Trusted VM Image Launch Using TEE Metric Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of implementing secure and reliable data management in third-party cloud environments, where trust is not inherently present, necessitates a solution to ensure data security and integrity.

Innovation Solution

A data processing method and apparatus utilizing a trusted execution environment, where a host device determines a metric value for a virtual machine, sends it to a client device, receives a decryption key, and runs the virtual machine image file based on this key, ensuring secure data management through a trusted execution environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trusted execution environment is implemented to ensure data security, then data security and reliability are improved, but device complexity and deployment costs increase

Engineering Contradiction:
Improvedata securityVSAvoidenvironment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted execution environment component as an intermediary between the host device and client device. This component acts as a mediator that verifies metric values and manages decryption keys, thereby establishing trust without requiring complete environmental trust. The intermediary handles the complex verification processes while presenting a simplified interface to users, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the trust verification process into distinct components: metric value generation on the host device, metric value transmission through the trusted execution environment component, and decryption key verification on the client device. This segmentation allows each component to focus on specific security tasks, improving overall reliability while making the complex trust establishment process more manageable and modular.

Inventive Principle:
Principle #1Segmentation

2Reliability

If metric value verification and decryption key transmission are implemented through a trusted execution environment component, then data integrity is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The host device pre-generates metric values that describe the virtual machine environment before client interaction. These metric values are prepared in advance and stored ready for transmission. When a client connects, the verification process uses these pre-computed values rather than requiring real-time analysis of the entire virtual machine state, significantly reducing processing time while maintaining data integrity verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12587368B2Method, apparatus, device and storage medium for data processing
Publication Date: 2026.03.24 BEIJING VOLCANO ENGINE TECH CO LTD
  • US12587368B2 patent drawing
  • US12587368B2 patent drawing
  • US12587368B2 patent drawing

AI summary

The embodiment of this disclosure provides a method, an apparatus, a device and a computer readable storage medium for data processing based on a trusted execution environment. The method includes: a host device determines, based on a first parameter set, a first metric value for describing a target virtual machine hosted on the host device. The host device sends the first metric value to a client device via a trusted execution environment component of the host device. Next, the host device receives, from the client device via the trusted execution environment component, a decryption key for decrypting a first virtual image file of the target virtual machine; and runs, based on the decryption key, the first virtual image file to start the target virtual machine. Thereby, a user may implement a data processing system based on a trusted execution environment.