Dynamic Trusted Execution Environment Hardware Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The configuration of hardware resources for keys stored in the Trusted Execution Environment (TEE) is static and hardcoded, making it expensive and inefficient to change or modify use cases, requiring a redesign for dynamic management.

Innovation Solution

A method for updating TEE hardware configuration using key update messages that include key update information, allowing for over-the-air (OTA) changes to grant or deny access to hardware resources based on authentication, utilizing encrypted key BLOBs and key update flags to dynamically manage access for trusted applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TEE hardware configuration is static and hardcoded by the manufacturer, then the security and reliability of the TEE is ensured, but the adaptability and flexibility to modify use cases or add new functionality is reduced

Engineering Contradiction:
ImproveTEE securityVSAvoidhardware configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration of TEE hardware resources through key update messages that can modify access permissions at runtime. The configuration is no longer static but can be changed by receiving authenticated key update information that reconfigures which hardware resources are accessible to the TEE, resolving the contradiction between fixed security and flexible adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of TEE hardware access by introducing key update messages that modify access permissions. Instead of changing physical hardware, the system changes the access parameters through cryptographic key updates, allowing flexible reconfiguration while maintaining security boundaries.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the configuration of stored keys in the TEE is changed to add new use cases or modify old use cases, then the adaptability and functionality of the TEE is improved, but the cost and complexity of software updates increases

Engineering Contradiction:
ImproveTEE functionalityVSAvoidsoftware update complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the configuration data from the main software firmware and separates it into independent key update messages. This allows configuration changes to be delivered independently of full software updates, reducing the complexity and cost of updates while maintaining adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent prepares configuration changes in advance as authenticated key update messages that can be deployed independently. The configuration updates are pre-packaged with authentication information, allowing them to be applied directly without requiring complex software update procedures.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If the TEE configuration is hardcoded in the manufacturer's software, then the manufacturing precision and initial security setup is ensured, but the ease of operation and maintenance for future modifications is reduced

Engineering Contradiction:
Improveinitial TEE configurationVSAvoidconfiguration modification
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent enables the TEE to self-configure by receiving authenticated key update messages. The system maintains its initial secure configuration but can autonomously update its own access permissions through cryptographic authentication, eliminating the need for manufacturer intervention or complex update procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3152698B1Dynamic configuration of trusted executed environment
Publication Date: 2019.07.24 SONY GROUP CORP
  • EP3152698B1 patent drawingFigure 1
  • EP3152698B1 patent drawingFigure 2
  • EP3152698B1 patent drawingFigure 3

AI summary

Systems and methods for dynamic trusted execution environment (TEE) hardware configuration are provided. A key update message including key update information is received and authenticated for a key stored in the TEE of a mobile computing device. The stored key may define access to hardware resources of the mobile computing device. The hardware configuration for the stored key in the TEE may be changed based upon the key update information.