secret, obtain a cryptographic measurement associated with a second TEE instance, validate the cryptographic measurement, and provision the second TEE instance with the encrypted secret. Additionally, the first TEE instance and the second TEE instance are both configured to service at least a first type of request.


