TEE-Based Trusted Channel for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of network security, existing HTTPS protocols are vulnerable to man-in-the-middle attacks, and Certificate Authorities (CAs) cannot verify the credibility of Trusted Execution Environments (TEEs) in untrusted cloud servers, preventing secure communication channels from being established between users and cloud servers.
Innovation Solution
A TEE-based method that initiates a trusted measurement mechanism to assess the operation environment and content within the TEE, sends the measurement results to a trusted verification module, and establishes a secure communication channel when the environment and content are deemed credible and secure, using a digital certificate signed by the trusted verification module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HTTPS protocol with CA verification is used, then secure communication channel can be established between user and website, but the CA cannot verify the credibility of TEE in untrusted cloud server
Solution Approach 1:
The patent introduces a trusted verification module as an intermediary between the user and the cloud server's TEE. This module operates within the TEE itself and performs verification functions that the external CA cannot provide, thereby resolving the contradiction between maintaining security verification and adapting to untrusted cloud environments.
Solution Approach 2:
The verification function is segmented into two parts: the trusted verification module that operates within the TEE to perform security measurements, and the external CA that handles traditional certificate verification. This segmentation allows each component to specialize in its strengths while working together to provide comprehensive verification.
2Reliability
If user trusts only the TEE module in untrusted cloud server, then privacy computing requirement can be met, but communication channel cannot be established due to lack of verification capability
Solution Approach 1:
The TEE performs self-verification through the trusted verification module that operates within its own environment. The TEE autonomously measures its own security state and generates verification information, eliminating the need for external verification of the TEE's internal state and enabling seamless channel establishment.
3Measurement precision
If CA verifies HTTPS server, then legal identity can be proven, but capability to detect TEE credibility and operation security is lacking
Solution Approach 1:
The patent adds a new dimension of verification by introducing hardware-based security measurements within the TEE environment. This goes beyond the traditional software-based certificate verification to include hardware-level integrity checks, creating a multi-dimensional verification framework that can detect TEE credibility and operation security.
Data Source
AI summary
A TEE-based method to establish trusted and secure channel between the user and public cloud environment, an apparatus, a computer device, and a computer-readable storage medium are provided. After a TEE is started, a trusted measurement mechanism of the TEE is called to perform security measurement on an operation environment and an operation content of a computing node operated in the TEE, and a measurement result is sent to a trusted verification module. Relevant verification information is acquired from a remote verification server of the TEE, and the trusted verification module is controlled to verify the measurement result according to the relevant verification information. When it is confirmed that the operation environment of the computing node is credible and the operation content of the computing node is secure, a communication channel is established between the user and the computing node.

