IL277974A

System and method for secure electronic transaction platform

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS 1. A computer implemented system for a trusted execution environment maintaining an isolated data processing subsystem, the system comprising:a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to both an operating system and kernel system, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the isolated data processing subsystem;a computer readable cache memory;and a secure enclave data processor configured to provide: a partner data receiver configured to separately receive one or more data sets from a plurality of corresponding partner computing devices, each of the one or more data sets digitally signed by a private key corresponding to each of the partner computing devices, the partner data receiver configured to validate the digital signature of the partner computing device;the partner data receiver configured to: (i) load a portion of the protected memory region into the computer readable cache memory, (ii) record the one or more validated data sets into the loaded portion of the data storage region in the protected memory region, and to (iii) unload and encrypt the portion of the protected memory region subsequent to the recordal;and a data processing subsystem interaction engine configured transmit a query data message to the data processing subsystem and to receive an output data structure generated by the data processing subsystem generated based on the one or more data sets stored in the protected memory region.
  2. 11
    A computer implemented method for a trusted execution environment maintaining an isolated data processing subsystem, the method operating on a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to an operating system and kernel system of a computing device implementing the trusted execution environment, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the isolated data processing subsystem, the method comprising:receiving one or more data sets from one or more corresponding partner computing devices, each of the one or more data sets digitally signed by a private key corresponding to each of the partner computing devices;validating the digital signature of the partner computing device;loading a portion of the protected memory region into a computer readable cache memory;recording the one or more validated data sets into the loaded portion of the data storage region in the protected memory region;unloading and encrypting the portion of the protected memory region subsequent to the recordal;transmitting a query data message to the data processing subsystem;processing the query data message based on a processing function that receives as an input the one or more data sets from the one or more corresponding partner computing devices or an aggregate thereof to generate an output data structure.
  3. 20
    A non-transitory computer readable medium, storing machine interpretable instructions which when executed by a processor, cause the processor to perform a computer implemented method for a trusted execution environment maintaining an isolated data processing subsystem, the method operating on a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to an operating system and kernel system of a computing device implementing the trusted execution environment, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the isolated data processing subsystem, the method comprising:receiving one or more data sets from one or more corresponding partner computing devices, each of the one or more data sets digitally signed by a private key corresponding to each of the partner computing devices;validating the digital signature of the partner computing device;loading a portion of the protected memory region into a computer readable cache memory;recording the one or more validated data sets into the loaded portion of the data storage region in the protected memory region;unloading and encrypting the portion of the protected memory region subsequent to the recordal;transmitting a query data message to the data processing subsystem;processing the query data message based on a processing function that receives as an input the one or more data sets from the one or more corresponding partner computing devices or an aggregate thereof to generate an output data structure.