Dynamic Trusted Execution Environment Hardware Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The configuration of hardware resources for keys stored in the Trusted Execution Environment (TEE) is static and hardcoded, making it expensive and inefficient to change or modify use cases, requiring a redesign for dynamic management.
Innovation Solution
A method for updating TEE hardware configuration using key update messages that include key update information, allowing for over-the-air (OTA) changes to grant or deny access to hardware resources based on authentication, utilizing encrypted key BLOBs and key update flags to dynamically manage access for trusted applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the TEE hardware configuration is static and hardcoded by the manufacturer, then the security and reliability of the TEE is ensured, but the adaptability and flexibility to modify use cases or add new functionality is reduced
Solution Approach 1:
The patent implements dynamic configuration of TEE hardware resources through key update messages that can modify access permissions at runtime. The configuration is no longer static but can be changed by receiving authenticated key update information that reconfigures which hardware resources are accessible to the TEE, resolving the contradiction between fixed security and flexible adaptability.
Solution Approach 2:
The patent changes the parameters of TEE hardware access by introducing key update messages that modify access permissions. Instead of changing physical hardware, the system changes the access parameters through cryptographic key updates, allowing flexible reconfiguration while maintaining security boundaries.
2Adaptability or versatility
If the configuration of stored keys in the TEE is changed to add new use cases or modify old use cases, then the adaptability and functionality of the TEE is improved, but the cost and complexity of software updates increases
Solution Approach 1:
The patent extracts the configuration data from the main software firmware and separates it into independent key update messages. This allows configuration changes to be delivered independently of full software updates, reducing the complexity and cost of updates while maintaining adaptability.
Solution Approach 2:
The patent prepares configuration changes in advance as authenticated key update messages that can be deployed independently. The configuration updates are pre-packaged with authentication information, allowing them to be applied directly without requiring complex software update procedures.
3Manufacturing precision
If the TEE configuration is hardcoded in the manufacturer's software, then the manufacturing precision and initial security setup is ensured, but the ease of operation and maintenance for future modifications is reduced
Solution Approach 1:
The patent enables the TEE to self-configure by receiving authenticated key update messages. The system maintains its initial secure configuration but can autonomously update its own access permissions through cryptographic authentication, eliminating the need for manufacturer intervention or complex update procedures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for dynamic trusted execution environment (TEE) hardware configuration are provided. A key update message including key update information is received and authenticated for a key stored in the TEE of a mobile computing device. The stored key may define access to hardware resources of the mobile computing device. The hardware configuration for the stored key in the TEE may be changed based upon the key update information.