Auxiliary TEE for Confidential Storage Offloading
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern computing systems face inefficiencies in data security and resource utilization due to the limited extension of trusted computing bases to auxiliary devices, leading to increased computing resource consumption and underutilization of auxiliary devices.
Innovation Solution
Extending the trusted computing base to auxiliary devices by establishing an auxiliary Trusted Execution Environment (TEE) and a trusted communication link between primary and auxiliary TEEs, allowing auxiliary devices to process and persistently store data, thereby offloading tasks from primary devices and enhancing security and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the trusted computing base is limited to primary devices only, then security is maintained through simpler architecture, but auxiliary devices remain underutilized and primary devices consume excessive computing resources
Solution Approach 1:
The trusted computing base is segmented into multiple trusted execution environments (TEEs), with primary TEEs on host devices and auxiliary TEEs on auxiliary devices. This segmentation allows secure distribution of trust across device boundaries, enabling auxiliary devices to participate in confidential computing while maintaining security through isolated TEE boundaries.
Solution Approach 2:
The patent implements nested TEE architecture where auxiliary TEEs are embedded within the broader trusted computing base. The auxiliary TEEs operate as nested trusted zones that inherit security properties from the primary TEEs while maintaining independent secure execution capabilities, allowing deep integration of auxiliary devices into the trusted computing fabric.
2Adaptability or versatility
If auxiliary devices are excluded from the trusted computing base, then security architecture remains simple, but auxiliary devices are underutilized and deactivated
Solution Approach 1:
The trusted execution environment architecture is designed to be universal, supporting both primary devices (CPUs, GPUs) and auxiliary devices (storage controllers, network interface cards). This multi-functionality allows any device with TEE capability to participate in confidential computing operations, whether for processing, storage, or networking functions.
Solution Approach 2:
The patent introduces TEE I/O intermediaries that mediate communication between trusted execution environments and untrusted external devices. These intermediaries enable auxiliary devices to participate in the trusted computing base by providing secure I/O interfaces that maintain TEE isolation while enabling auxiliary device functionality.
3Productivity
If primary devices process all confidential data, then security is maintained through centralized control, but computing resource consumption increases and performance decreases
Solution Approach 1:
Data processing tasks are segmented and distributed across multiple TEEs located on different devices. Primary TEEs handle certain operations while auxiliary TEEs handle others, dividing the computational workload and enabling parallel processing of confidential data across the trusted computing base.
Solution Approach 2:
The patent extends the trusted computing base from a single-device model to a multi-device distributed architecture. This dimensional expansion allows confidential computing operations to be distributed across spatially separated devices, enabling parallel processing and reducing the computational burden on any single primary device.
4Reliability
If auxiliary devices are integrated into the trusted computing base, then resource utilization improves and security is enhanced, but the attack surface increases
Solution Approach 1:
The trusted computing base is segmented into isolated TEE boundaries that confine trust to specific device contexts. Each TEE operates as an independent security domain, limiting the attack surface to individual TEEs rather than exposing the entire system. Compromises in one TEE do not automatically compromise other TEEs.
Solution Approach 2:
TEE I/O intermediaries are introduced as security mediators between trusted execution environments and external devices. These intermediaries verify and control all communications crossing TEE boundaries, preventing unauthorized access and limiting the propagation of attacks. The intermediaries act as security gatekeepers that reduce the effective attack surface despite increased system integration.
Data Source
AI summary
The technology disclosed herein enables a Trusted Execution Environment (TEE) to be extended to an auxiliary device that handles persistently storing data in a security enhanced manner. Extending the trusted computing base to the auxiliary device may involve establishing an auxiliary TEE in the auxiliary device and a trusted communication link between the primary and auxiliary TEEs. The primary TEE may include the computing resources of the primary devices (e.g., CPU and host memory) and the auxiliary TEE may include the computing resources of the auxiliary devices (e.g., hardware accelerators and auxiliary memory). The trusted communication link may enable the auxiliary TEE to access data of the primary TEE that is otherwise inaccessible to all software executing external to the primary TEE (e.g., host operating system and hypervisor). The auxiliary device may use the auxiliary TEE to process the data to avoid compromising the security enhancements provided by the primary TEE.


