IP Library Granted Patent US 12682106
Granted Patent B2
US 12682106 · App. 18/477,053 · Granted Jul 14, 2026

Cloud service system and data processing method based on cloud service

Inventor: Chuan Ye (Hangzhou, CN)
Assignee: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.
G06F21/6245G06F9/45558G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682106
App. No.
18/477,053
Granted
Jul 14, 2026
Kind
B2
Abstract

A cloud service system includes a first server and a physical device. The first server and the physical device are coupled through a physical channel. The first server includes a cloud instance. The physical device includes a trusted execution environment corresponding to the cloud instance. The physical device is configured to perform confidential calculation on data from the cloud instance through the trusted execution environment, and send a calculation result to the cloud instance.

Claims (50)

1 . A system comprising:

a first server comprising:

a cloud instance, wherein the cloud instance comprises data; and

a first operating system; and

a physical device coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server, and wherein the physical device comprises a trusted execution environment corresponding to the cloud instance, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system, and wherein the physical device is configured to:

obtain, from the cloud instance, the data;

perform a confidential scheming on the data through the trusted execution environment to obtain a result;

send, to the cloud instance, the result; and

reject operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when the first operating system is compromised.

2 . The system of claim 1 , wherein the physical device further comprises a second operating system, and wherein the physical device is further configured to:

receive, from the first operating system through the second operating system, the data; and

send, to the first operating system through the second operating system, the result to enable the first operating system to send the result to the cloud instance.

3 . The system of claim 2 , wherein the physical device is further configured to:

obtain a key corresponding to the cloud instance through the second operating system; and

further perform, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.

4 . The system of claim 1 , wherein the physical device is the second server, a smart card, or an offload card.

5 . The system of claim 4 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.

6 . The system of claim 4 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).

7 . The system of claim 1 , wherein the cloud instance is a first virtual machine, a first container, or a first bare metal server, and wherein the trusted execution environment is a second virtual machine, a second container, or a second bare metal server.

8 . A method implemented by a physical device, wherein the method comprises:

obtaining, from a cloud instance of a first server, data, wherein the physical device is coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server, and wherein the physical device comprises a trusted execution environment corresponding to the cloud instance, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system;

performing, through the trusted execution environment, a confidential scheming on the data to obtain a result;

sending, to the cloud instance, the result; and

rejecting operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when a first operating system of the first server is compromised.

9 . The method of claim 8 , further comprising:

receiving, through a second operating system of the physical device and from the first operating system of the first server, the data; and

sending, to the first operating system, and through the second operating system, the result to enable the first operating system to send the result to the cloud instance.

10 . The method of claim 9 , further comprising:

obtaining, through the second operating system, a key corresponding to the cloud instance; and

further performing, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.

11 . The method of claim 8 , wherein the physical device is the second server, a smart card, or an offload card.

12 . The method of claim 11 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.

13 . The method of claim 11 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).

14 . The method of claim 8 , wherein the cloud instance is a first virtual machine, a first container, or a first bare metal server, and wherein the trusted execution environment is a second virtual machine, a second container, or a second bare metal server.

15 . A physical device comprising:

a memory configured to store instructions and a trusted execution environment; and

one or more processors coupled to the memory and configured to execute the instructions to cause the physical device to:

obtain, from a cloud instance of a first server, data, wherein the physical device is coupled to the first server through a physical channel disposed between the physical device and the server, wherein the physical channel is a high-speed communication backplane, a high-speed computer extended bus, or a physical network when the physical device is a second server;

perform a confidential scheming on the data through the trusted execution environment to obtain a result;

send, to the cloud instance, the result; and

reject operations other than operations related to a confidential request, wherein the trusted execution environment rejects a sensitive data obtaining request when a first operating system of the first server is compromised, wherein the trusted execution environment maintains sensitive data of a user corresponding to the cloud instance and is isolated by the physical channel from the first operating system.

16 . The physical device of claim 15 , wherein the memory further comprises a second operating system, and wherein the one or more processors are further configured to execute the instructions to cause the physical device to:

receive, from the first operating system through the second operating system, the data; and

send, to the first operating system through the second operating system, the result to enable the first operating system to send the result to the cloud instance.

17 . The physical device of claim 16 , wherein the one or more processors are further configured to execute the instructions to cause the physical device to:

obtain a key corresponding to the cloud instance through the second operating system; and

further perform, based on the key, the confidential scheming on the data through the trusted execution environment to obtain the result.

18 . The physical device of claim 15 , wherein the physical device is the second server, a smart card, or an offload card.

19 . The physical device of claim 18 , wherein the physical channel is a high-speed computer extended bus when the physical device is the smart card or the offload card.

20 . The physical device of claim 18 , wherein the physical device is an offload card, and wherein the offload card comprises a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).