Auxiliary TEE for Confidential Storage Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing systems face inefficiencies in data security and resource utilization due to the limited extension of trusted computing bases to auxiliary devices, leading to increased computing resource consumption and underutilization of auxiliary devices.

Innovation Solution

Extending the trusted computing base to auxiliary devices by establishing an auxiliary Trusted Execution Environment (TEE) and a trusted communication link between primary and auxiliary TEEs, allowing auxiliary devices to process and persistently store data, thereby offloading tasks from primary devices and enhancing security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the trusted computing base is limited to primary devices only, then security is maintained through simpler architecture, but auxiliary devices remain underutilized and primary devices consume excessive computing resources

Engineering Contradiction:
Improveresource utilizationVSAvoidtrusted computing base extension
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The trusted computing base is segmented into multiple trusted execution environments (TEEs), with primary TEEs on host devices and auxiliary TEEs on auxiliary devices. This segmentation allows secure distribution of trust across device boundaries, enabling auxiliary devices to participate in confidential computing while maintaining security through isolated TEE boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested TEE architecture where auxiliary TEEs are embedded within the broader trusted computing base. The auxiliary TEEs operate as nested trusted zones that inherit security properties from the primary TEEs while maintaining independent secure execution capabilities, allowing deep integration of auxiliary devices into the trusted computing fabric.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Adaptability or versatility

If auxiliary devices are excluded from the trusted computing base, then security architecture remains simple, but auxiliary devices are underutilized and deactivated

Engineering Contradiction:
Improveauxiliary device utilizationVSAvoidtrusted computing base architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The trusted execution environment architecture is designed to be universal, supporting both primary devices (CPUs, GPUs) and auxiliary devices (storage controllers, network interface cards). This multi-functionality allows any device with TEE capability to participate in confidential computing operations, whether for processing, storage, or networking functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces TEE I/O intermediaries that mediate communication between trusted execution environments and untrusted external devices. These intermediaries enable auxiliary devices to participate in the trusted computing base by providing secure I/O interfaces that maintain TEE isolation while enabling auxiliary device functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If primary devices process all confidential data, then security is maintained through centralized control, but computing resource consumption increases and performance decreases

Engineering Contradiction:
Improvedata processing performanceVSAvoidcomputing resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

Data processing tasks are segmented and distributed across multiple TEEs located on different devices. Primary TEEs handle certain operations while auxiliary TEEs handle others, dividing the computational workload and enabling parallel processing of confidential data across the trusted computing base.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends the trusted computing base from a single-device model to a multi-device distributed architecture. This dimensional expansion allows confidential computing operations to be distributed across spatially separated devices, enabling parallel processing and reducing the computational burden on any single primary device.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If auxiliary devices are integrated into the trusted computing base, then resource utilization improves and security is enhanced, but the attack surface increases

Engineering Contradiction:
Improveconfidentiality and integrityVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The trusted computing base is segmented into isolated TEE boundaries that confine trust to specific device contexts. Each TEE operates as an independent security domain, limiting the attack surface to individual TEEs rather than exposing the entire system. Compromises in one TEE do not automatically compromise other TEEs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

TEE I/O intermediaries are introduced as security mediators between trusted execution environments and external devices. These intermediaries verify and control all communications crossing TEE boundaries, preventing unauthorized access and limiting the propagation of attacks. The intermediaries act as security gatekeepers that reduce the effective attack surface despite increased system integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230273808A1Confidential offloading of persistent storage operations in confidential computing environments
Publication Date: 2023.08.31 MELLANOX TECHNOLOGIES LTD(IL)
  • US20230273808A1 patent drawing
  • US20230273808A1 patent drawing
  • US20230273808A1 patent drawing

AI summary

The technology disclosed herein enables a Trusted Execution Environment (TEE) to be extended to an auxiliary device that handles persistently storing data in a security enhanced manner. Extending the trusted computing base to the auxiliary device may involve establishing an auxiliary TEE in the auxiliary device and a trusted communication link between the primary and auxiliary TEEs. The primary TEE may include the computing resources of the primary devices (e.g., CPU and host memory) and the auxiliary TEE may include the computing resources of the auxiliary devices (e.g., hardware accelerators and auxiliary memory). The trusted communication link may enable the auxiliary TEE to access data of the primary TEE that is otherwise inaccessible to all software executing external to the primary TEE (e.g., host operating system and hypervisor). The auxiliary device may use the auxiliary TEE to process the data to avoid compromising the security enhancements provided by the primary TEE.