Trusted Execution Environment for Secure Cloud VM Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud adoption is hindered by security concerns due to the need to trust cloud providers with sensitive information, as existing cloud infrastructures assume the trustworthiness of cloud vendors and their staff, lacking secure execution environments that protect customer secrets.
Innovation Solution
The implementation of a trusted execution environment (TEE) within cloud infrastructure, utilizing hardware-based security features like TPMs and fine-grained or coarse-grained TEEs, allows customers to create and run secure computations without sharing secrets with the cloud provider, using protocols like BYOK or KYOK to manage keys and ensure secure boot processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud infrastructure assumes trust in cloud providers and their staff, then cloud service delivery is simplified and efficient, but security is compromised as customer secrets are vulnerable to adversarial access
Solution Approach 1:
The system segments the cloud infrastructure into trusted and untrusted zones by introducing hardware-based trusted execution environments (TEEs) and security modules. Customer secrets are isolated in secure enclaves within the cloud provider's infrastructure, separated from the untrusted cloud environment. This allows efficient cloud service delivery in untrusted zones while maintaining security through segmentation in trusted zones.
Solution Approach 2:
The patent introduces security modules and trusted execution environments as intermediary components between customer secrets and the cloud infrastructure. These intermediaries act as mediators that enable cloud service delivery without requiring direct trust between customers and cloud providers, as the intermediary hardware enforces security boundaries and controls access to secrets.
2Reliability
If hardware-based trusted execution environments are implemented, then security of customer secrets is improved, but device complexity increases
Solution Approach 1:
The trusted execution environments and security modules operate autonomously to enforce security policies and protect customer secrets. The hardware-based TEEs self-manage secret protection without requiring complex external security management systems, reducing operational complexity while maintaining high security standards.
Solution Approach 2:
The patent designs security modules and TEEs with multi-functional capabilities that can serve multiple security purposes within the cloud infrastructure. These universal security components handle key management, secret protection, and authentication functions, reducing the need for multiple specialized security devices and simplifying the overall system architecture.
Data Source
AI summary
A method, system and apparatus for provisioning a computation into a trusted execution environment, including verifying the trusted execution environment, generating integrity information of the computation, generating sealed data, sending information of the computation, the sealed data, and integrity information to the trusted execution environment, confirming the sealed data, and verifying integrity of the computation information from the integrity information and the computation information.


