TEE-Based Trusted Channel for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of network security, existing HTTPS protocols are vulnerable to man-in-the-middle attacks, and Certificate Authorities (CAs) cannot verify the credibility of Trusted Execution Environments (TEEs) in untrusted cloud servers, preventing secure communication channels from being established between users and cloud servers.

Innovation Solution

A TEE-based method that initiates a trusted measurement mechanism to assess the operation environment and content within the TEE, sends the measurement results to a trusted verification module, and establishes a secure communication channel when the environment and content are deemed credible and secure, using a digital certificate signed by the trusted verification module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HTTPS protocol with CA verification is used, then secure communication channel can be established between user and website, but the CA cannot verify the credibility of TEE in untrusted cloud server

Engineering Contradiction:
Improveverification capabilityVSAvoidtrust model flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a trusted verification module as an intermediary between the user and the cloud server's TEE. This module operates within the TEE itself and performs verification functions that the external CA cannot provide, thereby resolving the contradiction between maintaining security verification and adapting to untrusted cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification function is segmented into two parts: the trusted verification module that operates within the TEE to perform security measurements, and the external CA that handles traditional certificate verification. This segmentation allows each component to specialize in its strengths while working together to provide comprehensive verification.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user trusts only the TEE module in untrusted cloud server, then privacy computing requirement can be met, but communication channel cannot be established due to lack of verification capability

Engineering Contradiction:
Improveprivacy protectionVSAvoidchannel establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The TEE performs self-verification through the trusted verification module that operates within its own environment. The TEE autonomously measures its own security state and generates verification information, eliminating the need for external verification of the TEE's internal state and enabling seamless channel establishment.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If CA verifies HTTPS server, then legal identity can be proven, but capability to detect TEE credibility and operation security is lacking

Engineering Contradiction:
Improveidentity verificationVSAvoidTEE security detection
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds a new dimension of verification by introducing hardware-based security measurements within the TEE environment. This goes beyond the traditional software-based certificate verification to include hardware-level integrity checks, creating a multi-dimensional verification framework that can detect TEE credibility and operation security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20240422014A1TEE-based method to establish trusted and secure channel between the user and public cloud environment, apparatus, computer device, and readable storage medium
Publication Date: 2024.12.19 DBAPPSECURITY CO LTD
  • US20240422014A1 patent drawing
  • US20240422014A1 patent drawing

AI summary

A TEE-based method to establish trusted and secure channel between the user and public cloud environment, an apparatus, a computer device, and a computer-readable storage medium are provided. After a TEE is started, a trusted measurement mechanism of the TEE is called to perform security measurement on an operation environment and an operation content of a computing node operated in the TEE, and a measurement result is sent to a trusted verification module. Relevant verification information is acquired from a remote verification server of the TEE, and the trusted verification module is controlled to verify the measurement result according to the relevant verification information. When it is confirmed that the operation environment of the computing node is credible and the operation content of the computing node is secure, a communication channel is established between the user and the computing node.