IP Library › Granted Patent US 11,770,368
Granted Patent B2
US 11,770,368 · App. 17/677,584 · Granted Sep 26, 2023

Techniques for shared private data objects in a trusted execution environment

Inventors: Mic Bowman (Boise, ID); Andrea Miele (Hillsboro, OR); James P. Held (Portland, OR); Anand Rajan (Beaverton, OR)
Assignee: Intel Corporation
H04L63/0428G06F21/57G06F21/6218H04L9/0822H04L9/3234H04L9/3236H04L63/123H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,368
App. No.
17/677,584
Granted
Sep 26, 2023
Kind
B2
Abstract

Techniques for sharing private data objects in a trusted execution environment using a distributed ledger are described. The techniques described herein may enable sharing of data objects, referred to herein as private data objects (PDOs), between individuals and organizations with access and update policies mediated by execution of code (referred to herein as a “smart contract”) carried with the PDO in a secure enclave. A distributed ledger may serve as a “public commit log” to ensure that there is a single, authoritative instance of the object and provide a means of guaranteeing atomicity of updates across interacting objects.

Claims (37)

1. A computer-implemented method, comprising:

registering a contract identifier with a distributed ledger;

selecting one or more of a plurality of contract enclaves;

requesting a provisioning secret for the one or more of the plurality of contract enclaves; and

sending an information element comprising an indication of private data to at least one of the one or more of the plurality of contract enclaves.

2. The computer-implemented method of claim 1 , wherein, the at least one of the one or more of the plurality of contract enclaves, creates a private data object (PDO) responsive to receiving the information element and sends the PDO to the distributed ledger.

3. The computer-implemented method of claim 1 , the provisioning secret comprising at least an encryption public key for the one or more of the plurality of contract enclaves.

4. The computer-implemented method of claim 1 , comprising selecting the one or more of the plurality of contract enclaves based on at least one of the following: processor, memory, latency, security, or software.

5. The computer-implemented method of claim 1 , comprising registering a contract owner public key with the distributed ledger.

6. The computer-implemented method of claim 1 , comprising receiving, from a provisioning service, a keyshare encrypted with an encryption private key associated with a one of the one or more of the plurality of contract enclaves.

7. The computer-implemented method of claim 6 , comprising sending the encrypted keyshare to the one of the one or more of the plurality of contract enclaves.

8. An apparatus comprising:

processing circuitry; and

memory coupled to the processing circuitry, the memory comprising instructions that when executed by the processing circuitry, causes the processing circuitry to:

register a contract identifier with a distributed ledger;

select one or more of a plurality of contract enclaves;

request a provisioning secret for the one or more of the plurality of contract enclaves; and

send an information element comprising an indication of private data to at least one of the one or more of the plurality of contract enclaves.

9. The apparatus of claim 8 , wherein, the at least one of the one or more of the plurality of contract enclaves creates a private data object (PDO) responsive to receiving the information element and sends the PDO to the distributed ledger.

10. The apparatus of claim 8 , the provisioning secret comprising at least an encryption public key for the one or more of the plurality of contract enclaves.

11. The apparatus of claim 8 , the instructions, when executed by the processing circuitry, cause the processing circuitry to select the one or more of the plurality of contract enclaves based on at least one of the following:

processor, memory, latency, security, or software.

12. The apparatus of claim 8 , the instructions, when executed by the processing circuitry, cause the processing circuitry to register a contract owner public key with the distributed ledger.

13. The apparatus of claim 8 , the instructions, when executed by the processing circuitry, cause the processing circuitry to receive, from a provisioning service, a keyshare encrypted with an encryption private key associated with a one of the one or more of the plurality of contract enclaves.

14. The apparatus of claim 13 , the instructions, when executed by the processing circuitry, cause the processing circuitry to send the encrypted keyshare to the one of the one or more of the plurality of contract enclaves.

15. A memory device, comprising a non-transitory computer-readable storage medium that stores instructions for execution by processing circuitry of a contract owner device, the instructions to cause the contract owner device to:

register a contract identifier with a distributed ledger

select one or more of a plurality of contract enclaves;

request a provisioning secret for the one or more of the plurality of contract enclaves; and

send an information element comprising an indication of private data to at least one of the one or more of the plurality of contract enclaves.

16. The memory device of claim 15 , wherein, the at least one of the one or more of the plurality of contract enclaves creates a private data object (PDO) responsive to receiving the information element and sends the PDO to the distributed ledger.

17. The memory device of claim 15 , the provisioning secret comprising at least an encryption public key for the one or more of the plurality of contract enclaves.

18. The memory device of claim 15 , the instructions, when executed by the processing circuitry, cause the contract owner device to select the one or more of the plurality of contract enclaves based on at least one of the following:

processor, memory, latency, security, or software.

19. The memory device of claim 15 , the instructions, when executed by the processing circuitry, cause the contract owner device to register a contract owner public key with the distributed ledger.

20. The memory device of claim 15 , the instructions, when executed by the processing circuitry, cause the contract owner device to receive, from a provisioning service, a keyshare encrypted with an encryption private key associated with a one of the one or more of the plurality of contract enclaves.

21. The memory device of claim 20 , the instructions, when executed by the processing circuitry, cause the contract owner device to send the encrypted keyshare to the one of the one or more of the plurality of contract enclaves.

Continuity (4)
Continuation 16723564 · Dec 20, 2019
Continuation 15721723 · Sep 29, 2017
Provisional Application 62547734 · Aug 18, 2017
Related Publication 20220182365A1 · Jun 9, 2022
Cited By (1)
US 12,683,802