Trusted Execution Environment Data Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing technologies face challenges in ensuring secure data transmission and authorization between multiple parties, particularly in protecting data privacy during evaluation processes, which requires real-time cooperation and cryptography-based secure multi-party computing protocols.

Innovation Solution

A data processing method and apparatus utilizing trusted execution environments (TEEs) for secure data transmission and authorization, where data providers upload encrypted data and authorization information to a data manager, allowing secure access and use by authorized users without real-time data provider involvement, leveraging TEEs for verification and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure multi-party computing protocol is used to protect data privacy, then data security and privacy protection are improved, but real-time cooperation and complex cryptography operations are required, increasing system complexity and processing time

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing trusted execution environments (TEEs) and authorization relationships before data processing occurs. The data provider预先 establishes a TEE with the data manager and configures authorization information, so that when data access is needed, the system can directly utilize the pre-configured trusted environment without performing complex real-time verification or cryptography operations, thus reducing system complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a data manager as an intermediary between the data provider and data user. The data manager operates within a TEE and handles authorization verification and key management, eliminating the need for direct complex cryptographic interactions between data providers and users. This intermediary approach simplifies the overall system architecture while preserving data security through the trusted execution environment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time cooperation between data provider and data user is required for data access, then data security control is improved, but processing time and system response speed deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing TEEs and authorization frameworks before data access requests occur. The data provider configures authorization information and establishes trusted execution environments in advance, enabling rapid data access without real-time security verification delays. When a data user requests access, the pre-configured TEE can immediately verify authorization and provide data keys, significantly reducing processing time while maintaining security control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing the TEE to autonomously handle authorization verification and key management without requiring real-time human intervention or complex cooperative protocols. The pre-established TEE automatically verifies data user credentials against stored authorization information and provides appropriate access keys, eliminating time-consuming manual security checks while ensuring secure data access

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3813324B1Data processing method and device
Publication Date: 2023.04.26 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3813324B1 patent drawingFigure 1~2
  • EP3813324B1 patent drawingFigure 3~4
  • EP3813324B1 patent drawingFigure 5~6

AI summary

Implementations of the present specification provide a data processing method and apparatus. A method performed by a data provider includes: obtaining first encrypted data of first plaintext data, a first key used to decrypt the first encrypted data, and authorization information about the first plaintext data; sending a verification request to a data manager, the data manager including a first trusted execution environment; receiving authentication information from the data manager, and performing verification based on the authentication information; when the verification succeeds, securely transmitting the first key and the authorization information to the first trusted execution environment; and providing the first encrypted data to the data manager.