Trusted Execution Broker for Policy-Based TEE Workload Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted execution technologies face challenges in scaling to large numbers of users, workloads, and computing environments, managing heterogeneous user requirements, and navigating jurisdictional legal complexities, while requiring manual intervention.

Innovation Solution

A trusted execution broker allocates workload payloads to multiple trusted execution platforms based on policies, enabling dynamic and automated management across heterogeneous environments and legal jurisdictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trusted execution technologies are implemented in secure datacenters, then security against threats is improved, but device complexity and management difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a broker as an intermediary component that manages trusted execution platforms. The broker handles workload allocation, platform selection, and coordination between clients and TEEs, thereby reducing management complexity while maintaining security. The broker abstracts the complex infrastructure details from end users and provides simplified interfaces for workload submission and result retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual intervention is used for trusted execution management, then control and security are improved, but productivity and scalability deteriorate

Engineering Contradiction:
ImprovecontrolVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automated self-service mechanisms where the broker automatically selects appropriate trusted execution platforms based on workload requirements, allocates resources, and manages execution without manual intervention. The platform selection and workload distribution are performed autonomously based on predefined policies and current system state, enabling scalability while maintaining controlled execution.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If static configuration options are used, then system stability is improved, but adaptability to heterogeneous requirements deteriorates

Engineering Contradiction:
Improvesystem stabilityVSAvoidadaptability to heterogeneous requirements
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system employs dynamic configuration where the broker can adapt platform selection and workload allocation based on changing requirements, available resources, and workload characteristics. The configuration is not fixed but can be adjusted in real-time to accommodate heterogeneous user requirements while maintaining system stability through controlled adaptation mechanisms and policy-based management.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If multiple trusted execution platforms are used, then adaptability and capacity are improved, but device complexity and coordination difficulty increase

Engineering Contradiction:
ImprovecapacityVSAvoidcoordination difficulty
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The broker is designed as a universal management component that can handle multiple types of trusted execution platforms through a unified interface. It provides multi-functional capabilities including workload submission, platform selection, execution monitoring, and result retrieval, thereby managing platform diversity without increasing coordination complexity for end users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12488109B2Trusted execution broker
Publication Date: 2025.12.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12488109B2 patent drawing
  • US12488109B2 patent drawing
  • US12488109B2 patent drawing

AI summary

Trusted execution of a workload payload is brokered among multiple trusted execution platforms. The workload payload is received from a source computing system and includes input data, trusted execution code, and one or more trusted execution policies. At least one of the multiple trusted execution platforms is selected based on the one or more trusted execution policies. A brokered payload is generated to include executable trusted execution code and the input data. The brokered payload is communicated to the selected at least one trusted execution platform. A brokered result generated from the brokered payload by the selected at least one trusted execution platform is received. A workload result based on the brokered result is returned to the source computing platform.