Trusted Message Module for Secure Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic messaging technologies, such as email, are insecure due to ease of interception and modification, and existing security solutions are often centralized and manual, making them slow to adopt and potentially invasive to user privacy.

Innovation Solution

A system for virally distributable trusted messaging that uses local and remote computing devices to securely transmit messages through a trusted message module, leveraging cryptographic techniques and trusted execution environments to establish secure communication channels without relying on third-party infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized security infrastructure (such as PKI) is used to secure electronic messaging, then message security and integrity are improved, but system complexity and adoption difficulty increase

Engineering Contradiction:
Improvemessage securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security functionality from centralized third-party infrastructure and embeds it directly into the messaging application through trusted execution environments. The TEE module within the messaging app provides cryptographic operations and security functions locally, eliminating the need for external PKI infrastructure while maintaining message security and integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The messaging application performs its own security operations independently within the trusted execution environment. The TEE module generates cryptographic keys, signs messages, and verifies signatures autonomously without requiring external security infrastructure. This self-service approach simplifies deployment while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual security management approaches are used, then security control is improved, but productivity and adoption speed deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidadoption speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically performs security operations including key generation, message signing, and verification without user intervention. The TEE module handles cryptographic operations autonomously, and the system automatically manages security credentials, enabling rapid adoption while maintaining strong security control through automated processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials and trusted execution environments are pre-configured within the messaging application before use. The TEE module is already present and configured in the application, allowing immediate secure messaging operations without manual setup or configuration steps, thereby accelerating adoption while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If third-party security infrastructure is deployed, then message integrity is improved, but loss of privacy and user autonomy worsen

Engineering Contradiction:
Improvemessage integrityVSAvoidprivacy loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent removes the need for third-party security infrastructure by embedding trusted execution environments directly within the messaging application. All security operations occur locally within the user's device TEE, eliminating the need to share private keys or message content with external authorities, thus preserving privacy while maintaining message integrity through local cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The messaging application independently performs all security functions including signing and verification within the local TEE without involving third parties. Users maintain full control of their private keys and security credentials locally, with no privacy loss to external entities, while message integrity is ensured through cryptographic signatures verified by the recipient's own TEE module.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3186918B1Virally distributable trusted messaging
Publication Date: 2020.07.22 INTEL CORP
  • EP3186918B1 patent drawingFigure 1
  • EP3186918B1 patent drawingFigure 2
  • EP3186918B1 patent drawingFigure 3

AI summary

Technologies for utilizing trusted messaging include a local computing device including a message client and a local trusted message module established in a trusted execution environment. The local trusted message module performs attestation of a remote computing device based on communication with a corresponding remote trusted message module established in a trusted execution environment of the remote computing device. The local trusted message module further exchanges, with the remote trusted message module, cryptographic keys in response to successful attestation of the remote computing device. The message client forwards outgoing messages to the local trusted message module and receives incoming messages from the local trusted message module. To securely transmit an outgoing message to the remote computing device, the local trusted message module receives the outgoing message from the message client, encrypts the outgoing message, and cryptographically signs the outgoing message, prior to transmittal to the remote trusted message module of the remote computing device. To securely receive an incoming message from the remote computing device, the local trusted message module receives the incoming message from the remote trusted message module of the remote computing device, decrypts the incoming message, and verifies a cryptographic signature of the incoming message, based on the exchanged cryptographic keys and prior to transmittal of the incoming message to the message client.