Trusted Grid Architecture for TEE Application Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The development of trusted applications based on trusted execution environments (TEE) is complex due to the need for high complexity in considering TEE characteristics and programming modes, requiring improved solutions for facilitating development, deployment, and interaction of upper-layer applications.

Innovation Solution

A trusted grid is constructed by deploying unified target code and metric values in multiple computing nodes, forming trusted nodes that verify and establish secure connections, utilizing trusted proxy logic for security services, and enabling simplified application development and deployment through a decentralized network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TEE-based trusted applications are developed with full consideration of TEE characteristics and programming modes, then security and reliability are improved, but development complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted grid as an intermediary layer between upper-layer applications and the TEE infrastructure. This grid provides standardized interfaces and automated verification mechanisms, allowing applications to benefit from TEE security without directly implementing complex TEE programming modes and characteristics

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the trusted computing functionality into modular components including trusted nodes, verification modules, and grid services. This segmentation allows security functions to be independently implemented and verified while simplifying the overall development process for applications

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple trusted nodes perform mutual verification based on target metric values, then security and reliability are improved, but verification time and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary verification where trusted nodes pre-validate each other's target metric values and establish trust relationships before actual computing tasks. This preliminary action reduces verification time during runtime while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent optimizes verification efficiency by changing parameters such as using hashed metric values for comparison, implementing incremental verification for repeated interactions, and adjusting verification depth based on trust levels between nodes

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12598184B2Methods for constructing trusted grid, trusted grids, and application interaction methods thereon
Publication Date: 2026.04.07 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • US12598184B2 patent drawing
  • US12598184B2 patent drawing
  • US12598184B2 patent drawing

AI summary

Trusted grid construction includes respectively loading, by a plurality of computing nodes, uniform target code in trusted execution environments (TEEs) of the plurality of computing nodes. A target metric value corresponding to the target code is stored to form a plurality of trusted nodes, where target logic corresponding to the uniform target code includes trusted proxy logic configured to provide a security related service for an upper-layer application. Each trusted node performs mutual verification with another trusted node based on the target metric value. A secure connection is established to the another trusted node after the mutual verification is passed, where a plurality of trusted nodes that establish secure connections to each other form a trusted grid.