IP Library Granted Patent US 12,596,806
Granted Patent B2
US 12,596,806 · App. 17/615,034 · Granted Apr 7, 2026

Methods, systems, and devices for trusted execution environments and secure data processing and storage environments

Inventor: Sean Peisert (San Rafael, CA)
Assignee: The Regents of the University of California
G06F21/57G06F21/31G06F21/602G06F21/604G06F21/78G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,806
App. No.
17/615,034
Granted
Apr 7, 2026
Kind
B2
Abstract

Disclosed herein are methods, systems, and devices for implementing trusted execution environments in the context of data security and data storage. Systems may include a login node comprising one or more processors configured to receive a request from a user, and a secure access port communicatively coupled to the login node and configured to process the request in accordance with one or more data access policies. Systems may further include a secure processing device communicatively coupled to the secure access port and comprising an encrypted portion configured to implement one or more data processing operations associated with the request. The systems may also include an encrypted data repository communicatively coupled to the secure processing device, the encrypted data repository comprising one or more storage devices, and being configured to encrypt and store data in the one or more storage devices.

Claims (36)

1 . A system comprising:

a login node comprising one or more processors configured to receive, from a user separate from the login node, a request associated with target data;

a secure access port, communicatively coupled to the login node, configured to process the request in accordance with one or more data access policies by identifying one or more data processing operations from a set of data processing operations based on both a time associated with the request and a pattern associated with different requests submitted prior to the request, wherein the secure access port comprises a container execution environment in which the one or more data access policies are applied to the request;

a secure processing hardware communicatively coupled to the secure access port to receive the request provided by the login node and comprising an encrypted portion configured to implement the one or more data processing operations and directly provide a response to the user without communicating through the login node that provided the request to the secure processing hardware, wherein the encrypted portion comprises a trusted execution environment configured to apply, to the response, one or more output policies configured to permit output of statistical results derived from the target data after randomized noise from within a bounded range is added to the statistical results to obfuscate the target data and wherein the one or more data processing operations are executed within the trusted execution environment, wherein the secure processing hardware corresponds to one or more central processing units (CPUs); and

an encrypted data repository communicatively coupled to the secure processing hardware, the encrypted data repository comprising one or more storage devices, and being configured to encrypt and store data in the one or more storage devices, and wherein the trusted execution environment brokers access to the one or more storage devices.

2 . The system of claim 1 , wherein the container execution environment is configured to implement a sandbox layer.

3 . The system of claim 2 , wherein the container execution environment is configured to implement a virtual environment.

4 . The system of claim 1 , wherein the secure processing hardware is configured to implement hardware encryption.

5 . The system of claim 4 , wherein the hardware encryption of the secure processing hardware is implemented via a secure portion of a main processor.

6 . The system of claim 1 , wherein the secure processing hardware is configured to implement software encryption.

7 . The system of claim 1 further comprising:

an additional secure access port communicatively coupled to the login node and configured to process the response to the request in accordance with one or more data access policies.

8 . The system of claim 1 , wherein the login node is one of a plurality of nodes in cluster of nodes.

9 . A method comprising:

receiving, at a secure access port of a secure environment from a user via a login node, a request associated with target data;

processing the request in accordance with one or more data access policies to provide a response by identifying one or more data processing operations from a set of data processing operations based on both a time associated with the request and a pattern associated with different requests submitted prior to the request;

determining, using a secure processing hardware of the secure environment, if the one or more data processing operations should be implemented based on the received request, wherein the secure access port comprises a container execution environment in which the one or more data access policies are applied to the request to determine if the processing operations should be implemented, and wherein the processing device comprises a trusted execution environment and in which the one or more data processing operations implemented, wherein the secure processing hardware corresponds to one or more central processing units (CPUs), wherein the trusted execution environment configured to apply, to the response, one or more output policies configured to permit output of statistical results derived from the target data after randomized noise from within a bounded range is added to the statistical results to obfuscate the target data; and

initiating, by the trusted execution environment, communication with an encrypted data repository responsive to the determining, the encrypted data repository being communicatively coupled to the secure environment.

10 . The method of claim 9 , wherein the authenticating further comprises:

authenticating a key included in the request.

11 . The method of claim 9 , wherein the determining further comprises:

identifying the one or more data access policy based, at least in part, on the received request.

12 . The method of claim 11 further comprising:

instantiating the container execution environment based, at least in part, on the identified one or more data access policies.

13 . The method of claim 12 , wherein the instantiating of the container execution environment further comprises:

implementing a sandbox layer.

14 . The method of claim 9 , wherein the request is a data access request.

15 . A device comprising:

a secure access port communicatively coupled to a login node and configured to receive, from a user separate from the login node, a request associated with target data, the secure access port comprising a container execution environment configured to process the request in accordance with one or more data access policies by identifying one or more data processing operations from a set of data processing operations based on both a time associated with the request and a pattern associated with different requests submitted prior to the request; and

a secure processing hardware communicatively coupled to the secure access port and comprising an encrypted portion configured to implement the one or more data processing operations and directly provide a response to the user without communicating through the login node, the secure processing hardware being communicatively coupled to an encrypted data repository, wherein the encrypted portion of the secure processing hardware comprises a trusted execution environment and wherein the one or more data processing operations are executed within the trusted execution environment configured to apply, to the response, one or more output policies configured to permit output of statistical results derived from the target data after randomized noise from within a bounded range is added to the statistical results to obfuscate the target data, and wherein the trusted execution environment brokers access to the encrypted data repository, wherein the secure processing hardware corresponds to one or more central processing units (CPUs).

16 . The device of claim 15 , wherein the container execution environment is configured to implement a sandbox layer.

17 . The device of claim 16 , wherein the container execution environment is configured to implement a virtual environment.

18 . The device of claim 15 , wherein the secure processing hardware is configured to implement hardware encryption.

19 . The device of claim 18 , wherein the secure processing hardware comprises a main processor, and wherein the main processor comprises a secure portion encrypted at a hardware level.

20 . The device of claim 15 , wherein the device further comprises:

an additional secure access port communicatively coupled to the login node and configured to process the response to the request in accordance with one or more data access policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2022
From: PEISERT, SEAN
To: THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
Reel/Frame 058972/0023 →
Continuity (2)
Provisional Application 62854259 · May 29, 2019
Related Publication 20220229908A1 · Jul 21, 2022
References Cited (26)
US 10700865B1 · Hendrick · 2020 [cited by examiner]
US 10853350B1 · Sharifi Mehr · 2020 [cited by examiner]
US 20100199104A1 · Rijnswou · 2010 [cited by applicant]
US 20110167477A1 · Piccirillo · 2011 [cited by examiner]
US 20140164791A1 · Chaturvedi et al. · 2014 [cited by applicant]
US 20140317420A1 · Daniels · 2014 [cited by examiner]
US 20150270956A1 · Basmov · 2015 [cited by examiner]
US 20150317490A1 · Carey · 2015 [cited by examiner]
US 20160117506A1 · Buer · 2016 [cited by examiner]
US 20170097881A1 · Hodel · 2017 [cited by examiner]
US 20190197246A1 · Viswanathan · 2019 [cited by examiner]
US 20190362083A1 · Ortiz · 2019 [cited by examiner]
WO 2020343362A1 · 2020 [cited by applicant]
Dwork, Cynthia. Differential Privacy. In Proceedings of the 33rd International Colloquium on Automata, Languages and Programming, Part II (ICALP), vol. 4052 of Lecture Notes in Computer Science, pp. 1-12. Springer Verla… [cited by applicant]
Globalplatform, Inc. Introduction to Trusted Execution Environments. https://globalplatform.org/wp-content/uploads/2018/05/Introduction-to-Trusted-Execution-Environment-15May2018.pdf, May 2018. [cited by applicant]
International Application Serial No. PCT/US20/34994, Preliminary Report on Patenability mailed Dec. 9, 2021, 8 pgs. [cited by applicant]
Mohamed Sabt, Mohammed Achernial, and Abdelmadjid Bouabdallah. Trusted Execution Environment: What It Is, and What It Is Not. In 14th IEEE International Conference on Trust, Security and Privacy in Computing and Communi… [cited by applicant]
Peisert, Sean. “Leveraging Trust Execution Environments for Secure, Privacy-Preserving Data Processing”, Lawrence Berkeley National Laboratory & University of California, Davis, Jan. 13, 2019. 10 pages. [cited by applicant]
Peisert, Sean. “Usable Computer Security and Privacy to Enable and Encourage Data Sharing for Scientific Research”, Lawrence Berkeley National Laboratory and University of California, Davis. National Academies of Scienc… [cited by applicant]
Int'l Application No. PCT/US20/34994, International Search Report and Written Opinion mailed Aug. 12, 2020. [cited by applicant]
Akram et al., “Enabling DesignSpaceExplorationforRISC-VSecureCompute Environments”, Proceedings of the Fifth Workshop on Computer Architecture Research with RISC-V (CARRV), (co-located with ISCA 2021) Jun. 17, 2021. [cited by applicant]
Peisert, “Trustworthy Scientific Computing,” Communications of the ACM (CACM), vol. 64, No. 5, pp. 18-21, (May 2021). [cited by applicant]
Akram et al., “Performance Analysis of Scientific Computing Workloads on General Purpose TEEs,” Proceedings of the 35th IEEE International Parallel & Distributed Processing Symposium (May 17-21, 2021). [cited by applicant]
Akram, “Trusted Execution for High-Performance Computing,” Proceedings of the 15th EuroSys Doctoral Workshop (EuroDW), 2021. [cited by applicant]
Akram, “Architectures for Secure High-Performance Computing,” Proceedings of the Young Architect Workshop (YArch) held in conjunction with the International Conference on Architectural Support for Programming Languages … [cited by applicant]
Akram et al., “Performance Analysis of Scientific Computing Workloads on Trusted Execution Environments,” arXiv preprint arXiv:2010.13216, Oct. 25, 2020. [cited by applicant]