Trusted VM Image Decryption Using Host TEE Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing secure and reliable data management in a third-party cloud environment provided by third-party companies is not trusted environment, how to implement secure and reliable data management in a trusted execution environment, how to implement secure and reliable data management in a third-party cloud environment is a technical problem that needs to be solved currently.

Innovation Solution

A data processing method based on a trusted execution environment, where a host device determines a first metric value describing a target virtual machine, sends it to a client device, receives a decryption key, and runs the virtual machine based on the key, ensuring secure data management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is uploaded to third-party cloud environment, then data management convenience is improved, but data security and trustworthiness deteriorate

Engineering Contradiction:
Improvedata management convenienceVSAvoiddata security and trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments data management into two parts: unencrypted data processing in the third-party cloud environment and encrypted data storage/access controlled by the user's client device. This allows convenient cloud usage while maintaining security through separation of compute and data control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the client device acts as a mediator between the user and the third-party cloud environment. The client device holds decryption keys and controls data access, mediating all data operations to ensure security while allowing cloud processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted execution environment is implemented, then data security is improved, but deployment cost and complexity increase

Engineering Contradiction:
Improvedata securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The TEE component in the host device serves as an intermediary that provides trusted execution capabilities without requiring the entire cloud infrastructure to be rebuilt. This localized TEE implementation reduces deployment complexity compared to full trusted cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies trusted execution environment capabilities locally at the host device level rather than requiring system-wide implementation. This localized approach reduces overall deployment complexity while maintaining security for specific data workloads.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption is applied to data, then data security is improved, but data processing efficiency deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments data into encrypted and unencrypted portions, processing unencrypted data efficiently in the cloud while keeping only critical data encrypted. This selective encryption approach maintains processing efficiency for most operations while securing sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TEE component acts as an intermediary that enables efficient encrypted data processing by providing hardware-accelerated cryptographic operations. This mediator reduces the performance overhead typically associated with encryption through specialized hardware support.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4726584A1Data processing method and apparatus, and device and storage medium
Publication Date: 2026.04.15 BEIJING VOLCANO ENGINE TECH CO LTD
  • EP4726584A1 patent drawingFigure 1A~1B
  • EP4726584A1 patent drawingFigure 2
  • EP4726584A1 patent drawingFigure 3A

AI summary

The embodiment of this disclosure provides a method, an apparatus, a device and a computer readable storage medium for data processing based on a trusted execution environment. The method includes: a host device determines, based on a first parameter set, a first metric value for describing a target virtual machine hosted on the host device. The host device sends the first metric value to a client device via a trusted execution environment component of the host device. Next, the host device receives, from the client device via the trusted execution environment component, a decryption key for decrypting a first virtual image file of the target virtual machine; and runs, based on the decryption key, the first virtual image file to start the target virtual machine. Thereby, a user may implement a data processing system based on a trusted execution environment.