Brownfield Security Gateway with Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing infrastructure and industrial systems are vulnerable to malicious attacks due to multiple points of access, and firewalls are susceptible to bugs that can allow attackers to bypass security measures, exposing critical systems to risks.
Innovation Solution
A brownfield security gateway is configured with a trusted execution environment (TEE) and a trusted peripheral device, utilizing communication transport protocols and cryptography to securely isolate and control access to connected devices, combining cryptographic and physical security features to form a trusted cyber physical system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are used to protect from malicious attacks, then security is improved, but firewalls are susceptible to bugs that may result in attackers being able to inject executable code and bypass security
Solution Approach 1:
The patent introduces a brownfield security gateway as an intermediary device positioned between the network and the controllable device. This gateway acts as a mediator that inspects, filters, and controls all communications, preventing malicious executable code from reaching the target device while allowing legitimate traffic to pass through. The gateway serves as a protective buffer that addresses the vulnerability of traditional firewalls to code injection attacks.
Solution Approach 2:
The patent segments the system into distinct functional components: the brownfield security gateway, the TEE environment, and the controllable device. By dividing the security architecture into separate layers with specific responsibilities, the system isolates the critical controllable device from direct network exposure while maintaining controlled access through the gateway, thereby preventing bypass attacks.
2Ease of operation
If multiple points of access are provided for controller devices, then ease of operation is improved, but vulnerabilities to malicious attacks increase
Solution Approach 1:
The patent applies different security qualities to different access points and communication paths. The brownfield security gateway implements localized security policies that inspect and control traffic based on its source, destination, and content. This allows multiple access points to remain available for operational convenience while each access point is subject to appropriate security scrutiny, preventing unauthorized or malicious access.
Solution Approach 2:
The security gateway serves as an intermediary that mediates all access to the controllable device regardless of the source. Even though multiple parties (administrators, cloud service providers, end users) need access for operational purposes, the gateway inspects and controls all communications, allowing legitimate access while blocking malicious attacks attempting to exploit these multiple access points.
3Reliability
If cryptography is used to secure communications, then security is improved, but data must be decrypted upon entering the TEE which may expose it to risks
Solution Approach 1:
The patent extracts the decryption operation from the general system environment and places it specifically within the Trusted Execution Environment (TEE). By taking out this sensitive cryptographic operation and isolating it within a hardware-based secure boundary, the system ensures that decrypted data never resides in untrusted memory or processing areas. The TEE provides a secure enclave where decryption occurs, and the resulting plaintext is immediately used or discarded without exposure to the rest of the system.
Solution Approach 2:
The TEE creates an inert or secure environment for handling decrypted data. This hardware-isolated environment acts as a protected atmosphere where sensitive operations (decryption and subsequent processing) occur without exposure to external threats or internal system vulnerabilities. The inert nature of the TEE ensures that even if the rest of the system is compromised, the decrypted data remains protected within this secure enclave.
Data Source
AI summary
A brownfield security gateway is configured to support a trusted execution environment (TEE) that employs cryptographic and physical security—which forms a trusted cyber physical system—to protect sensitive transmissions on route to a controllable device. The gateway may be implemented with a System on Chip (SoC) that utilizes an application layer gateway to filter content within a transmission. When the application layer gateway authorizes the transmission, the transmission is forwarded to a trusted peripheral device that is configured with communication transport protocols, and the trusted peripheral device transfers the transmission to the controllable device. The trusted peripheral device and the controllable device are physically protected by, for example, protected distribution systems. Accordingly, the trusted peripheral device functions as a gateway between the SoC and the controllable device.


