Trusted VM Image Decryption Using Host TEE Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing secure and reliable data management in a third-party cloud environment provided by third-party companies is not trusted environment, how to implement secure and reliable data management in a trusted execution environment, how to implement secure and reliable data management in a third-party cloud environment is a technical problem that needs to be solved currently.
Innovation Solution
A data processing method based on a trusted execution environment, where a host device determines a first metric value describing a target virtual machine, sends it to a client device, receives a decryption key, and runs the virtual machine based on the key, ensuring secure data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is uploaded to third-party cloud environment, then data management convenience is improved, but data security and trustworthiness deteriorate
Solution Approach 1:
The system segments data management into two parts: unencrypted data processing in the third-party cloud environment and encrypted data storage/access controlled by the user's client device. This allows convenient cloud usage while maintaining security through separation of compute and data control.
Solution Approach 2:
The patent introduces an intermediary mechanism where the client device acts as a mediator between the user and the third-party cloud environment. The client device holds decryption keys and controls data access, mediating all data operations to ensure security while allowing cloud processing.
2Reliability
If trusted execution environment is implemented, then data security is improved, but deployment cost and complexity increase
Solution Approach 1:
The TEE component in the host device serves as an intermediary that provides trusted execution capabilities without requiring the entire cloud infrastructure to be rebuilt. This localized TEE implementation reduces deployment complexity compared to full trusted cloud environments.
Solution Approach 2:
The patent applies trusted execution environment capabilities locally at the host device level rather than requiring system-wide implementation. This localized approach reduces overall deployment complexity while maintaining security for specific data workloads.
3Reliability
If encryption is applied to data, then data security is improved, but data processing efficiency deteriorates
Solution Approach 1:
The system segments data into encrypted and unencrypted portions, processing unencrypted data efficiently in the cloud while keeping only critical data encrypted. This selective encryption approach maintains processing efficiency for most operations while securing sensitive information.
Solution Approach 2:
The TEE component acts as an intermediary that enables efficient encrypted data processing by providing hardware-accelerated cryptographic operations. This mediator reduces the performance overhead typically associated with encryption through specialized hardware support.
Data Source
Figure 1A~1B
Figure 2
Figure 3A
AI summary
The embodiment of this disclosure provides a method, an apparatus, a device and a computer readable storage medium for data processing based on a trusted execution environment. The method includes: a host device determines, based on a first parameter set, a first metric value for describing a target virtual machine hosted on the host device. The host device sends the first metric value to a client device via a trusted execution environment component of the host device. Next, the host device receives, from the client device via the trusted execution environment component, a decryption key for decrypting a first virtual image file of the target virtual machine; and runs, based on the decryption key, the first virtual image file to start the target virtual machine. Thereby, a user may implement a data processing system based on a trusted execution environment.