IP Library › Granted Patent US 12,339,943
Granted Patent B2
US 12,339,943 · App. 17/635,897 · Granted Jun 24, 2025

Verifiability for execution in trusted execution environment

Inventors: Zheng Yan (Espoo, FI); Wei Sun (Xi'an, CN); Wenxiu Ding (Xi'an, CN)
Assignee: NOKIA TECHNOLOGIES OY
G06F21/33G06F21/53G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,339,943
App. No.
17/635,897
Granted
Jun 24, 2025
Kind
B2
Abstract

Example embodiments of the present disclosure relate to verifiability for execution in a trusted execution environment (TEE). According to a method, a request for execution of a task is transmitted by a first apparatus and to a second apparatus, the task comprising a plurality of functions to be executed. A first validation key is generated from identification information of the plurality of functions based on an expected execution plan in at least one trusted execution environment of the second apparatus. An execution result for the task and a second validation key are received from the second apparatus. Correctness of the execution result is determined by comparing the first validation key with the second validation key. Through the solution, it is possible to provide the verifiability of the correctness of the execution result returned by the remote apparatus and achieves high performance on security, trust, and privacy.

Claims (75)

1. A first apparatus, comprising:

at least one processor; and

at least one memory including computer program code;

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to:

transmit, to a second apparatus, a request for execution of a task, the task comprising a plurality of functions to be executed;

generate a first validation key from identification information of the plurality of functions based on an expected execution plan in at least one trusted execution environment of the second apparatus;

receive, from the second apparatus, an execution result for the task and a second validation key; and

determine correctness of the execution result by comparing the first validation key with the second validation key,

wherein the expected execution plan at least indicates an execution order of the plurality of functions, and wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the first validation key by:

generating intermediate keys for the plurality of functions in the execution order, an intermediate key for a function being determined at least based on an intermediate key for a predecessor function of the function in the execution order; and

determining the first validation key based on the generated intermediate key for a last function of the plurality of functions.

2. The apparatus of claim 1 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the intermediate keys by: for a given function of the plurality of functions,

determining a first number of predecessor functions for the given function and a second number of successor functions for the given function in the execution order;

generating validation information for the given function based on the first number; and

generating the intermediate key for the given function based on the second number and the validation information.

3. The apparatus of claim 2 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the validation information by:

in response to the first number indicating one predecessor function, generating the validation information by concatenating the intermediate key for the one predecessor function and the identification information of the given function.

4. The apparatus of claim 2 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the validation information by:

in response to the first number indicating a plurality of predecessor functions, generating the validation information for the given function by:

combining the intermediate keys for the plurality of predecessor functions to obtain a combined intermediate key, and

concatenating the combined intermediate key and the identification information of the given function.

5. The apparatus of claim 2 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the validation information by:

in response to the first number indicating zero predecessor function, generating the validation information by concatenating a random number and the identification information of the given function, the random number being also used for generation of the second validation key.

6. The apparatus of claim 5 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, further cause the first apparatus to:

generate the random number by applying a hash function to input data to be processed in the task.

7. The apparatus of claim 2 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the intermediate key based on the second number and the validation information by:

in response to the second number indicating zero successor function, generating the intermediate key for the given function by applying a hash function to the validation information.

8. The apparatus of claim 2 , wherein the expected execution plan further indicates distribution of the plurality of functions across the at least one trusted execution environment, and

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to generate the intermediate key for the given function based on the second number and the validation information by:

in response to the second number indicating at least one successor function, determining, based on the expected execution plan, whether the at least one successor function is executed in a different trusted execution environment than that of the given function;

in response to determining that the at least one successor function is executed in a different trusted execution environment than that of the given function, generating the intermediate key for the given function by applying a hash function to the validation information; and

in response to determining that the at least one successor function is executed in a same trusted execution environment as that of the given function, determining the validation information as the intermediate key for the given function.

9. The apparatus of claim 1 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the first apparatus to determine the correctness of the execution result by:

in response to the second validation key being the same as the first validation key, determining that the execution result is correct; and

in response to the second validation key being different from the first validation key, determining that the execution result is incorrect.

10. A second apparatus, comprising:

at least one processor; and

at least one memory including computer program code;

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to:

receive, from a first apparatus, a request for execution of a task, the task comprising a plurality of functions to be executed;

execute, based on an execution plan, the plurality of functions in at least one trusted execution environment to obtain an execution result for the task;

generate a second validation key from identification information of the plurality of functions based on the execution plan; and

transmit, to the first apparatus, the execution result and the second validation key for validating correctness of the execution result,

wherein the execution plan at least indicates an execution order of the plurality of functions, and wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the second validation key by:

generating intermediate keys for the plurality of functions in the execution order, an intermediate key for a function being determined at least based on an intermediate key for a predecessor function of the function in the execution order; and

determining the second validation key based on the generated intermediate key for a last function of the plurality of functions.

11. The apparatus of claim 10 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the intermediate keys for the plurality of functions by:

generating the intermediate keys for the plurality of functions within the at least one trusted execution environment.

12. The apparatus of claim 10 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the intermediate keys by: for a given function of the plurality of functions,

determining a first number of predecessor functions for the given function and a second number of successor functions for the given function in the execution order;

generating validation information for the given function based on the first number of predecessor functions; and

generating the intermediate key for the given function based on the second number and the validation information.

13. The apparatus of claim 12 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the validation information by:

in response to the first number indicating zero predecessor function, generating the validation information by concatenating a random number and the identification information of the given function, the random number being also used by the first apparatus for generation of a first validation key.

14. The apparatus of claim 13 , wherein the random number is generated by applying a hash function to input data to be processed in the task.

15. The apparatus of claim 13 , wherein the expected execution plan further indicates distribution of the plurality of functions across the at least one trusted execution environment, and

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the validation information by:

in response to the first number indicating at least one predecessor function for the given function, determining, based on the execution plan, whether the at least one predecessor function and the given function are executed in a same trusted execution environment as that of the given function; and

generating the validation information based on the first number and a result of the determining.

16. The apparatus of claim 15 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the validation information based on the first number and the result of the determining by:

in response to the first number indicating one predecessor function and in response to determining that the predecessor function and the given function are executed in the same trusted execution environment, generating the validation information by concatenating the intermediate key for the predecessor function and the identification information of the given function; and

in response to the first number indicating one predecessor function and in response to determining that the predecessor function and the given function are executed in different trusted execution environments, determining the validation information by:

applying a hash function to a result of execution of the predecessor function that is obtained in the trusted execution environment where the given function is executed, to obtain a hashed result,

converting the intermediate key for the predecessor function based on the hashed result, and

concatenating the converted intermediate key and the identification information of the given function.

17. The apparatus of claim 15 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the validation information based on the first number and the result of the determining by:

in response to the first number indicating a plurality of predecessor functions and in response to determining that the plurality of predecessor functions are executed in a same trusted execution environment as that of the given function, generating the validation information by the following:

combining the intermediate keys for the plurality of predecessor functions to obtain a combined intermediate key, and

concatenating the combined intermediate key and the identification information of the given function.

18. The apparatus of claim 15 , wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the second apparatus to generate the validation information based on the first number and the result of the determining by:

in response to the first number indicating a plurality of predecessor functions and in response to determining that the plurality of predecessor functions are executed in a different trusted execution environment than that of the given function, generating the validation information by:

for a given predecessor function of the plurality of predecessor functions, applying a hash function to a result of execution of the predecessor function that is obtained in the trusted execution environment where the given function is executed, to obtain a hashed result,

converting the intermediate key for the given predecessor function based on the hashed result, and

combining the converted intermediate keys for the plurality of predecessor functions to obtain a combined intermediate key, and

concatenating the combined intermediate key and the identification information of the given function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: YAN, ZHENG; SUN, WEI; WENXIU, DING
To: NOKIA TECHNOLOGIES OY
Reel/Frame 059869/0822 →
Continuity (1)
Related Publication 20220292174A1 · Sep 15, 2022
References Cited (61)
US 8285999B1 · Ghose · 2012 [cited by examiner]
US 20140082329A1 · Ghose · 2014 [cited by examiner]
US 20160248589A1 · Potlapally · 2016 [cited by examiner]
US 20180204005A1 · Gajek · 2018 [cited by examiner]
US 20200136797A1 · Yu · 2020 [cited by examiner]
US 20200201910A1 · Gavaudan · 2020 [cited by examiner]
US 20210328798A1 · Liu · 2021 [cited by examiner]
US 20210397676A1 · Fu · 2021 [cited by examiner]
CN 103795717A · 2014 [cited by applicant]
CN 107409118A · 2017 [cited by applicant]
CN 109150811A · 2019 [cited by applicant]
CN 109889498A · 2019 [cited by applicant]
EP 3499847A1 · 2019 [cited by applicant]
WO 2018078406A1 · 2018 [cited by applicant]
WO 2019016549A1 · 2019 [cited by applicant]
WO 2019120317A2 · 2019 [cited by applicant]
Yu et al., “A Survey of Verifiable Computation”, Mobile Networks and Applications, vol. 22, No. 3, May 6, 2017, 16 pages. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 19942311.2, dated Mar. 28, 2023, 5 pages. [cited by applicant]
Cafaro et al., “Space-efficient Verifiable Secret Sharing Using Polynomial Interpolation”, IEEE Transactions on Cloud Computing, vol. 6, No. 2, Apr.-Jun. 1, 2018, pp. 453-463. [cited by applicant]
Ma et al., “Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing”, IEEE Transactions on Dependable and Secure Computing, vol. 14, No. 6, Nov.-Dec. 1, 2017, 679-692. [cited by applicant]
Renjith et al., “Verifiable El-gamal re-encryption with authenticity in cloud”, Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 4-6, 2013, 5 pages. [cited by applicant]
Sun et al., “Verifiable Privacy-Preserving Multi-Keyword Text Search in the Cloud Supporting Similarity-Based Ranking”, IEEE Transactions on Parallel and Distributed Systems, vol. 25, No. 11, Nov. 2014, pp. 3025-3035. [cited by applicant]
Wang et al., “Verifiable Auditing for Outsourced Database in Cloud Computing”, IEEE Transactions on Computers, vol. 64, No. 11, Nov. 1, 2015, pp. 3293-3303. [cited by applicant]
Wen et al., “A Verifiable Data Deduplication Scheme in Cloud Computing”, International Conference on Intelligent Networking and Collaborative Systems, Sep. 10-12, 2014, pp. 85-88. [cited by applicant]
Xu et al., “Circuit Ciphertext-Policy Attribute-Based Hybrid Encryption with Verifiable Delegation in Cloud Computing”, IEEE Transactions on Parallel and Distributed Systems, vol. 27, No. 1, Jan. 1, 2016, pp. 119-129. [cited by applicant]
Yadav et al., “Secure data storage operations with verifiable outsourced decryption for mobile cloud computing”, International Conference on Recent Advances and Innovations in Engineering, May 9-11, 2014, 5 pages. [cited by applicant]
Guo et al., “Verifiable privacy-preserving monitoring for cloud-assisted mHealth systems”, IEEE Conference on Computer Communications (INFOCOM), Apr. 26-May 1, 2015, pp. 1026-1034. [cited by applicant]
Catalano et al., “Practical homomorphic macs for arithmetic circuits”, Annual International Conference on the Theory and Applications of Cryptographic Techniques, 2013, pp. 336-352. [cited by applicant]
Yan et al., “Context-aware verifiable cloud computing”, IEEE Access, vol. 5, Feb. 9, 2017, pp. 2211-2227. [cited by applicant]
Santos et al., “Toward Coercion-Resistant End-to-End Verifiable Electronic Voting Systems”, 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, Jul. 16-18, 2013, pp. 1696-1… [cited by applicant]
Park et al., “Themis: A Mutually Verifiable Billing System for the Cloud Computing Environment”, IEEE Transactions on Services Computing, vol. 6, No. 3, Jul.-Sep. 2013, pp. 300-313. [cited by applicant]
Liu et al., “Publicly Verifiable Inner Product Evaluation over Outsourced Data Streams under Multiple Keys”, IEEE Transactions on Services Computing, vol. 10, No. 5, Sep.-Oct. 1, 2017, pp. 826-838. [cited by applicant]
Li et al., “TMACS: A Robust and Verifiable Threshold Multi-Authority Access Control System in Public Cloud Storage”, IEEE Transactions on Parallel and Distributed Systems, vol. 27, No. 5, May 1, 2016, pp. 1484-1496. [cited by applicant]
Schiffman et al., “Cloud Verifier: Verifiable Auditing Service for laaS Clouds”, IEEE Ninth World Congress on Services, Jun. 28-Jul. 3, 2013, pp. 239-246. [cited by applicant]
Duarte et al., “Leveraging ARM TrustZone and Verifiable Computing to Provide Auditable Mobile Functions”, Proceedings of the 15th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and … [cited by applicant]
Backes et al., “Verifiable delegation of computation on outsourced data”, Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security, Nov. 2013, pp. 863-874. [cited by applicant]
Benabbas et al., “Verifiable delegation of computation over large datasets”, Advances in Cryptology, 2011, 20 pages. [cited by applicant]
Chung et al., “Improved delegation of computation using fully homomorphic encryption”, Annual Cryptology Conference, 2010, pp. 483-501. [cited by applicant]
Fiore et al., “Publicly verifiable delegation of large polynomials and matrix computations, with applications”, Proceedings of the 2012 ACM conference on Computer and communications security, Oct. 2012, pp. 501-512. [cited by applicant]
Hohenberger et al., “How to securely outsource cryptographic computations”, Theory of Cryptography Conference, 2005, pp. 264-282. [cited by applicant]
Lai et al., “Verifiable computation on outsourced encrypted data”, European Symposium on Research in Computer Security, 2014, pp. 273-291. [cited by applicant]
Parno et al., “How to delegate and verify in public: Verifiable computation from attribute-based encryption”, Theory of Cryptography Conference, 2012, pp. 422-439. [cited by applicant]
Dijk et al., “Speeding up Exponentiation using an Untrusted Computational Resource”, Designs, Codes and Cryptography, 2006, vol. 39, pp. 253-273. [cited by applicant]
Gennaro et al., “Fully homomorphic message authenticators”, International Conference on the Theory and Application of Cryptology and Information Security, 2013, pp. 301-320. [cited by applicant]
Boneh et al., “Homomorphic signatures for polynomial functions”, Advances in Cryptology, 2011, pp. 149-168. [cited by applicant]
Thaler, “Practical verified computation with streaming interactive proofs”, Dissertation, May 2013, 288 pages. [cited by applicant]
Kate et al., “Constant-size commitments to polynomials and their applications”, International Conference on the Theory and Application of Cryptology and Information Security, 2010, pp. 177-194. [cited by applicant]
Setty et al., “Making argument systems for outsourced computation practical (sometimes)”, Network & Distributed System Security Symposium (NDSS), Feb. 2012, 20 pages. [cited by applicant]
Setty et al., “Taking proof-based verified computation a few steps closer to practicality”, 21st USENIX Security Symposium, 2012, pp. 1-16. [cited by applicant]
Sasson et al., “SNARKs for C: Verifying Program Executions Succinctly and in Zero Knowledge”, Advances in Cryptology, 2013, pp. 90-108. [cited by applicant]
Anati et al., “Innovative Technology for CPU Based Attestation and Sealing”, Proceedings of the 2nd international workshop on hardware and architectural support for security and privacy, vol. 13, No. 7, 2013, pp. 1-7. [cited by applicant]
Schuster et al., “VC3: Trustworthy Data Analytics in the Cloud Using SGX”, IEEE Symposium on Security and Privacy, May 17-21, 2015, pp. 38-54. [cited by applicant]
Dean et al., “Mapreduce: Simplified data processing on large clusters”, Communications of the ACM, vol. 51, No. 1 Jan. 2008, pp. 107-113. [cited by applicant]
Low, “Hardware Security: Intel SGX and VC3”, EECS Instructional & Electronics Support, Sep. 2018, pp. 1-8. [cited by applicant]
Subramanyan et al., “A Formal Foundation for Secure Remote Execution of Enclaves”, Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017, pp. 1-16. [cited by applicant]
“Intro to SGX: From HTTP to Enclaves”, Medium, Retrieved on Feb. 25, 2022, Webpage available at : https://medium.com/corda/intro-to-sgx-from-http-to-enclaves-1bf38a3bf595. [cited by applicant]
Tang et al., “Authenticated Key-value Stores with Hardware Enclaves”, arXiv, Apr. 26, 2019, 16 pages. [cited by applicant]
Alder et al., “Migrating SGX Enclaves with Persistent State”, arXiv, Mar. 29, 2018, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for corresponding Patent Cooperation Treaty Application No. PCT/CN2019/101427, dated Apr. 24, 2020, 9 pages. [cited by applicant]
Notice of Allowance received for corresponding European Patent Application No. 19942311.2, dated Oct. 16, 2023, 8 pages. [cited by applicant]
Office action received for corresponding Chinese Patent Application No. 201980099545.3, dated Apr. 22, 2023, 6 pages of office action and no page of Translation available. [cited by applicant]