TEE Data Access Enforcement for Privacy Policy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are reluctant to trust applications with their confidential data due to the lack of assurance that privacy policies are enforced, and there is no protection against unauthorized data disclosure, necessitating a solution to enhance trustworthiness and transparency in data handling.

Innovation Solution

A data access device and method utilizing a Trusted Execution Environment (TEE) with a Data Exposure Enforcement (DEE) unit to enforce a data exposure policy (DEP), including an input unit, processing unit, and output unit, which manipulates data according to anonymization, exposure, and aggregation policies to ensure compliance with the DEP, ensuring data confidentiality and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a service provider publishes a data privacy policy, then data transparency is improved, but data protection against unauthorized disclosure remains insufficient

Engineering Contradiction:
Improvedata transparencyVSAvoiddata protection
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent introduces a Data Exposure Enforcement (DEE) unit as an intermediary component between the application and the data storage. This DEE unit, running in a Trusted Execution Environment (TEE), acts as a mediator that enforces the data exposure policy by controlling which data is accessible to whom, thereby resolving the contradiction between publishing privacy policies and actually protecting data from unauthorized disclosure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical security measures with a software-based enforcement mechanism running in a TEE. The TEE provides a secure computational environment that automatically enforces data exposure policies without requiring manual intervention or traditional access control mechanisms, enabling both transparency through policy publication and reliable protection through automated enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If user data is entrusted to an application, then data accessibility is improved, but user trust is reduced due to lack of assurance on privacy policy enforcement

Engineering Contradiction:
Improvedata accessibilityVSAvoiduser trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The DEE unit implements self-service by automatically enforcing data exposure policies without requiring manual review or intervention. The system autonomously determines which data can be accessed by which users based on the published privacy policy, maintaining both ease of data accessibility and user trust through transparent, automated enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent substitutes manual trust-building mechanisms with a TEE-based automated enforcement system. The TEE provides cryptographic guarantees and attestation mechanisms that automatically assure users their data is protected according to the published policy, eliminating the need for manual verification while maintaining both accessibility and trust.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If data is processed according to application requirements, then data usability is improved, but data security is worsened due to potential unauthorized access

Engineering Contradiction:
Improvedata usabilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data processing function into two distinct parts: the Application Processing Unit that handles business logic and data transformation, and the DEE unit that handles security enforcement. This segmentation allows the system to maintain data usability through flexible application processing while preventing unauthorized access through dedicated security enforcement, resolving the contradiction between adaptability and security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12511435B2Device and method for enforcing a data policy
Publication Date: 2025.12.30 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US12511435B2 patent drawing
  • US12511435B2 patent drawing
  • US12511435B2 patent drawing

AI summary

A data access device for enforcing a data policy, including an input unit, a processing unit, a data exposure enforcement unit, and an output unit, where the data access device is configured to run in a trusted execution environment; the input unit is configured to receive a first data including a request for handling data, and a target identification; the processing unit is configured to process the first data to attain a second data including the target identification and a data structure according to requirements of an application running in the data access device; the data exposure enforcement unit is configured to manipulate the second data according to a data exposure policy to attain a third data; and the output unit is configured to output the third data.