Trusted Execution Environment for Secure Mutual Device Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic techniques for secure data exchange between computing devices often rely on trusted third parties or complex communication protocols, which can introduce security vulnerabilities and complexity, especially when direct connections are absent.

Innovation Solution

Implementing a Trusted Execution Environment (TEE) in a data exchange device that uses hardware-based encryption to isolate and protect data, allowing secure transfer of protected content without exposing it to the operating system or malicious processes, and enabling secure key distribution and retrieval without the need for a mutually trusted third party.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic techniques with trusted third parties are used, then data security is maintained, but system complexity and vulnerability increase

Engineering Contradiction:
Improvedata securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trust function from a separate trusted third party and embeds it directly into the data exchange device through a Trusted Execution Environment. This eliminates the need for external trust authorities while maintaining security, reducing system complexity by removing intermediary components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The Trusted Execution Environment acts as a secure intermediary within the data exchange device, providing isolated execution space for cryptographic operations. This mediator protects sensitive data without requiring mutual trust between communicating devices, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct connections between devices are established, then communication efficiency improves, but security vulnerabilities increase when connections are absent

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The data exchange device performs self-verification through the Trusted Execution Environment, autonomously establishing trust with communicating devices without external intervention. This self-service approach enables secure communication efficiency improvements by eliminating the need for pre-established trusted connections.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the trust parameter from requiring pre-established trusted connections to using cryptographic verification within the TEE. This parameter change allows devices to securely communicate without direct trusted connections, maintaining efficiency while reducing vulnerabilities.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If sensitive data is exposed to operating system processes, then data accessibility improves, but security protection decreases

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the execution environment into a Trusted Execution Environment for sensitive cryptographic operations and a regular operating system environment for general tasks. This segmentation allows data to be accessible where needed while maintaining strong protection within the isolated TEE boundary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Trusted Execution Environment is nested within the operating system, providing a secure container for sensitive operations. This nested structure enables data accessibility to the OS while maintaining isolation and protection, allowing the OS to access data through controlled interfaces without exposing it to malicious processes.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11971980B2Using trusted execution environments to perform a communal operation for mutually-untrusted devices
Publication Date: 2024.04.30 RED HAT INC
  • US11971980B2 patent drawing
  • US11971980B2 patent drawing
  • US11971980B2 patent drawing

AI summary

The technology disclosed herein enables a computing device to use a trusted execution environment to retrieve protected content from mutually-untrusted devices. An example method may include: establishing, by a processor, a trusted execution environment in a computing device, wherein the trusted execution environment uses memory encryption and comprises executable code; providing, by the processor, attestation data to a set of computing devices, the attestation data representing the executable code in the trusted execution environment; receiving, by the processor, cryptographic key data from the set of computing devices; and causing, by the processor, the executable code to execute in the trusted execution environment and to initiate an operation using the cryptographic key data.