Client-Authorized Data Access Using TEE Credential Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing importance of data security in data interaction between user terminals and cloud environments poses challenges in ensuring the confidentiality and integrity of user data, particularly in the absence of user authorization and the risk of unauthorized access and leakage.

Innovation Solution

A data access method involving a trusted execution environment (TEE) and credential management service (TKS) that ensures secure data access by sending authorization requests to clients, obtaining access credentials based on user authorization, and processing data within a secure computing environment to prevent unauthorized access and leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted between user terminals and cloud environment, then data processing capability is improved, but data security and confidentiality deteriorate due to unauthorized access risks

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a credential management service as an intermediary between user terminals and cloud environment. This service manages access credentials and authorization, allowing data processing to occur while maintaining security through controlled access. The intermediary verifies credentials before permitting data transmission and processing, thus resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented to prevent unauthorized access, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The credential management service operates autonomously to verify credentials and manage access control. Instead of requiring complex manual authorization processes, the system automatically validates access credentials and manages permission levels. This self-service approach maintains high data security while reducing the operational complexity of access control management.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple access credentials are managed for different clients, then access control precision is improved, but management complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidcredential management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The credential management service provides a universal platform for managing multiple access credentials across different clients and data resources. Instead of implementing separate credential management systems for each client or resource, the patent creates a multi-functional service that handles credential issuance, verification, and revocation for all clients uniformly. This universal approach improves access control precision while reducing overall management complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4708091A1Data access method, apparatus, device and readable storage medium
Publication Date: 2026.03.11 BEIJING ZITIAO NETWORK TECH CO LTD
  • EP4708091A1 patent drawingFigure 1
  • EP4708091A1 patent drawingFigure 2
  • EP4708091A1 patent drawingFigure 3

AI summary

Embodiments of the disclosure provide a data access method, an apparature, a device and a readable storage medium. The method includes: in response to a demand of processing the data resource generated in a target application, sending a data access authorization request for the data resource to a plurality of clients of the target application, the plurality of clients being associated with the data resource. The authorization information for the data access authorization request is received respectively from at least one of the plurality of clients. At least one access credential respectively corresponding to the at least one client is obtained based on the authorization information. The target data associated with the at least one client in the data resource is accessed with the at least one access credential to process the target data.