Trusted Execution Environment Data Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing technologies face challenges in ensuring secure data transmission and authorization between multiple parties, particularly in protecting data privacy during evaluation processes, which requires real-time cooperation and cryptography-based secure multi-party computing protocols.
Innovation Solution
A data processing method and apparatus utilizing trusted execution environments (TEEs) for secure data transmission and authorization, where data providers upload encrypted data and authorization information to a data manager, allowing secure access and use by authorized users without real-time data provider involvement, leveraging TEEs for verification and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure multi-party computing protocol is used to protect data privacy, then data security and privacy protection are improved, but real-time cooperation and complex cryptography operations are required, increasing system complexity and processing time
Solution Approach 1:
The patent applies preliminary action by pre-establishing trusted execution environments (TEEs) and authorization relationships before data processing occurs. The data provider预先 establishes a TEE with the data manager and configures authorization information, so that when data access is needed, the system can directly utilize the pre-configured trusted environment without performing complex real-time verification or cryptography operations, thus reducing system complexity while maintaining security
Solution Approach 2:
The patent introduces a data manager as an intermediary between the data provider and data user. The data manager operates within a TEE and handles authorization verification and key management, eliminating the need for direct complex cryptographic interactions between data providers and users. This intermediary approach simplifies the overall system architecture while preserving data security through the trusted execution environment
2Reliability
If real-time cooperation between data provider and data user is required for data access, then data security control is improved, but processing time and system response speed deteriorate
Solution Approach 1:
The patent applies preliminary action by pre-establishing TEEs and authorization frameworks before data access requests occur. The data provider configures authorization information and establishes trusted execution environments in advance, enabling rapid data access without real-time security verification delays. When a data user requests access, the pre-configured TEE can immediately verify authorization and provide data keys, significantly reducing processing time while maintaining security control
Solution Approach 2:
The patent enables self-service by allowing the TEE to autonomously handle authorization verification and key management without requiring real-time human intervention or complex cooperative protocols. The pre-established TEE automatically verifies data user credentials against stored authorization information and provides appropriate access keys, eliminating time-consuming manual security checks while ensuring secure data access
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Implementations of the present specification provide a data processing method and apparatus. A method performed by a data provider includes: obtaining first encrypted data of first plaintext data, a first key used to decrypt the first encrypted data, and authorization information about the first plaintext data; sending a verification request to a data manager, the data manager including a first trusted execution environment; receiving authentication information from the data manager, and performing verification based on the authentication information; when the verification succeeds, securely transmitting the first key and the authorization information to the first trusted execution environment; and providing the first encrypted data to the data manager.