Trusted Execution Program for Secure Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data sharing platforms face challenges in ensuring data security and efficiency during data analysis, as existing technologies like Federated Learning and Zero-knowledge Proof require frequent communication between data users and contributors, compromising security and efficiency.

Innovation Solution

A data sharing method utilizing a trusted execution program that decrypts and analyzes encrypted data within a data sharing platform, ensuring only authorized users interact with the data, and the execution process remains invisible to users, thereby maintaining data security and improving analysis efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted and stored in a data sharing platform, then data security is improved, but data analysis efficiency deteriorates due to frequent communication requirements

Engineering Contradiction:
Improvedata securityVSAvoiddata analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a trusted execution environment as an intermediary component that mediates between encrypted data storage and analysis operations. This TEE acts as a secure enclave where decryption and analysis occur without exposing data to external parties, eliminating the need for frequent communication between data users and contributors while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the data analysis process into distinct components: data remains encrypted in storage, decryption occurs within the isolated TEE environment, and analysis results are extracted without exposing intermediate data states. This segmentation allows simultaneous achievement of security and efficiency.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If frequent communication occurs between data users and contributors for data analysis, then data analysis capability is improved, but data security deteriorates

Engineering Contradiction:
Improvedata analysis capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The trusted execution environment serves as a mediator that enables data analysis capability while preventing direct exposure of data. Users can perform complex analysis operations through the TEE interface without establishing direct communication channels with data contributors, thus maintaining security while preserving analytical versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements local quality by creating a specialized secure environment (TEE) with different security properties than the general system. Within this localized enclave, data can be decrypted and analyzed with full capability, while the surrounding system maintains strict encryption and access controls.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20230308290A1Data sharing method and electronic device
Publication Date: 2023.09.28 AGRI GENOMICS INST CHINESE ACADEMY OF AGRI SCI
  • US20230308290A1 patent drawing
  • US20230308290A1 patent drawing
  • US20230308290A1 patent drawing

AI summary

Disclosed is a data sharing method and an electronic device. The data sharing method includes: acquiring encrypted data to be analyzed, selected by a data user, in a data sharing platform; and decrypting, by using a trusted execution program, the encrypted data to be analyzed to obtain decrypted data, and performing, by using the trusted execution program, data analysis on the decrypted data, to obtain a data analysis result of the encrypted data to be analyzed, where the trusted execution program is provided with identity authentication information of the data user set in a built-in manner, and an execution process of the trusted execution program is invisible to the data user, which can ensure the security of shared data in a process of data sharing and improve the efficiency of data analysis.