Trusted Execution Environment for Secure Mutual Device Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic techniques for secure data exchange between computing devices often rely on trusted third parties or complex communication protocols, which can introduce security vulnerabilities and complexity, especially when direct connections are absent.
Innovation Solution
Implementing a Trusted Execution Environment (TEE) in a data exchange device that uses hardware-based encryption to isolate and protect data, allowing secure transfer of protected content without exposing it to the operating system or malicious processes, and enabling secure key distribution and retrieval without the need for a mutually trusted third party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cryptographic techniques with trusted third parties are used, then data security is maintained, but system complexity and vulnerability increase
Solution Approach 1:
The patent extracts the trust function from a separate trusted third party and embeds it directly into the data exchange device through a Trusted Execution Environment. This eliminates the need for external trust authorities while maintaining security, reducing system complexity by removing intermediary components.
Solution Approach 2:
The Trusted Execution Environment acts as a secure intermediary within the data exchange device, providing isolated execution space for cryptographic operations. This mediator protects sensitive data without requiring mutual trust between communicating devices, simplifying the overall system architecture.
2Productivity
If direct connections between devices are established, then communication efficiency improves, but security vulnerabilities increase when connections are absent
Solution Approach 1:
The data exchange device performs self-verification through the Trusted Execution Environment, autonomously establishing trust with communicating devices without external intervention. This self-service approach enables secure communication efficiency improvements by eliminating the need for pre-established trusted connections.
Solution Approach 2:
The system changes the trust parameter from requiring pre-established trusted connections to using cryptographic verification within the TEE. This parameter change allows devices to securely communicate without direct trusted connections, maintaining efficiency while reducing vulnerabilities.
3Ease of operation
If sensitive data is exposed to operating system processes, then data accessibility improves, but security protection decreases
Solution Approach 1:
The patent segments the execution environment into a Trusted Execution Environment for sensitive cryptographic operations and a regular operating system environment for general tasks. This segmentation allows data to be accessible where needed while maintaining strong protection within the isolated TEE boundary.
Solution Approach 2:
The Trusted Execution Environment is nested within the operating system, providing a secure container for sensitive operations. This nested structure enables data accessibility to the OS while maintaining isolation and protection, allowing the OS to access data through controlled interfaces without exposing it to malicious processes.
Data Source
AI summary
The technology disclosed herein enables a computing device to use a trusted execution environment to retrieve protected content from mutually-untrusted devices. An example method may include: establishing, by a processor, a trusted execution environment in a computing device, wherein the trusted execution environment uses memory encryption and comprises executable code; providing, by the processor, attestation data to a set of computing devices, the attestation data representing the executable code in the trusted execution environment; receiving, by the processor, cryptographic key data from the set of computing devices; and causing, by the processor, the executable code to execute in the trusted execution environment and to initiate an operation using the cryptographic key data.


