Trusted VM Image Launch Using TEE Metric Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of implementing secure and reliable data management in third-party cloud environments, where trust is not inherently present, necessitates a solution to ensure data security and integrity.
Innovation Solution
A data processing method and apparatus utilizing a trusted execution environment, where a host device determines a metric value for a virtual machine, sends it to a client device, receives a decryption key, and runs the virtual machine image file based on this key, ensuring secure data management through a trusted execution environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted execution environment is implemented to ensure data security, then data security and reliability are improved, but device complexity and deployment costs increase
Solution Approach 1:
The patent introduces a trusted execution environment component as an intermediary between the host device and client device. This component acts as a mediator that verifies metric values and manages decryption keys, thereby establishing trust without requiring complete environmental trust. The intermediary handles the complex verification processes while presenting a simplified interface to users, resolving the contradiction between security and complexity.
Solution Approach 2:
The system segments the trust verification process into distinct components: metric value generation on the host device, metric value transmission through the trusted execution environment component, and decryption key verification on the client device. This segmentation allows each component to focus on specific security tasks, improving overall reliability while making the complex trust establishment process more manageable and modular.
2Reliability
If metric value verification and decryption key transmission are implemented through a trusted execution environment component, then data integrity is improved, but communication overhead and processing time increase
Solution Approach 1:
The host device pre-generates metric values that describe the virtual machine environment before client interaction. These metric values are prepared in advance and stored ready for transmission. When a client connects, the verification process uses these pre-computed values rather than requiring real-time analysis of the entire virtual machine state, significantly reducing processing time while maintaining data integrity verification.
Data Source
AI summary
The embodiment of this disclosure provides a method, an apparatus, a device and a computer readable storage medium for data processing based on a trusted execution environment. The method includes: a host device determines, based on a first parameter set, a first metric value for describing a target virtual machine hosted on the host device. The host device sends the first metric value to a client device via a trusted execution environment component of the host device. Next, the host device receives, from the client device via the trusted execution environment component, a decryption key for decrypting a first virtual image file of the target virtual machine; and runs, based on the decryption key, the first virtual image file to start the target virtual machine. Thereby, a user may implement a data processing system based on a trusted execution environment.


