Client-Authorized Data Access Using TEE Credential Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing importance of data security in data interaction between user terminals and cloud environments poses challenges in ensuring the confidentiality and integrity of user data, particularly in the absence of user authorization and the risk of unauthorized access and leakage.
Innovation Solution
A data access method involving a trusted execution environment (TEE) and credential management service (TKS) that ensures secure data access by sending authorization requests to clients, obtaining access credentials based on user authorization, and processing data within a secure computing environment to prevent unauthorized access and leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transmitted between user terminals and cloud environment, then data processing capability is improved, but data security and confidentiality deteriorate due to unauthorized access risks
Solution Approach 1:
The patent introduces a credential management service as an intermediary between user terminals and cloud environment. This service manages access credentials and authorization, allowing data processing to occur while maintaining security through controlled access. The intermediary verifies credentials before permitting data transmission and processing, thus resolving the contradiction between productivity and reliability.
2Reliability
If access control mechanisms are implemented to prevent unauthorized access, then data security is improved, but system complexity increases
Solution Approach 1:
The credential management service operates autonomously to verify credentials and manage access control. Instead of requiring complex manual authorization processes, the system automatically validates access credentials and manages permission levels. This self-service approach maintains high data security while reducing the operational complexity of access control management.
3Measurement precision
If multiple access credentials are managed for different clients, then access control precision is improved, but management complexity increases
Solution Approach 1:
The credential management service provides a universal platform for managing multiple access credentials across different clients and data resources. Instead of implementing separate credential management systems for each client or resource, the patent creates a multi-functional service that handles credential issuance, verification, and revocation for all clients uniformly. This universal approach improves access control precision while reducing overall management complexity through consolidation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the disclosure provide a data access method, an apparature, a device and a readable storage medium. The method includes: in response to a demand of processing the data resource generated in a target application, sending a data access authorization request for the data resource to a plurality of clients of the target application, the plurality of clients being associated with the data resource. The authorization information for the data access authorization request is received respectively from at least one of the plurality of clients. At least one access credential respectively corresponding to the at least one client is obtained based on the authorization information. The target data associated with the at least one client in the data resource is accessed with the at least one access credential to process the target data.