Enclave Memory Region Secure Device Address Map

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing trusted execution environments face performance and battery-life issues due to the time- and power-consuming encryption and decryption processes required for secure communication with hardware devices, particularly in mobile systems.

Innovation Solution

Implementing an enclave memory region with a secure access control model that uses a device enclave mode bit to enable direct memory access and memory-mapped I/O communications without the need for encryption, allowing secure communication between the enclave and devices through a secure device address map and register filter component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and decryption are used for secure communication between enclave and hardware devices, then security is maintained, but performance and battery life deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the communication path into two distinct channels: an encrypted channel for general data communication and a secure unencrypted channel for time-sensitive operations. The secure device address map creates a dedicated memory region that bypasses encryption, while the device enclave mode bit identifies which channel to use. This segmentation allows critical performance operations to avoid encryption overhead while maintaining security for other communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism—the secure device address map and device enclave mode bit—that mediates between the enclave and hardware devices. This intermediary enables direct memory access for time-sensitive operations without requiring encryption/decryption, thus resolving the contradiction by providing a trusted shortcut path while maintaining overall security through the mode bit verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and decryption are used for secure communication between enclave and hardware devices, then security is maintained, but energy consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The communication system is segmented into encrypted and unencrypted paths based on operational requirements. Time-sensitive operations use the unencrypted path through the secure device address map, consuming minimal energy, while other operations use the encrypted path. The device enclave mode bit determines which path to take, enabling energy-efficient operation for critical functions without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption parameter dynamically based on the device enclave mode bit. When the mode bit indicates a time-sensitive operation, encryption is disabled for that transaction, reducing energy consumption. This parameter change allows the system to adapt energy usage to operational requirements, extending battery life while maintaining security for non-time-critical operations.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If direct memory access is enabled for devices to communicate with enclave, then communication efficiency improves, but security risks increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by creating a secure device address map that maps only specific device addresses to enclave memory regions. This localized address mapping ensures that direct memory access is permitted only for authorized device-enclave communication paths, while other access attempts are blocked. The device enclave mode bit further refines this local quality by identifying authorized transactions at the bit level, maintaining security while enabling efficient direct access where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10565370B2System and method for enabling secure memory transactions using enclaves
Publication Date: 2020.02.18 INTEL CORP
  • US10565370B2 patent drawing
  • US10565370B2 patent drawing
  • US10565370B2 patent drawing

AI summary

Various embodiments are generally directed to an apparatus, method, and other techniques to provide direct-memory access, memory-mapped input-output, and/or other memory transactions between devices designated for use by an enclave and the enclave itself. A secure device address map may be configured to map addresses for the enslave device and the enclave, and a register filter component may grant access to the enclave device to the enclave.