Confidential Computing Secure Enclave Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices are vulnerable to attacks and untrustworthy due to the need to balance security, runtime, and memory constraints, especially in cloud and edge services, where data and operations are controlled remotely by third-party entities.

Innovation Solution

Implementing a security intelligent controller with component authentication, secure boot processes, data encryption with integrity and anti-replay mechanisms, and secure physical objects like fuses, PUFs, and lockable non-volatile memory to reduce the number of trusted components and ensure secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data and operations are controlled remotely by third-party entities in cloud and edge services, then service accessibility and scalability are improved, but security and trustworthiness deteriorate due to vulnerability to attacks

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the trusted computing base by introducing a secure enclave that isolates critical security functions from the untrusted remote environment. The enclave separates sensitive operations (encryption, authentication) from general-purpose processing, allowing remote services to access computing resources while maintaining security boundaries that prevent attacks on the core trust anchor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure enclave acts as an intermediary between untrusted remote services and the trusted computing resources. It mediates all security-critical operations by receiving requests from remote entities, performing authenticated operations within the protected environment, and returning results without exposing the underlying trust mechanisms to potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If hardware and software engineers balance security, runtime, and memory constraints, then system performance is maintained, but computing devices become vulnerable to attacks due to unavoidable security trade-offs

Engineering Contradiction:
Improvesystem performanceVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts security-critical functions from the general-purpose processing environment into a dedicated secure enclave. By taking out encryption, authentication, and key management operations from the vulnerable host system, the enclave eliminates the need for engineers to balance security against performance in the main system, as these functions now run in a protected environment where security constraints are hard-coded into the hardware architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure enclave provides beforehand cushioning by pre-establishing security boundaries and protection mechanisms before attacks can occur. The hardware-enforced isolation and trusted execution environment are configured in advance to prevent attacks on cryptographic operations and sensitive data, rather than attempting to respond to threats after they manifest in the performance-critical path.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If the number of trusted components is reduced through authentication and encryption mechanisms, then security against attacks is improved, but device complexity increases due to additional security protocols

Engineering Contradiction:
Improvesecurity against attacksVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions (authentication, encryption, integrity verification, and anti-replay protection) into a single integrated secure enclave architecture. Instead of implementing separate security protocols for each function, the enclave combines them into unified hardware-enforced mechanisms, reducing the overall complexity of security protocols while maintaining comprehensive protection against attacks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure enclave provides universal security services that handle multiple security requirements through a single trusted interface. Rather than requiring different complex protocols for authentication, encryption, and integrity checking, the enclave offers a multi-functional trusted execution environment that handles all these security needs through standardized hardware-enforced operations, simplifying the security architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250211452A1System and methods for confidential computing
Publication Date: 2025.06.26 SDG LOGIC INC
  • US20250211452A1 patent drawing
  • US20250211452A1 patent drawing
  • US20250211452A1 patent drawing

AI summary

Systems, apparatuses, methods, and computer-readable media for implementing confidential computing of one or more computing systems and/or devices using component authentication and data encryption with integrity and anti-replay mechanisms are disclosed. In some examples, the systems, apparatuses, methods, and computer-readable media described herein can perform various techniques, including one or more secure boot processes, component and data authentication, and data encryption with integrity and anti-replay, among other secure techniques. One implementation may include executing secure boot process based on authentication of a device identifier stored in a secure physical object of a processing device. Another implementation may include encrypting and storing a counter value corresponding to a cache line and generating an integrity tag value replacing error correction code bits associated with the cache line with the generated cache line tag value.