Distributed Trusted Execution Environment Termination via Confirmation Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a system of connected accelerator subsystems, terminating a distributed trusted execution environment (TEE) poses security risks if not done properly, as malicious code can inject and read confidential data from unencrypted traffic between accelerators.
Innovation Solution
Each accelerator subsystem includes a root of trust with processing circuitry that erases workload and results data from memory, sends confirmation messages, and only terminates the TEE after verifying data erasure across connected subsystems, ensuring data confidentiality through encryption and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the TEE is terminated on one accelerator without being terminated on connected accelerators, then the processing can be reset faster, but security is compromised as malicious code can read confidential data from unencrypted traffic
Solution Approach 1:
The patent applies preliminary action by requiring all connected accelerators to terminate their TEEs and erase confidential data before any accelerator is reset. The root of trust coordinates termination across the distributed system, ensuring that data erasure is completed on all accelerators before resetting begins, thus preventing security breaches during the transition state
Solution Approach 2:
The patent implements feedback through confirmation messages exchanged between roots of trust and the host system. Each root of trust sends a confirmation message indicating that data erasure has been completed on its accelerator, and the host system waits to receive all confirmation messages before allowing resets to proceed, ensuring security is maintained
2Reliability
If confirmation messages are exchanged between roots of trust to verify data erasure, then security is improved, but the termination process becomes more complex
Solution Approach 1:
The host system acts as an intermediary that coordinates the termination process across multiple accelerators. It collects confirmation messages from all roots of trust, verifies that data erasure is complete on all connected accelerators, and then signals when it is safe to proceed with resets, simplifying the overall coordination complexity
Solution Approach 2:
The patent segments the termination process into distinct phases: first, all accelerators erase their confidential data; second, roots of trust send confirmation messages; third, the host system verifies all confirmations; and fourth, accelerators are reset. This segmentation makes the complex distributed termination process manageable and verifiable
Data Source
AI summary
A method for securely terminating a distributed trusted execution environment (TEE) spanning a plurality of work accelerators. After wiping sensitive data from the memory of its accelerator, a root of trust for each accelerator is configured to receive confirmation that the data has been wiped from the processor memory in relevant other accelerators prior to moving on to the next stage at which the TEE on its associated accelerator is terminated. Since the data has been wiped from the other accelerators, even if a third party were to inject malicious code into the accelerator, they would be unable to read out the secret data from the other accelerators since the data has been wiped from those other accelerators. In this way, a mechanism is provided for ensuring that when the distributed TEE is terminated, malicious third parties are unable to read out confidential data from the accelerators.


