Trusted Execution Environment for Secure Cryptocurrency Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptocurrency exchange systems are vulnerable to frontrunning attacks and other security threats, preventing fair exchanges and leading to potential theft or loss of assets, and they fail to provide real-time cross-trading between multiple independent cryptocurrency systems.

Innovation Solution

Implementing a real-time cryptocurrency exchange platform using trusted hardware, such as secure enclaves like Intel SGX, which ensures secure transactions by conditioning the release of blockchain transactions on confirmation thresholds and utilizing leader election protocols to prevent malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cryptocurrency exchange systems are used, then basic transaction functionality is provided, but the systems are vulnerable to frontrunning attacks and other security threats

Engineering Contradiction:
Improvesecurity against frontrunning attacksVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary component between the cryptocurrency exchange platform and the blockchain network. This TEE acts as a secure mediator that isolates critical operations from external attacks, preventing frontrunning by ensuring that transaction data remains confidential until execution. The TEE serves as a hardware-based trust anchor that mediates the exchange process without requiring complex multi-signature protocols or decentralized coordination mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If real-time cross-trading between multiple independent cryptocurrency systems is implemented, then trading speed and efficiency are improved, but vulnerability to attacks and theft increases

Engineering Contradiction:
Improvereal-time cross-trading capabilityVSAvoidexposure to attacks and theft
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a secure, isolated execution environment within the TEE that acts as an 'inert atmosphere' for cryptographic operations. This protected environment prevents malicious code, hardware attacks, and network interference from affecting the cross-trading operations. By confining sensitive operations within this inert TEE environment, the system achieves real-time cross-chain trading without exposing private keys or transaction data to external threats.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If trusted execution environment is used to secure transactions, then security against theft is improved, but hardware requirements and cost increase

Engineering Contradiction:
Improveprotection against theftVSAvoidtrusted hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the TEE-based exchange platform to serve multiple functions: it secures private keys, manages order books, executes cross-chain swaps, and provides audit logging all within a single hardware module. This multi-functional approach eliminates the need for separate hardware security modules, cold storage devices, and monitoring systems, making the TEE a universal security solution that protects against theft while maintaining operational simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11244309B2Real-time cryptocurrency exchange using trusted hardware
Publication Date: 2022.02.08 CORNELL UNIVERSITY
  • US11244309B2 patent drawing
  • US11244309B2 patent drawing
  • US11244309B2 patent drawing

AI summary

An apparatus in an illustrative embodiment comprises a processing platform that includes one or more processing devices each comprising a processor coupled to a memory. The processing platform is configured to communicate over at least one network with one or more additional sets of processing devices associated with at least a first blockchain-based cryptocurrency system. Each of at least a subset of the one or more processing devices of the processing platform comprises a trusted execution environment, such as a secure enclave. The processing platform is further configured to release from the trusted execution environment of a given one of the one or more processing devices of the processing platform a first blockchain transaction on the first blockchain-based cryptocurrency system, and to condition release of a second blockchain transaction relating to the first blockchain transaction on receipt of at least a specified threshold amount of evidence of confirmation of the first blockchain transaction on the first blockchain-based cryptocurrency system.